<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1652215597704667757</id><updated>2011-12-02T16:36:02.588+01:00</updated><category term='Tools'/><category term='Englisch'/><category term='Varia'/><category term='Security'/><category term='Feedback'/><category term='Toolbars'/><category term='Reacties'/><category term='Beveiliging'/><category term='Anti Malware Help Feedback'/><title type='text'>Emphyrio's Security Blog</title><subtitle type='html'>&lt;a href="http://www.antimalwarehelp.be/"&gt;&lt;strong&gt;Anti Malware Help&lt;/strong&gt;&lt;/a&gt;    &lt;a href="http://emphyrio.blog.com/"&gt;&lt;strong&gt;Emphyrio's Security Blog&lt;/strong&gt; (English)&lt;/a&gt;</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>41</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-3125425498990810326</id><published>2011-10-17T14:42:00.001+02:00</published><updated>2011-10-17T14:44:51.117+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>PC Info is gelanceert !</title><content type='html'>&lt;p&gt;17 Oktober 2011 - PC Info gelanceert !&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;PC Info® is ontwikkeld met in het achterhoofd de behoefte van de gebruiker om relevante informatie op een forum te posten en de Helper die de juiste informatie wil verkrijgen.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Deze tool maakt het beiden gemakkelijker om de juiste informatie te posten.&lt;br /&gt;Voor de gebruiker betekend dit het einde van lang en frustrerend zoekwerk, voor de Helper het verkrijgen van de relevante info.&lt;br /&gt;&lt;br /&gt;Beiden varen er dus wel bij.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Wat kost het? Niets !&lt;br /&gt;Géén toolbars, géén spyware,snearware,adware of welke "-ware" dan ook.&lt;br /&gt;Niet onbelangrijk : Een volledige log (alles aangevinkt), duurt minder dan een seconde !!! &lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Meer info : &lt;a title="E Dev" href="http://www.antimalwarehelp.be/E%20Dev/index.html" target="_blank"&gt;E Dev&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;E Dev® is een initiatief van Emphyrio met als doelgratis tools aan te bieden die ontwikkeld zijn in C# Net.&lt;br /&gt;Enkel Nucia en &lt;a href="http://www.antimalwarehelp.be/E%20Dev/index.html#nogo" target="_blank"&gt;E Dev &lt;/a&gt;zijn de officiële aanbieders voor PC Info®.&lt;br /&gt;Nucia zorgt eveneens voor de support. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-3125425498990810326?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/3125425498990810326'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/3125425498990810326'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/10/pc-info-is-gelanceert.html' title='PC Info is gelanceert !'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-278557555339970113</id><published>2011-09-22T13:52:00.002+02:00</published><updated>2011-09-22T14:07:22.689+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>Noodpatch voor Adobe Flash Player</title><content type='html'>&lt;strong&gt;Donderdag 22 september 2011&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Adobe brengt een noodpatch uit voor een door Google ontdekt Flash-lek dat reeds actief wordt misbruikt. Naast dat kritieke lek dicht het ook grote gaten, in Flash en Reader.&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;Adobe raadt iedereen aan om onmiddellijk te updaten naar de net verschenen nieuwste Flash-versie. Dat is versie &lt;strong&gt;10.3.183.10&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-278557555339970113?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/278557555339970113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/278557555339970113'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/09/noodpatch-voor-adobe-flash-player.html' title='Noodpatch voor Adobe Flash Player'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-2613788846530254705</id><published>2011-08-16T00:04:00.002+02:00</published><updated>2011-08-16T00:06:27.556+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anti Malware Help Feedback'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Englisch'/><category scheme='http://www.blogger.com/atom/ns#' term='Feedback'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Anti Malware Help veranderd van URI</title><content type='html'>Vanaf vandaag, 16 Augustus 2011 vind je Anti Malware op het volgende adres :&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.antimalwarehelp.be/"&gt;http://www.antimalwarehelp.be/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nu ook in het Engels.&lt;br /&gt;&lt;br /&gt;U can find Anti Malware Help from today of on this URL adres:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.antimalwarehelp.be/"&gt;http://www.antimalwarehelp.be/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;English and Dutch&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-2613788846530254705?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/2613788846530254705'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/2613788846530254705'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/08/anti-malware-help-veranderd-van-uri.html' title='Anti Malware Help veranderd van URI'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-8867804865951200225</id><published>2011-07-26T02:48:00.009+02:00</published><updated>2011-07-26T03:49:05.014+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>ShellServiceObjectDelayLoad</title><content type='html'>&lt;p&gt;&lt;span&gt;&lt;strong&gt;ShellServiceObjectDelayLoad&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]&lt;br /&gt;"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"&lt;br /&gt;&lt;br /&gt;Instead of pointing to the file itself, it points to the CLSID's InProcServer, which contains the information about the particular DLL file that is being used.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Windows Registry Editor Version 5.00&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}&lt;br /&gt;@="C:\\Windows\\System32\\webcheck.dll"="WebCheck"&lt;br /&gt;&lt;br /&gt;[HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32]&lt;br /&gt;@="C:\\Windows\\System32\\webcheck.dll"&lt;br /&gt;"ThreadingModel"="Apartment"&lt;br /&gt;&lt;br /&gt;The trouble is that with Windows 7, the CLSID's InProcServer {E6FB5E20-DE35-11CF-9C87-00AA005127ED} doesn't exist.&lt;br /&gt;If we try too look for {E6FB5E20-DE35-11CF-9C87-00AA005127ED} in&lt;br /&gt;[HKEY_CLASSES_ROOT\CLSID\] we won't find it.&lt;br /&gt;So, where did it go ?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Windows Registry Editor Version 5.00&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]&lt;br /&gt;"{00C6D95F-329C-409a-81D7-C46C66EA7F33}"=""&lt;br /&gt;"{80009818-f38f-4af1-87b5-eadab9433e58}"="MF ADTS Property Handler"&lt;br /&gt;&lt;strong&gt;"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler" &amp;lt;&amp;lt;&amp;lt;&amp;lt; This is interesting !!!&lt;/strong&gt;&lt;br /&gt;"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"&lt;br /&gt;&lt;strong&gt;"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck" &amp;lt;&amp;lt;&amp;lt;&amp;lt; Here we have our "old" CLSID&lt;/strong&gt;&lt;br /&gt;"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"&lt;br /&gt;"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"&lt;br /&gt;"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So lets check out "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"&lt;br /&gt;&lt;br /&gt;Windows Registry Editor Version 5.00&lt;br /&gt;&lt;br /&gt;[HKEY_CLASSES_ROOT\CLSID\{08165EA0-E946-11CF-9C87-00AA005127ED}]&lt;br /&gt;@="WebCheckWebCrawler"&lt;br /&gt;&lt;br /&gt;[HKEY_CLASSES_ROOT\CLSID\{08165EA0-E946-11CF-9C87-00AA005127ED}\InProcServer32]&lt;br /&gt;&lt;strong&gt;@="C:\\Windows\\System32\\webcheck.dll" &amp;lt;&amp;lt;&amp;lt;&amp;lt; There we have it !!!!&lt;/strong&gt;&lt;br /&gt;"ThreadingModel"="Apartment"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So MS changed the CLSID for webcheck.dll, thats why we couldn't find webcheck.dll on his "old" place.&lt;br /&gt;&lt;br /&gt;Emphyrio :)&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-8867804865951200225?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/8867804865951200225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/8867804865951200225'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/07/shellserviceobjectdelayload.html' title='ShellServiceObjectDelayLoad'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-7840987611625722866</id><published>2011-06-22T22:45:00.007+02:00</published><updated>2011-06-23T14:10:40.426+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Windows update probleem (KB2478663 en KB2518870- Juni 2011)</title><content type='html'>De laatste update van MS geeft problemen.&lt;br /&gt;Meerbepaald de beveiligingsupdate voor Microsoft .NET Framework 4.&lt;br /&gt;KB2478663 .&lt;br /&gt;&lt;br /&gt;Manueel installeren is hier de boodschap.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/nl-nl/details.aspx?FamilyID=c72635e4-c733-4fa1-9db0-75de6ead9e1c"&gt;&lt;strong&gt;KB2478663&lt;/strong&gt;&lt;/a&gt; en &lt;a href="http://www.microsoft.com/downloads/nl-nl/details.aspx?familyid=f7afba05-974f-48f8-b600-9e131ceb7951&amp;displaylang=nl"&gt;&lt;strong&gt;KB2518870&lt;/strong&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Let goed op want er zijn &lt;strong&gt;drie verschillende builds&lt;/strong&gt;, je moet&lt;br /&gt;dus enkel diegene downloaden die voor jouw systeem geschikt is.&lt;br /&gt;&lt;br /&gt;Bijvoorbeeld:&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;NDP40-KB2478663-&lt;strong&gt;IA64&lt;/strong&gt;.exe  Itanium processor&lt;/li&gt;  &lt;br /&gt;&lt;li&gt;NDP40-KB2478663-&lt;strong&gt;x64&lt;/strong&gt;.exe  64 Bits&lt;/li&gt;&lt;br /&gt;&lt;li&gt;NDP40-KB2478663-&lt;strong&gt;x86&lt;/strong&gt;.exe  32 Bits&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Downloaden naar je bureaublad.&lt;br /&gt;Dubbelklikken en installeren.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#cccccc;"&gt;OPMERKING :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Vista en W7 gebruikers: rechtsklikken en kiezen voor &lt;em&gt;Uitvoeren als administrator&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Besturingssystemen:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Windows 7;Windows Server 2003;Windows Server 2008;Windows Server 2008 R2;Windows Vista;Windows XP&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-7840987611625722866?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/7840987611625722866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/7840987611625722866'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/06/windows-update-probleem-kb2478663-juni.html' title='Windows update probleem (KB2478663 en KB2518870- Juni 2011)'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-5030536562580082722</id><published>2011-06-20T00:29:00.011+02:00</published><updated>2011-06-26T15:51:35.293+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>PC Info vs 2.3.0 Béta</title><content type='html'>&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;strong&gt;PC Info&lt;/strong&gt; © is een tool om gemakkelijker gegevens te verzamelen ivm je PC.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Geschreven in C#&lt;br /&gt;Target: Windows XP / Vista en 7, all 32/64, .Net 4.0.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-KTjuQQsaOTU/TgEHFxD8AsI/AAAAAAAAAF4/eTuy0q3l_VI/s1600/Tab1_sc.png"&gt;&lt;/a&gt;&lt;a href="http://2.bp.blogspot.com/-bxhxqHUcszw/TgQLy1D8XUI/AAAAAAAAAGA/j4OwEFg96AY/s1600/Tab1_sc.png"&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/-xK5LtP1LQl8/Tgc4sobgZGI/AAAAAAAAAGI/54DwjFNSAtw/s1600/Tab1_sc.png"&gt;&lt;img style="WIDTH: 400px; HEIGHT: 277px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5622524999213540450" border="0" alt="" src="http://4.bp.blogspot.com/-xK5LtP1LQl8/Tgc4sobgZGI/AAAAAAAAAGI/54DwjFNSAtw/s400/Tab1_sc.png" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/-VpdmwHygK1k/Tgc43KrqciI/AAAAAAAAAGQ/Xi3uaAY_V-A/s1600/Tab3_sc.png"&gt;&lt;img style="WIDTH: 400px; HEIGHT: 280px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5622525180206805538" border="0" alt="" src="http://4.bp.blogspot.com/-VpdmwHygK1k/Tgc43KrqciI/AAAAAAAAAGQ/Xi3uaAY_V-A/s400/Tab3_sc.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/-VpdmwHygK1k/Tgc43KrqciI/AAAAAAAAAGQ/Xi3uaAY_V-A/s1600/Tab3_sc.png"&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-5030536562580082722?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5030536562580082722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5030536562580082722'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/06/pc-info-vs-20-beta.html' title='PC Info vs 2.3.0 Béta'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-xK5LtP1LQl8/Tgc4sobgZGI/AAAAAAAAAGI/54DwjFNSAtw/s72-c/Tab1_sc.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-6409071097940387595</id><published>2011-06-11T15:10:00.005+02:00</published><updated>2011-08-24T00:08:54.349+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anti Malware Help Feedback'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Anti Malware Help soms onbereikbaar</title><content type='html'>Problemen met de Host server van Telenet, zorgen er reeds een maand voor dat de website &lt;a href="http://www.emphyrio.be/"&gt;&lt;strong&gt;Anti Malware Help&lt;/strong&gt;&lt;/a&gt; met de regelmaat van een klok niet te bereiken is.&lt;br /&gt;&lt;br /&gt;In 4 weken tijd is dit nu de vijfde maal en nu duurt het reeds drie dagen.&lt;br /&gt;&lt;br /&gt;Mijn verontschuldigingen voor dit ongemak, een oplossing is in de maak en zal naar alle waarschijnljkheid volgende maand toegepast worden.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;*********************************************************************&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Troubles with the Host server of Telenet is the cause of Anti Malware Help is irregulary not online.&lt;br /&gt;&lt;br /&gt;In four weeks is this the fiftht time in a row, this time during allready three days.&lt;br /&gt;&lt;br /&gt;My apolygies for the inconveniance, a solution to avoid this in the future is in the make.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;UPDATE : &lt;span&gt;New &lt;/span&gt;URI : &lt;a href="http://www.antimalwarehelp.be/"&gt;&lt;span style="font-size:130%;color:#ff0000;"&gt;Anti Malware Help&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-6409071097940387595?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6409071097940387595'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6409071097940387595'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/06/anti-malware-help-soms-onbereikbaar.html' title='Anti Malware Help soms onbereikbaar'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-7040824705041179907</id><published>2011-05-30T16:53:00.004+02:00</published><updated>2011-06-08T14:07:41.489+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Skype levert per ongeluk ongevraagd software mee</title><content type='html'>Tijdens de laatste update van &lt;strong&gt;Skype &lt;/strong&gt;naar aanleiding van de laatste problemen, hebben klanten ongevraagd software meegekregen van&lt;strong&gt; EasyBits GO&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;Deze sofware wordt echter niet juist geinstalleerd waardoor het ook niet correct te verwijderen valt.&lt;br /&gt;&lt;br /&gt;Om de software toch te kunnen verwijderen, heeft de ontwikkelaar van &lt;em&gt;EasyBits GO&lt;/em&gt; een speciale uninstaller uitgegeven.&lt;br /&gt;&lt;br /&gt;Lees verder op &lt;a href="http://www.emphyrio.be/Flash_news_archief.html#skype2"&gt;Anti Malware Help&lt;/a&gt;......&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-7040824705041179907?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/7040824705041179907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/7040824705041179907'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/05/skype-levert-per-ongeluk-ongevraagd.html' title='Skype levert per ongeluk ongevraagd software mee'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-3183821248445577011</id><published>2011-05-26T16:45:00.002+02:00</published><updated>2011-05-30T23:58:12.310+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Skype momenteel offline....</title><content type='html'>Skype kampt momenteel met een storing.&lt;br /&gt;Gebruikers van de software kunnen niet meer inloggen.&lt;br /&gt;Ook de website werkt niet.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Fix&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;Gebruikers van Skype (Windows en Mac) kunnen via een fix, hun client weer werkend krijgen.&lt;br /&gt;&lt;br /&gt;Zie verder op &lt;span&gt;&lt;a href="http://www.emphyrio.be/Flash_news_archief.html#skype"&gt;Anti Malware Help&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-3183821248445577011?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/3183821248445577011'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/3183821248445577011'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/05/skype-momenteel-offline.html' title='Skype momenteel offline....'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-8234849245432886027</id><published>2011-05-17T18:44:00.005+02:00</published><updated>2011-05-18T00:08:55.243+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>TDL4 infectie op Windows 7-32bits</title><content type='html'>&lt;strong&gt;&lt;span style="color:#ffff33;"&gt;OPMERKING: Onderstaand is een verslag van een TDL4 behandeling&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ffff33;"&gt;bedoeld voor malware analysten.&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ffff33;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ffff33;"&gt;Het is geenszins de bedoeling deze procedure te gebruiken als gewone gebruiker.&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Naar aanleiding van een rogue besmetting (Anti Malware Doctor), zette ik rkill en MBAM (volledige scan) in.&lt;br /&gt;&lt;br /&gt;MBAM log was clean.&lt;br /&gt;&lt;br /&gt;TDSSKiller gaf echter aanduiding van een TDL besmetting.&lt;br /&gt;Uit de TDSSKiller log las ik dat hij deze verwijderde.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Omdat de TS géén antivirus had geinstalleerd, advizeerde ik hem/haar dit alsnog te doen.&lt;br /&gt;&lt;strong&gt;&lt;a href="http://www.avira.com/en/avira-free-antivirus"&gt;Avira Antivir&lt;/a&gt;&lt;/strong&gt; melde een aanwezigheid van een &lt;em&gt;Rootkit&lt;/em&gt; en een &lt;em&gt;Vundoinfectie&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;&lt;span style="color:#ff0000;"&gt;Starting master boot sector scan:Master boot sector HD0&lt;br /&gt;[DETECTION] Contains code of the BOO/TDss.M boot sector virus&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;[NOTE] The boot sector was not written!Master boot sector HD1&lt;br /&gt;[INFO] No virus was found!&lt;br /&gt;Start scanning boot sectors:Boot sector 'C:\'&lt;br /&gt;[DETECTION] Contains code of the BOO/TDss.M boot sector virus&lt;br /&gt;[NOTE] The boot sector was not written!&lt;br /&gt;&lt;br /&gt;Starting to scan executable files (registry).&lt;br /&gt;The registry was scanned ( '1711' files ).&lt;br /&gt;&lt;br /&gt;Starting the file scan:&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ff0000;"&gt;Begin scan in 'C:\Windows\system32'C:\Windows\system32\dsdmol.dll&lt;br /&gt;[DETECTION] Is the TR/Vundo.Gen2 Trojan&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;Beginning disinfection:C:\Windows\system32\dsdmol.dll&lt;br /&gt;[DETECTION] Is the TR/Vundo.Gen2 Trojan&lt;br /&gt;[WARNING] The file could not be copied to quarantine!&lt;br /&gt;[WARNING] The file could not be deleted!&lt;br /&gt;[NOTE] The file is scheduled for deleting after reboot.&lt;br /&gt;The repair notes were written to the file 'C:\avrescue\rescue.avp'.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Was opzich merkwaardig omdat MBAM hier geen melding van had gemaakt.&lt;br /&gt;CF ingezet en een ongeldige Netsvc gevonden.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;.....&lt;br /&gt;R2 cchdohew;Crcdisk Filter Helper;c:\windows\System32\svchost.exe [2009-07-14 20992]&lt;br /&gt;.....&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;cchdohew&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Deze verwijderdt met een CFScript gevolgd door een tweede maal TDSSKiller.&lt;br /&gt;De CF log was clean, TDSSKiller vertoonde de zelfde handelingen als ervoor.&lt;br /&gt;&lt;br /&gt;Blijkbaar was TDSSKiller niet instaat deze te verwijderen.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;aswMBR.exe&lt;/strong&gt; ingezet.&lt;br /&gt;Deze toonde netjes de Rootkit (TDL4) infectie en verwijderde die na een aswMBR fix.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;aswMBR version 0.9.5.256 Copyright(c)&lt;br /&gt;2011 AVAST SoftwareRun date: 2011-05-10 21:40:35-----------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;21:40:35.762 OS Version: Windows 6.1.7600&lt;br /&gt;21:40:35.762 Number of processors: 2 586 0xF0B&lt;br /&gt;21:40:35.764 ComputerName: FRANCA-PC UserName: Franca&lt;br /&gt;21:40:36.212 Initialize success&lt;br /&gt;21:40:42.836 Disk 0 (boot) \Device\Harddisk0\DR0 -&amp;gt; \Device\Ide\IAAStorageDevice-0&lt;br /&gt;21:40:42.838 Disk 0 Vendor: WDC_WD16 04.0 Size: 152627MB BusType: 3&lt;br /&gt;21:40:42.853 Disk 0 MBR read successfully&lt;br /&gt;21:40:42.856 Disk 0 MBR scan&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ff0000;"&gt;21:40:42.859 Disk 0 &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="mailto:TDL4@MBR"&gt;&lt;span style="font-size:85%;color:#ff0000;"&gt;&lt;strong&gt;TDL4@MBR&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;&lt;span style="color:#ff0000;"&gt; code has been found&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;21:40:42.862 Disk 0 Windows 7 default MBR code found via API&lt;br /&gt;21:40:42.866 Disk 0 MBR hidden&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ff0000;"&gt;21:40:42.869 Disk 0 MBR [TDL4] **ROOTKIT**&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;21:40:42.873 Disk 0 trace - called modules:&lt;br /&gt;21:40:42.878 21:40:42.882 Scan finished successfully&lt;br /&gt;21:41:06.713 Disk 0 MBR has been saved successfully to "C:\Users\Franca\Desktop\MBR.dat"&lt;br /&gt;21:41:06.714 The log file has been saved successfully to "C:\Users\Franca\Desktop\aswMBR.txt"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;TDSSKiller was na deze handeling eveneens "clean".&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.nucia.eu/forum/showthread.php?t=63609"&gt;http://www.nucia.eu/forum/showthread.php?t=63609&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-8234849245432886027?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/8234849245432886027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/8234849245432886027'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/05/tdl4-infectie-op-windows-7-32bits.html' title='TDL4 infectie op Windows 7-32bits'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-8149228125126705270</id><published>2011-05-11T14:47:00.002+02:00</published><updated>2011-05-11T14:50:41.794+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Facebook lekt jarenlang persoonlijke data</title><content type='html'>&lt;p&gt;Meer dan 100.000 applicaties hebben toegang tot de persoonlijke data van Facebookgebruikers.&lt;br /&gt;Daardoor hebben adverteerders en app-aanbieders die informatie mogelijk al in handen.&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Facebook gebruikt sindsdien &lt;strong&gt;oauth2.0&lt;/strong&gt; voor de authenticeren van de gebruiker.&lt;br /&gt;Dat protocol is veiliger.&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Het is aan te raden om je wachtwoord te veranderen.&lt;br /&gt;Daardoor worden de tokens ongeldig verklaard en vraagt de applicatie bij een volgend gebruikpnieuw toestemming om toegang te krijgen tot de persoonlijke pagina’s.&lt;br /&gt;Maar dan wordt dus oauth2.0 gebruikt.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Bronnen: &lt;a href="http://webwereld.nl/nieuws/106631/facebook-lekt-jarenlang-persoonlijke-data.html#utm_source=list_news_headline_8&amp;amp;utm_medium=website&amp;amp;utm_campaign=ww"&gt;Webwereld&lt;/a&gt; &lt;a href="http://www.symantec.com/connect/blogs/facebook-applications-accidentally-leaking-access-third-parties"&gt;Symantec&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-8149228125126705270?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/8149228125126705270'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/8149228125126705270'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/05/facebook-lekt-jarenlang-persoonlijke.html' title='Facebook lekt jarenlang persoonlijke data'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-2026892767951274554</id><published>2011-04-30T15:28:00.002+02:00</published><updated>2011-08-24T00:09:48.984+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>Gomeo redirect</title><content type='html'>&lt;p&gt;Je wordt geredirect naar sites als gomeo.nl, information-seeking.com, etc.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;De werkwijze om deze infectie aan te pakken vind je op &lt;a href="http://www.antimalwarehelp.be/ned/Infecties/Gomeo%20redirect.html"&gt;&lt;strong&gt;Anti Malware Help&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-2026892767951274554?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/2026892767951274554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/2026892767951274554'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/04/gomeo-redirect.html' title='Gomeo redirect'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-681200406683571376</id><published>2011-04-19T14:29:00.007+02:00</published><updated>2011-04-19T14:48:24.087+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Google en Privacy</title><content type='html'>Opruimen geeft een lekker gevoel.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Internet geschiedenis verwijderdt in de browser(s).&lt;/li&gt;&lt;br /&gt;&lt;li&gt;DNS cache geledigd&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Cookies opgeruimd&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Flashcookies verwijderdt&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Ccleaner gerunt&lt;/li&gt;&lt;/ul&gt;Dan zitten we lekker opgeruimd en veilig, niet?&lt;br /&gt;Niet dus !&lt;br /&gt;&lt;br /&gt;Als je net als ik een Google account heb, ga dan eens naar je Google account &amp;gt; &lt;em&gt;Mijn Account&lt;br /&gt;&lt;/em&gt;En onder &lt;em&gt;Mijn Producten&lt;/em&gt; kies je &lt;em&gt;Webgeschiedenis&lt;br /&gt;&lt;/em&gt;Wees vervolgens zo verbaasd als ik.......&lt;br /&gt;&lt;br /&gt;Daar staat alles netjes bijgehouden.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Bezochtte websites&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Afbeeldingen&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Muziek&lt;/li&gt;&lt;br /&gt;&lt;li&gt;en ga zo maar door....&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;Je kan wel verwijderen, maar ik wil dit weg&lt;br /&gt;&lt;br /&gt;Dat kan dus:&lt;/p&gt;&lt;em&gt;Gebruik het liefst IE voor deze bewerkingen&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;Ga naar Google account &amp;gt; Mijn Account &amp;gt; Mijn Producten en kies Bewerken.&lt;br /&gt;Vervolgens Product verwijderen &amp;gt; Webgeschiedenis definitief verwijderen.&lt;br /&gt;Geef je paswoord in (rechts)&lt;br /&gt;Vink aan : &lt;strong&gt;Ja, ik wil Webgeschiedenis permanent verwijderen uit mijn Google-account&lt;br /&gt;&lt;/strong&gt;Klik op &lt;em&gt;Verwijder Webgeschiedenis&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Done!&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-681200406683571376?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/681200406683571376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/681200406683571376'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/04/google-en-privacy.html' title='Google en Privacy'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-6609758203915830695</id><published>2011-04-14T23:17:00.004+02:00</published><updated>2011-04-27T00:28:31.849+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>Adobe brengt een noodpatch uit.</title><content type='html'>&lt;p&gt;Vanaf &lt;strong&gt;vrijdag 15 april&lt;/strong&gt; brengt Adobe een noodpatch uit. &lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Wat is er kwetsbaar?&lt;/strong&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Adobe Flash Player, versies eerder dan versie 10.2.153.1 voor Windows, Mac OS X, Linux en Solaris systemen &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Adobe Flash Player, versies eerder dan versie 10.2.154.25 voor Chrome gebruikers&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Adobe Flash Player, versies eerder dan versie 10.2.156.12 voor Android gebruikers&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Adobe Reader en Acrobat, versie 10.0.2 en oudere 10.x en 9.x versies. &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Adobe Reader X is momenteel door zijn "protected mode" beschermd tegen deze exploits. Een update voor deze zal dan rond 14 Juni 2011 volgen.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Meer info en hoe te werk gaan vind je op &lt;a href="http://www.emphyrio.be/Flash_news.html#adobe"&gt;&lt;strong&gt;Anti Malware Help&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-6609758203915830695?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6609758203915830695'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6609758203915830695'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/04/adobe-brengt-een-noodpatch-uit.html' title='Adobe brengt een noodpatch uit.'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-4689845493366957200</id><published>2011-04-14T14:29:00.002+02:00</published><updated>2011-04-14T14:47:48.838+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>Beheersrechten in Windows.</title><content type='html'>Een account gebruiken dat niet de volledige beheersrechten heeft, biedt niets dan voordelen.&lt;br /&gt;&lt;br /&gt;Het voorkomt:&lt;/p&gt;64% van alle Microsoft "vulnerabilities"(= "zwakheden" zeg maar).&lt;br /&gt;&lt;br /&gt;75% van de Windows 7 lekken in 2010.&lt;br /&gt;&lt;br /&gt;100% van de Office exploits in 2010.&lt;br /&gt;&lt;br /&gt;100% van de Internet Explorer 8 (IE8) gaten in 2010. &lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;Tot deze conclusie kwam &lt;a href="http://www.beyondtrust.com/PressReleases/Microsoft-Vulnerabilities-Report.aspx?section=Press-Releases"&gt;&lt;strong&gt;Beyond Trust&lt;/strong&gt;&lt;/a&gt;, een bedrijf dat zich specialiseert in autorisatiemanagement.&lt;br /&gt;&lt;br /&gt;Het volledig rapport kan je &lt;a href="http://www.beyondtrust.com/whitepapers/BeyondTrust2010-Microsoft-Vulnerability-analysis.aspx"&gt;&lt;strong&gt;hier&lt;/strong&gt;&lt;/a&gt; lezen. &lt;br /&gt;&lt;p /&gt;Een account aanmaken met &lt;strong&gt;beperkte&lt;/strong&gt; rechten is snel gemaakt.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.schoonepc.nl/instal/gebruikers.html"&gt;In Windows XP&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.schoonepc.nl/vista/gebruikersaccounts_afstellen.html"&gt;In Windows Vista&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.minatica.be/content/293-Een-account-aanmaken-in-Windows-7"&gt;In Windows 7&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-4689845493366957200?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/4689845493366957200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/4689845493366957200'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/04/beheersrechten-in-windows.html' title='Beheersrechten in Windows.'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-649506951667125522</id><published>2011-04-13T02:11:00.002+02:00</published><updated>2011-04-13T02:13:45.355+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>Dropbox is lek.</title><content type='html'>&lt;p&gt;De populaire online opslag- en data-uitwisseldienst Dropbox is lek. Daarom is het, zeker voor zakelijke gebruikers, af te raden om de dienst te gebruiken.&lt;br /&gt;&lt;br /&gt;Lees er meer over &lt;a title="Dropbox lek" href="http://webwereld.nl/nieuws/106319/data-uitwisseldienst-dropbox-is-lek.html" target="_blank"&gt;hier&lt;/a&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-649506951667125522?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/649506951667125522'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/649506951667125522'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/04/dropbox-is-lek.html' title='Dropbox is lek.'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-5077855402912630678</id><published>2011-04-12T02:54:00.009+02:00</published><updated>2011-04-19T15:53:41.956+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Avast problemen met virus defs 110411-1</title><content type='html'>&lt;p&gt;11 April 2011&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p class="high"&gt;&lt;span class="high"&gt;Avast heeft problemen met &lt;strong&gt;virus defs 110411-1&lt;/strong&gt;&lt;/span&gt;.&lt;/p&gt;Deze update bevat een error dat resulteert in het onterecht markeren van goede sites als zijnde slecht. De meeste sites die een script bevatten in een bepaalde formaat, zorgden bij Avast voor deze melding. Het Avast team had echter het probleem snel ontdekt en tevens voor een fix-update gezorgt.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;strong class="high"&gt;virus defs 110411-2&lt;/strong&gt; lost het probleem op. &lt;/p&gt;&lt;br /&gt;&lt;p&gt;Indien er nog gebruikers zijn die hiervan last hebben, worden ze verzocht om deze update manueel uit te voeren. &lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Dit doe je zo:&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Rechtsklik op de avast icoon in de Taakbalk (de oranje (a) bal) en selecteer Update &amp;gt; Engine and Virus Definitions.&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Nadat je succesvol hebt geupdate doe je het volgende:&lt;/p&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Open Avast!.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Selecteer "Maintenance".&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Selecteer"Virus Chest".&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Sorteer "by time moved" (volgens tijd verplaatst) naar Chest.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Selecteer de bestanden die je wil herstellen.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Rechtsklik en selecteer "Restore".&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;Bron: &lt;a href="https://blog.avast.com/2011/04/11/false-positive-issue-with-virus-defs-110411-1/"&gt;Avast Blogt &lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-5077855402912630678?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/5077855402912630678/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/04/avast-problemen-met-virus-defs-110411-1.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5077855402912630678'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5077855402912630678'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/04/avast-problemen-met-virus-defs-110411-1.html' title='Avast problemen met virus defs 110411-1'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-1492722284571651729</id><published>2011-03-19T00:23:00.005+01:00</published><updated>2011-03-19T00:54:16.428+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>MBR infectie op een Hewlett-Packard Windows 7 systeem</title><content type='html'>Gisteren kwam ik een MBR infectie tegen op een Windows 7 x64 systeem.&lt;br /&gt;De log en behandeling kan je op &lt;a href="http://www.nucia.eu/forum/showthread.php?p=594799#post594799"&gt;&lt;strong&gt;deze link&lt;/strong&gt;&lt;/a&gt; bekijken.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Win7 repair CD kon het niet fixen en gaf de volgende output:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Problem Event Name: StartupRepairOffline&lt;/li&gt;&lt;li&gt;Problem Signature 01: 6.1.7600.16385&lt;/li&gt;&lt;li&gt;Problem Signature 02: 6.1.7600.16385&lt;/li&gt;&lt;li&gt;Problem Signature 03: unknown&lt;/li&gt;&lt;li&gt;Problem Signature 04: 18&lt;/li&gt;&lt;li&gt;Problem Signature 05: ExternalMedia&lt;/li&gt;&lt;li&gt;Problem Signature 06: 1&lt;/li&gt;&lt;li&gt;Problem Signature 07: MissingOsLoader&lt;/li&gt;&lt;/ul&gt;HD op een andere PC aangesloten en deze bevestigde de MBR infectie tijdens het opstarten:&lt;br /&gt;&lt;br /&gt;"Threat found, Object: MBR sector of the 0. physical disk, Threat: Win32/Olmarik.AJL trojan"&lt;br /&gt;&lt;br /&gt;De clean actie geeft : "Error while cleaning - operation unavailable for this object type".&lt;br /&gt;&lt;br /&gt;Het handeld hier over een HP pc en deze geeft een aantal herstelopties:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;HP-repair mode&lt;/li&gt;&lt;li&gt;een aantal repair opties &lt;/li&gt;&lt;li&gt;een dos-box&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;De oplossing:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Wanneer je van de originele PC start en de keuze krijgt om in een dosbox te geraken,geef je volgende commando's (na elkaar) in:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;bootrec /fixmbr +[Enter] &lt;/li&gt;&lt;li&gt;bootrec /fixboot +[Enter] &lt;/li&gt;&lt;li&gt;Herstart dan je PC&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Wanneer er een melding komt dat de pc niet meer kan booten, plaats je de Windows DVD in de pc en selecteer je de repair (herstel) optie.&lt;br /&gt;Herstart je pc.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-1492722284571651729?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/1492722284571651729/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/03/mbr-infectie-op-een-hewlett-packard.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/1492722284571651729'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/1492722284571651729'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/03/mbr-infectie-op-een-hewlett-packard.html' title='MBR infectie op een Hewlett-Packard Windows 7 systeem'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-4305393542068701613</id><published>2011-03-18T15:56:00.011+01:00</published><updated>2011-03-19T22:00:59.596+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>SP1 voor Windows 7 x64, WSUS  veroorzaakt problemen</title><content type='html'>Korte tijd geleden werd SP1 beschikbaar gestelt voor Windows 7.&lt;br /&gt;Gebruikers die verbonden zijn met een server waarop WSUS (Windows Server Update Services) draait krijgen nu te maken met een kritieke foutmelding tijdens het opstarten: 0xc00000034&lt;br /&gt;&lt;br /&gt;Voornamelijk de x64 versie word hierdoor geplaagt.&lt;br /&gt;&lt;br /&gt;MS &lt;a href="http://support.microsoft.com/KB/975484"&gt;&lt;strong&gt;raad deze gebruikers aan&lt;/strong&gt; &lt;/a&gt;om terug te keren naar een herstelpunt waarop SP1 nog niet geinstalleerd is.&lt;br /&gt;Het is maar de vraag in hoeverre dat dit nog mogelijk is vermits je systeem immers niet meer wil opstarten.&lt;br /&gt;&lt;br /&gt;Een mogelijke oplossing is deze (enkel voor Windows 7) :&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Maak eerst wel het best &lt;a href="http://windows.microsoft.com/nl-nl/windows7/Back-up-the-registry"&gt;een backup van je register &lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;!&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Start je PC op in Veilige Modus (gewoonlijk F8).&lt;/li&gt;&lt;li&gt;Selecteer "Uw computer herstellen " in "Geavanceerde opstartopties " en klik op Enter.&lt;/li&gt;&lt;li&gt;Selecteer Windows 7 als de te herstellen installatie en klik op Volgende.&lt;/li&gt;&lt;li&gt;Selecteer de taal en een toetsenbordinvoermethode en klik op Volgende.&lt;/li&gt;&lt;li&gt;Selecteer een gebruikersnaam, typ uw wachtwoord en klik op OK.&lt;/li&gt;&lt;li&gt;Klik onder Opties voor systeemherstel op Opdrachtprompt en druk op Enter.&lt;/li&gt;&lt;li&gt;Typ de volgende opdrachten bij de opdrachtprompt. &lt;strong&gt;Druk na elke opdracht op Enter&lt;/strong&gt;:&lt;/li&gt;&lt;/ol&gt;&lt;ul&gt;&lt;li&gt;Reg load HKLM\BaseSystem C:\Windows\System32\config\SYSTEM&lt;/li&gt;&lt;li&gt;Reg delete "HKLM\BaseSystem\ControlSet001\Control\Session Manager" /v SetupExecute&lt;/li&gt;&lt;li&gt;Reg add "HKLM\BaseSystem\ControlSet001\Control\Session Manager" /v SetupExecute /t REG_MULTI_SZ&lt;/li&gt;&lt;li&gt;Reg unload HKLM\BaseSystem&lt;/li&gt;&lt;li&gt;Typ exit bij de opdrachtprompt en druk op Enter.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Start de computer opnieuw op.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Windows Vista gebruikers dienen vanaf hun Windows DVD op te starten om het bovenstaande uit te voeren.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Meer info over dit onderwerp kan je &lt;a href="http://technet.microsoft.com/en-us/library/ff817622(WS.10).aspx"&gt;&lt;strong&gt;op deze link&lt;/strong&gt; &lt;/a&gt;vinden.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-4305393542068701613?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/4305393542068701613/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/03/sp1-voor-windows-7-x64-wsus-veroorzaakt.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/4305393542068701613'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/4305393542068701613'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/03/sp1-voor-windows-7-x64-wsus-veroorzaakt.html' title='SP1 voor Windows 7 x64, WSUS  veroorzaakt problemen'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-5194180021205006723</id><published>2011-02-10T23:44:00.002+01:00</published><updated>2011-02-10T23:52:17.146+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Microsoft schakelt Autorun definitief uit.</title><content type='html'>&lt;strong&gt;Microsoft schakelt Autorun definitief uit.&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;In de Windowsupdate van deze week wordt de Autorun functie definitief uitgeschakeld.&lt;br /&gt;Vroeger kon je usb stick automatisch opstarten dmv de &lt;em&gt;autorun.inf&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;Nu dus niet meer.&lt;br /&gt;&lt;br /&gt;Is dit goed?&lt;br /&gt;Ja, want malware gebruikte gretig deze functie.&lt;br /&gt;CD/DVD's startten echter nog wel automatisch op (als dit is ingesteld).&lt;br /&gt;&lt;br /&gt;Bij Windows 7 gebruikers is deze functie zowiezo uitgeschakeld.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-5194180021205006723?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/5194180021205006723/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/02/microsoft-schakelt-autorun-definitief.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5194180021205006723'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5194180021205006723'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/02/microsoft-schakelt-autorun-definitief.html' title='Microsoft schakelt Autorun definitief uit.'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-4702020994487474263</id><published>2011-01-29T09:46:00.003+01:00</published><updated>2011-01-29T09:50:15.165+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>Valse AVG Antivirus 2011</title><content type='html'>Alsof de perikelen rond AVG 2011 nog niet genoeg zijn, is er nu ook een rogue* van deze tool in de omloop.&lt;br /&gt;&lt;br /&gt;Lees meer erover in de &lt;a title="Rogues" href="http://www.emphyrio.be/rogues.html#AVG" target="_blank"&gt;Rogues Verwijder Instructies&lt;/a&gt; op &lt;strong&gt;Anti Malware Help&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;*&lt;span style="font-size:85%;"&gt;&lt;em&gt;Een rogue is een malware tool dat pretendeert een AV tool te zijn.&lt;/em&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-4702020994487474263?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/4702020994487474263/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/01/valse-avg-antivirus-2011.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/4702020994487474263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/4702020994487474263'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/01/valse-avg-antivirus-2011.html' title='Valse AVG Antivirus 2011'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-5939984221122148062</id><published>2011-01-20T15:44:00.005+01:00</published><updated>2011-01-20T19:51:41.018+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>ESET online markeert geldig bestand</title><content type='html'>ESET Online markeert C&lt;em&gt;:\WINDOWS\system32\kb.dll Win32 &lt;/em&gt;als Bamital.EX trojan&lt;br /&gt;&lt;br /&gt;Daarom is het aan te raden om ESET online niet te laten cleanen.&lt;br /&gt;Deze optie staat als default.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;ESET is momenteel op de hoogte gebracht van deze fout.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-5939984221122148062?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/5939984221122148062/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/01/eset-online-verwijderd-windows.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5939984221122148062'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5939984221122148062'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2011/01/eset-online-verwijderd-windows.html' title='ESET online markeert geldig bestand'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-1914890766569603319</id><published>2010-12-25T06:02:00.004+01:00</published><updated>2011-01-20T16:03:54.588+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>AVG markeert MBAM als een Trojan</title><content type='html'>[&lt;strong&gt;OPGELOST&lt;/strong&gt;]&lt;br /&gt;&lt;br /&gt;Een update van &lt;strong&gt;AVG op 24 December 2010&lt;/strong&gt; zorgde ervoor dat twee DLL files van MBAM (&lt;em&gt;mbamcore.dll&lt;/em&gt; en &lt;em&gt;mbamnet.dll&lt;/em&gt;) aanzien werden als malware.&lt;br /&gt;AVG heeft deze false positive bevestigd en ondertussen gecorrigeerd.&lt;br /&gt;&lt;br /&gt;Wat te doen wanneer je deze per ongeluk in quarantine hebt geplaatst ?&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1 . Exclude de Malwarebytes' Anti-Malware program files directory&lt;/strong&gt;&lt;br /&gt;(gewoonlijk &lt;em&gt;C:\Program Files\Malwarebytes' Anti-Malware&lt;/em&gt;,&lt;br /&gt;of &lt;em&gt;C:\Program Files (x86)\Malwarebytes' Anti-Malware&lt;/em&gt; op x64 operating systems) van AVG.&lt;br /&gt;&lt;br /&gt;Gedetailleerde instructies hoe je dit moet doen kan je &lt;a href="http://forums.malwarebytes.org/index.php?showtopic=10138&amp;amp;st=0&amp;amp;p=167851&amp;amp;#entry167851"&gt;hier&lt;/a&gt; vinden.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2. Herstel de DLL bestanden vanuit de AVG kluis.&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Start AVG&lt;/li&gt;&lt;li&gt;Klik op Geschiedenis &gt; Virus kluis&lt;/li&gt;&lt;li&gt;Selecteer &lt;strong&gt;mbamnet.dll&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;Klik op &lt;em&gt;Herstellen&lt;/em&gt;&lt;/li&gt;&lt;li&gt;Selecteer &lt;strong&gt;mbamcore.dll&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;Klik op &lt;em&gt;Herstellen&lt;/em&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="font-size:85%;"&gt;Bron: &lt;/span&gt;&lt;/em&gt;&lt;a href="http://forums.malwarebytes.org/index.php?showtopic=71130"&gt;&lt;em&gt;&lt;span style="font-size:85%;"&gt;MBAM.org&lt;/span&gt;&lt;/em&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-1914890766569603319?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/1914890766569603319/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/12/avg-markeert-mbam-als-een-trojan.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/1914890766569603319'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/1914890766569603319'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/12/avg-markeert-mbam-als-een-trojan.html' title='AVG markeert MBAM als een Trojan'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-4827669476766694011</id><published>2010-12-24T09:13:00.004+01:00</published><updated>2011-06-21T16:13:19.584+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Online cursussen Programmeren.</title><content type='html'>Het heeft een tijdje geduurd, maar ik heb dan eindelijk een goede, degelijke cursus gevonden.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.homeandlearn.co.uk/"&gt;&lt;strong&gt;Free computer Tutorials&lt;/strong&gt;&lt;/a&gt; is van &lt;strong&gt;Home &amp;amp; Learn&lt;/strong&gt; en bied enkele cursussen aan voor beginners. Gratis en in het Engels.&lt;br /&gt;&lt;br /&gt;Een greep uit het ruime aanbod:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Visual Basic.Net&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Visual C#.Net&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Java&lt;/li&gt;&lt;br /&gt;&lt;li&gt;PHP&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Web design&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Een ander goede bron is &lt;a href="http://en.csharp-online.net/CSharp_and_Visual_CSharp_Development"&gt;&lt;strong&gt;C# Online&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Als je, net zoals ik, leergierig bent en geinteresserd in programmeren,&lt;br /&gt;maar het moe bent van de zoveelste "Hello World" te doornemen, zijn deze websites de moeite waard om uit te checken.&lt;br /&gt;&lt;br /&gt;Veel leerplezier :)&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-4827669476766694011?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/4827669476766694011/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/12/online-cursussen-programmeren.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/4827669476766694011'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/4827669476766694011'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/12/online-cursussen-programmeren.html' title='Online cursussen Programmeren.'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-1227604459466762157</id><published>2010-11-17T15:35:00.004+01:00</published><updated>2010-11-17T15:56:44.023+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Anti Malware Help</title><content type='html'>Regelmatig wordt de website &lt;a href="http://www.emphyrio.be/index.html"&gt;&lt;strong&gt;Anti Malware Help&lt;/strong&gt;&lt;/a&gt; bijgewerkt en nieuwe onderwerpen toegevoegd.&lt;br /&gt;&lt;br /&gt;De nieuwe onderwerpen die onlangs zijn toegevoegd noemen :&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a class="menu" title="Verwijderen van Rogues" href="http://www.emphyrio.be/rogues.html" target="_blank"&gt;Verwijder rogues&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Met voorlopig &lt;em&gt;Security Tools&lt;/em&gt;, &lt;em&gt;Think Point&lt;/em&gt; en &lt;em&gt;Security Suit&lt;/em&gt;.&lt;br /&gt;Dagelijks duiken er wel nieuwe Rogues (valse anti malware tools) op.&lt;br /&gt;Diegene die op de website behandelt worden, zijn de meest actuele in de regio.&lt;br /&gt;&lt;br /&gt;Als er nieuwe ontwikkelingen zijn op dit gebied, wordt hierop ingespeelt.&lt;br /&gt;Op deze manier trachten we de slachtoffers zo snel en acuraat mogelijk te helpen.&lt;br /&gt;&lt;br /&gt;De richtlijnen worden in het nederlands geschreven.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="menu" title="Compatibiliteits lijst" href="http://www.emphyrio.be/compatibiliteit.html" target="_blank"&gt;Compatibiliteit&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In deze rubriek trachten we de vraag te beantwoorden : Welk tool op welk systeem, 32 en 64 bits.&lt;br /&gt;Niet zo eenvoudig te achterhalen soms, maar we doen ons best.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="menu" title="ShieldsUp" href="https://www.grc.com/x/ne.dll?bh0bkyd2" target="_blank"&gt;ShieldsUp&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Doet je firewall wat hij moet doen?&lt;br /&gt;Ben je voldoende afgeschermd tegen binnenkomende aanvallen?&lt;br /&gt;Bij &lt;strong&gt;ShieldsUp&lt;/strong&gt; krijg je hierop een betrouwbaar antwoord.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="menu" title="herstelpunten" href="http://www.emphyrio.be/herstelpunt.html" target="_self"&gt;Herstelpunten opruimen&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Wanneer een systeem niet naar behoren functioneert, is dit een van de eerste handelingen:&lt;br /&gt;Het terugzetten naar een vorig systeemherstelpunt.&lt;br /&gt;&lt;br /&gt;Hier worden de werkwijze voor de verschillende &lt;em&gt;Operating Systemen&lt;/em&gt; uitgelegd.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Op dit moment wordt er hard gewerkt om de site eveneens in het Engels beschikbaar te maken.&lt;/p&gt;&lt;p&gt;Emphyrio :)&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-1227604459466762157?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/1227604459466762157/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/11/anti-malware-help.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/1227604459466762157'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/1227604459466762157'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/11/anti-malware-help.html' title='Anti Malware Help'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-4324809075363678009</id><published>2010-10-24T01:20:00.003+02:00</published><updated>2010-10-24T01:24:43.618+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Facebook applicaties sturen privé-informatie door</title><content type='html'>Uit een onderzoek van de Amerikaanse zakenkrant &lt;a class="bbc_url" href="http://online.wsj.com/article/SB10001424052702304772804575558484075236968.html" rel="external" target="_blank"&gt;The Wall Street Journal&lt;/a&gt; blijkt dat een groot aantal Facebook-applicaties persoonlijke informatie van de Facebook-gebruiker doorstuurt naar online adverteerders en bedrijven.&lt;br /&gt;&lt;br /&gt;Volgens &lt;em&gt;The Wallstreet Journal&lt;/em&gt; zou het gaan om miljoenen gebruikers.&lt;br /&gt;Zelfs van de gebruikers die hun account deels privé hebben ingesteld, zou informatie doorgestuurd zijn door veel applicaties.&lt;br /&gt;&lt;br /&gt;De applicaties op &lt;em&gt;Facebook&lt;/em&gt;, waaronder ook het populaire &lt;strong&gt;Farmville&lt;/strong&gt;, maken gebruik van een identificatienummer voor iedere gebruiker.&lt;br /&gt;Hierdoor kan informatie van de gebruiker en diens vrienden makkelijk worden verzameld.&lt;br /&gt;Het identificatienummer is eigenlijk bedoeld om de gegevens voor andere gebruikers zichtbaar te maken.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Facebook &lt;/em&gt;vermeldt dat ze het probleem momenteel proberen op te lossen.&lt;br /&gt;Daarnaast laat de netwerksite weten dat ze de verspreiding van privégegevens proberen te verkleinen.&lt;br /&gt;&lt;br /&gt;We volgen dit met de grootste belangstelling.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;Bron :&lt;/span&gt;&lt;a href="http://www.techzine.nl/nieuws/24308/facebook-applicaties-sturen-prive-informatie-door.html"&gt;&lt;span style="font-size:78%;"&gt; Techzine&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-4324809075363678009?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/4324809075363678009/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/10/facebook-applicaties-sturen-prive.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/4324809075363678009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/4324809075363678009'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/10/facebook-applicaties-sturen-prive.html' title='Facebook applicaties sturen privé-informatie door'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-6174225136260597518</id><published>2010-09-15T20:37:00.018+02:00</published><updated>2010-09-15T22:27:25.105+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Englisch'/><title type='text'>HJT Analyst, something for You?</title><content type='html'>&lt;p&gt;Often I am getting the question dropped : How do I become a Hijackthis Analyst?&lt;br /&gt;The answer to this question isn't gonna be a quicky one.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Prologue&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Actually the term "Hijackthis Analyst" is old fashion and is from the days that most malware could be identified and solved by use of the Hijackthis tool &lt;span style="font-size:85%;"&gt;(original written by Merijn)&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;"Anti Malware Analyst" is a more up to date and accurate discription.&lt;br /&gt;&lt;br /&gt;Today we are confronted with root/boot kits (often the result of exploit abuse) and therefore it's necessary to make use of alternative tools.&lt;br /&gt;&lt;br /&gt;Combofix (sUBs), DDS (sUBs), OTL (Old Timer), Gmer (Gmer), The Avenger (Swandog46) are the most used nowadays.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Function Discription&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Solving a malware problem, posted by the Topic starter (TS).&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Analyse and interpreting of logs posted by the TS or on request of the analyst.&lt;/li&gt;&lt;/ul&gt;This forms the base on writting a fix and solving the problem.&lt;br /&gt;&lt;br /&gt;Solving a malware problem is done in 4 steps:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;br /&gt;&lt;li&gt;Analyze / diagnose: Recognize the symptoms and the malware involved.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Treatment: Writing of the fix.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Prognose: Expected result.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Feedback: Evaluate and adjust the treatment.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Kwalifications&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Know how to read !!!&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Maturity&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Inquisitive&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Knowledge of Windows Operating System and his Registery.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;DOS (batch) knowledge.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Stress resistant&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Persistence &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Courses&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nederlands / Dutch : &lt;a href="http://www.hijackthis.nl/forum/"&gt;Hijackthis.nl&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;English / Engels: &lt;a href="http://www.bleepingcomputer.com/forums/"&gt;Bleeping Computer&lt;/a&gt;, &lt;a href="http://www.spywareinfoforum.com/index.php?act=idx?s=ead6647122ddc12136ad95d05f788e5a"&gt;SWI&lt;/a&gt; and &lt;a href="http://www.geekstogo.com/forum/forums.html"&gt;Geekstogo&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Conclusion&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Solving a malware problem is a very intensive job that could take up a lot of time.&lt;br /&gt;&lt;br /&gt;Even more time then you expected.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The difference between a Analyst and a &lt;strong&gt;good&lt;/strong&gt; Analyst is the knowlegde you gathered and the efficiency to use that knowledge to solve the problem.&lt;br /&gt;&lt;br /&gt;The reward is the intellectual victory you get and, not in the least, the gratitude of the Topic Starter.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Emphyrio :)&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-6174225136260597518?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/6174225136260597518/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/09/hjt-analyst-something-for-you.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6174225136260597518'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6174225136260597518'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/09/hjt-analyst-something-for-you.html' title='HJT Analyst, something for You?'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-764159673218800148</id><published>2010-08-17T14:48:00.005+02:00</published><updated>2010-08-17T14:53:18.441+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>MBAM manueel updaten</title><content type='html'>Indien je géén internetverbinding hebt en je beschikt over een andere PC die wél internet heeft, kan je MBAM alsvolgt updaten :&lt;br /&gt;&lt;br /&gt;Eerst op BEIDE PC's je &lt;a href="http://www.nucia.nl/forum/showthread.php?t=21313"&gt;verborgen bestanden en mappen&lt;/a&gt; weergeven.&lt;br /&gt;&lt;br /&gt;Op de PC mét internet update je MBAM.&lt;br /&gt;Kopieer volgend bestand eveneens op je USB stick of CD:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Windows XP en 2000 :&lt;br /&gt;C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\&lt;strong&gt;rules.ref&lt;/strong&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Windows Vista en Wndows 7 :&lt;br /&gt;C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\&lt;strong&gt;rules.ref&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;Zet MBAM eveneens op deze USB flashdrive of CD en installeer deze op je andere PC.&lt;br /&gt;Zet rules.ref vanaf je USB stick in de juiste map.&lt;br /&gt;Start MBAM.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-764159673218800148?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/764159673218800148/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/08/mbam-manueel-updaten.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/764159673218800148'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/764159673218800148'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/08/mbam-manueel-updaten.html' title='MBAM manueel updaten'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-5927843594583248430</id><published>2010-08-17T14:02:00.031+02:00</published><updated>2010-11-29T03:28:19.467+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>Security Suite verwijderen.</title><content type='html'>Voer exact de procedure uit zoals beschreven staat.&lt;br /&gt;Indien je Vista hebt, alles uitvoeren als administrator........&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;De mogelijkheid bestaat dat de infectie je niet toelaat om bestanden te downloaden.&lt;br /&gt;Als dit het geval is dan moet je de nodige (en opgesomde tools) van een ander PC downloaden.&lt;br /&gt;Hiervoor kan je CD/DVD, externe HD of een USB stick gebruiken.&lt;br /&gt;&lt;br /&gt;Om MBAM geupdate te plaatsen op je PC, volg je &lt;a href="http://antimalwarehelp.blogspot.com/2010/08/mbam-manueel-updaten.html"&gt;deze volgende instructies&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Symptomen in Hijackthis:&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;O4 - HKLM\..\Run: [&lt;random&gt;] C:\Documents and Settings\Bleeping\Local Settings\Application Data\*random*\*random*shdw.exe&lt;br /&gt;O4 - HKCU\..\Run: [&lt;random&gt;] C:\Documents and Settings\Bleeping\Local Settings\Application Data\*random*\*random*shdw.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;STAP 1&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Start je PC op in &lt;a href="http://www.nucia.nl/forum/showthread.php?t=21312"&gt;Veilige Modus met Netwerkverbinding&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;STAP 2&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;ul&gt;&lt;li&gt;Open IE&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Ga naar Extra &gt; Internetopties &gt; Tabblad &lt;em&gt;Verbindingen&lt;/em&gt;.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Klik op &lt;em&gt;LAN-instellingen&lt;/em&gt;.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Onder &lt;em&gt;Automatische configuratie&lt;/em&gt; moet enkel &lt;em&gt;Instellingen automatisch detecteren&lt;/em&gt; aan staan.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Onder &lt;em&gt;Proxyserver&lt;/em&gt; mag er &lt;strong&gt;niets&lt;/strong&gt; aangevinkt zijn.&lt;/li&gt;&lt;br /&gt;&lt;/span&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Sluiten door OK &gt; Toepassen &gt; OK&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;STAP 3&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Eerst moeten we de processen van &lt;em&gt;Security Suite&lt;/em&gt; stoppen.&lt;br /&gt;Dit doen we door gebruik te maken van het tool : &lt;strong&gt;rkill.com&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Download &lt;a href="http://download.bleepingcomputer.com/grinler/rkill.com"&gt;rkill.com &lt;/a&gt;naar je bureaublad en dubbelklik erop. Dit zal de processen stoppen.&lt;br /&gt;Wees geduldig want dit kan een beetje tijd in beslag nemen.&lt;br /&gt;&lt;br /&gt;Wanneer je tijdens deze procedure een boodschap mocht krijgen dat rkill.com een infectie is, schrik dan niet en negeer dit gewoon.&lt;br /&gt;Het is namelijk een vals alarm van Security Suite.&lt;br /&gt;&lt;br /&gt;Wanneer je hiermee problemen blijft houden , download dan &lt;a href="http://download.bleepingcomputer.com/grinler/iExplore.exe"&gt;iExplorer.exe &lt;/a&gt;(hernoemde rkill.com) en probeer deze dan.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;ZEER BELANGRIJK !!!! Herstart je PC niet na het uitvoeren van rkill.com&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;STAP 4&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Download &lt;a href="http://www.besttechie.net/mbam/mbam-setup.exe"&gt;MalwareBytes' Anti-Malware &lt;/a&gt;en sla het op je bureaublad op.&lt;br /&gt;Dubbelklik op mbam-setup.exe om het programma te installeren.&lt;br /&gt;&lt;br /&gt;Zorg dat er na de installatie een vinkje is geplaatst bij:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;ul&gt;&lt;li&gt;Update MalwareBytes' Anti-Malware&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Start MalwareBytes' Anti-Malware&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Klik daarna op "Voltooien".&lt;br /&gt;Indien een update gevonden wordt, zal die gedownload en geïnstalleerd worden.&lt;br /&gt;&lt;br /&gt;Zodra het programma gestart is ga je naar het tabblad "Instellingen".&lt;br /&gt;Vink hier aan: "Sluit Internet Explorer tijdens verwijdering van malware".&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Ga naar het tabblad "Updates" en Update MBAM.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Ga daarna naar het tabblad "Scanner", kies hier voor "Volledige Scan".&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Druk vervolgens op "Scannen" om de scan te starten.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Het scannen kan een tijdje duren, dus wees geduldig.&lt;br /&gt;Wanneer de scan voltooid is, klik op OK, daarna "Bekijk Resultaten" om de resultaten te zien.&lt;br /&gt;Zorg ervoor dat daar alles aangevinkt is.&lt;br /&gt;Klik vervolgens op: "Verwijder geselecteerde".&lt;br /&gt;&lt;br /&gt;Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten.&lt;br /&gt;&lt;br /&gt;Indien MBAM vraagt om een herstart, doe dit dan ook.&lt;br /&gt;&lt;br /&gt;Het log wordt automatisch bewaard door MalwareBytes' Anti-Malware en kan je terugvinden door op de "Logs" tab te klikken in het programma.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;STAP 5&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Deze infectie gaat gewoonlijk samen met een TDL3 infectie.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Download &lt;a href="http://support.kaspersky.com/downloads/utils/tdsskiller.zip"&gt;TDSSKiller&lt;/a&gt; en plaats het op je bureaublad.&lt;br /&gt;Pak de bestanden in &lt;em&gt;tdsskiller.zip&lt;/em&gt; uit.&lt;br /&gt;Open de map &lt;em&gt;tdsskiller&lt;/em&gt; en dubbelklik op &lt;em&gt;TDSSKiller.exe&lt;/em&gt; om de tool te starten.&lt;br /&gt;Klik op de knop "Start Scan" en volg de instructies.&lt;br /&gt;&lt;br /&gt;Als er een Reboot (herstart) wordt gevraagt, dan klik je op &lt;em&gt;Reboot Now&lt;/em&gt;.&lt;br /&gt;Anders klik je op &lt;em&gt;Report&lt;/em&gt;.&lt;br /&gt;Kopiëer en bewaar de logfile die tevoorschijn komt.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Opmerking:&lt;br /&gt;&lt;br /&gt;Wanneer er een herstart nodig was, vind je de logfile in C:\TDSSKiller.[Version]_[Date]_[Time]_log.txt&lt;/em&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-5927843594583248430?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/5927843594583248430/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/08/voer-exact-de-procedure-uit-zoals.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5927843594583248430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5927843594583248430'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/08/voer-exact-de-procedure-uit-zoals.html' title='Security Suite verwijderen.'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-6200859921876616670</id><published>2010-08-09T21:35:00.002+02:00</published><updated>2010-08-09T21:37:45.389+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Mivercon Security Forum</title><content type='html'>&lt;strong&gt;Blue Medicine&lt;/strong&gt; heet voortaan &lt;strong&gt;&lt;a href="http://www.mivercon.be/forum/index.php"&gt;Mivercon Security Forum&lt;/a&gt;&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;Het vroegere forum heeft enkel een andere naam en domein gekregen.&lt;br /&gt;De service is het zelfde.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-6200859921876616670?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/6200859921876616670/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/08/mivercon-security-forum.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6200859921876616670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6200859921876616670'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/08/mivercon-security-forum.html' title='Mivercon Security Forum'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-6998381089613784141</id><published>2010-07-25T15:23:00.019+02:00</published><updated>2010-08-13T15:41:49.346+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>Antivir Solution Pro verwijderen.</title><content type='html'>Antivir Solution Pro is een &lt;em&gt;Rogue&lt;/em&gt;. Een "vals" antivirustool dus.&lt;br /&gt;&lt;br /&gt;In een Hijackthis log zijn er de volgende symptomen te zien :&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5643&lt;br /&gt;O4 - HKLM\..\Run: [] %UserProfile%\local settings\application data\\.exe&lt;br /&gt;O4 - HKCU\..\Run: [] %UserProfile%\local settings\application data\\.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;De oplossing:&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Deze lijn mag je fixen in Hijackthis :&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:78%;"&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5643 &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Vervolgens:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Open IE&lt;br /&gt;Ga naar Extra &gt; Internetopties &gt; Tabblad &lt;em&gt;Verbindingen&lt;/em&gt;.&lt;br /&gt;Klik op &lt;em&gt;LAN-instellingen&lt;/em&gt;.&lt;br /&gt;Onder &lt;em&gt;Automatische configuratie&lt;/em&gt; moet enkel &lt;em&gt;Instellingen automatisch detecteren&lt;/em&gt; aan staan.&lt;br /&gt;Onder &lt;em&gt;Proxyserver&lt;/em&gt; mag er &lt;strong&gt;niets&lt;/strong&gt; aangevinkt zijn.&lt;br /&gt;Sluiten door OK &gt; Toepassen &gt; OK&lt;br /&gt;Herstart je PC..&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Download &lt;a href="http://www.besttechie.net/mbam/mbam-setup.exe"&gt;MalwareBytes' Anti-Malware&lt;/a&gt; en sla het op je bureaublad op.&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Start je PC op in &lt;strong&gt;&lt;a href="http://www.nucia.nl/forum/showthread.php?t=21312"&gt;Veilige Modus&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Eénmaal in &lt;em&gt;Veilige Modus&lt;/em&gt;, voer je het volgende uit:&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Dubbelklik op &lt;strong&gt;mbam-setup.exe&lt;/strong&gt; om het programma te installeren.&lt;br /&gt;Ga nu naar de Program Files\&lt;strong&gt;Malwarebytes' Antimalware&lt;/strong&gt; map.&lt;br /&gt;Selecteer de &lt;strong&gt;mbam.exe&lt;/strong&gt; file.&lt;br /&gt;Hernoem deze naar &lt;strong&gt;iexplore.exe&lt;br /&gt;&lt;/strong&gt;Maak een snelkoppeling en plaats deze op je bureaublad.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Herstart je PC in &lt;strong&gt;Normale Modus&lt;/strong&gt;.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;In normale modus doe je het volgende:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Dubbelklik op iexplore.exe (&lt;= de hernoemde mbam.exe)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Als MBAM opent UPDATE je MBAM via Update tab &gt; Check for updates.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Vervolgens selecteer je de snelle scan en klik je op &lt;em&gt;Scan&lt;/em&gt;&lt;/li&gt;.&lt;br /&gt;&lt;li&gt;Als de scan gedaan is, klik je op &lt;em&gt;OK&lt;/em&gt; en &lt;em&gt;Show Results&lt;/em&gt;&lt;/li&gt;.&lt;br /&gt;&lt;li&gt;Vergewis je ervan dat alle items geselecteert zijn en klik op &lt;em&gt;Remove Selected&lt;/em&gt;&lt;/li&gt;.&lt;br /&gt;&lt;li&gt;Herstart je PC indien MBAM hierom vraagt.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Als alles uitgevoerd is, zal er een log tevoorschijn komen.&lt;br /&gt;Bewaar deze log.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Hernoem&lt;strong&gt; iexplore.exe&lt;/strong&gt; (uit de Program Files\&lt;em&gt;Malwarebytes' Antimalware&lt;/em&gt; map) terug naar &lt;strong&gt;mbam.exe&lt;/strong&gt; en verwijder de snelkoppeling van je bureaublad.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Emphyrio :)&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-6998381089613784141?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/6998381089613784141/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/07/antivir-solution-pro-verwijderen.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6998381089613784141'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6998381089613784141'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/07/antivir-solution-pro-verwijderen.html' title='Antivir Solution Pro verwijderen.'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-7574969829873993612</id><published>2010-06-28T05:07:00.013+02:00</published><updated>2010-06-28T05:39:14.604+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>Een "verdwenen" partitie herstellen.</title><content type='html'>&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Door een wispelturige gril van Windows, was ik een partitie kwijtgeraakt.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Mijn Backup partitie van 283 Gb nog wel.&lt;br /&gt;Tijd om opzoek te gaan naar een gratis recoverytool dus.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Eerst had ik &lt;a href="http://www.findandmount.com/"&gt;Partition Find and Mount 2.31&lt;/a&gt; gedownload.&lt;br /&gt;De &lt;em&gt;free to use&lt;/em&gt; versie natuurlijk.&lt;br /&gt;&lt;br /&gt;Nadat ik de noodzakelijke scan opties had ingesteld ( Thorough), vond deze tool een aantal verloren gewaande partities.&lt;br /&gt;&lt;br /&gt;De partitie die ik moest zien te recupereren bedroeg 283 Gb.&lt;br /&gt;Het terugzetten van een directorie van 40 Gb duurde 24 uur.&lt;br /&gt;&lt;br /&gt;Met 283 Gb te herstellen had ik dus enkele dagen te gaan.&lt;br /&gt;Dit duurde me té lang.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Vervolgens &lt;a href="http://tokiwa.qee.jp/EN/PartitionRecovery/PartitionRecoveryEN.zip"&gt;PartitionRecovery 1.0&lt;/a&gt; ontdekt.&lt;br /&gt;Klein, gratis en vereist geen install.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Unzippen en klikken op PartitionRecovery.exe.&lt;br /&gt;Vervolgens klik je in het vakje waar de partitie zich zou moeten bevinden.&lt;br /&gt;Klikken op &lt;em&gt;Restore&lt;/em&gt; en ....pats !!!&lt;/p&gt;&lt;br /&gt;&lt;p&gt;In minder dan één seconde was mijn partitie hersteld.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Prachtig.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;a href="http://www.emphyrio.be/images/PartitionRecovery.png"&gt;&lt;img style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 562px; CURSOR: hand; HEIGHT: 330px; TEXT-ALIGN: center" alt="" src="http://www.emphyrio.be/images/PartitionRecovery.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="color:#ff0000;"&gt;Toch nog even een belangrijke waarschuwing :&lt;/span&gt;&lt;/strong&gt; &lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Als dit je ooit voorvalt (een verdwenen partitie) ga dan niet zitten te experimenteren.&lt;br /&gt;En al zeker niet een extra of nieuwe partitie aanmaken.&lt;br /&gt;&lt;br /&gt;Wanneer je dat doet, is er géén hoop tot recovery (herstel) meer.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-7574969829873993612?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/7574969829873993612/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/06/een-partitie-herstellen.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/7574969829873993612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/7574969829873993612'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/06/een-partitie-herstellen.html' title='Een &quot;verdwenen&quot; partitie herstellen.'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-1790517219420944682</id><published>2010-06-27T18:48:00.011+02:00</published><updated>2010-09-21T22:42:22.292+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Englisch'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>Whistler Bootkit (English)</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Update:&lt;/strong&gt; Combofix removes this infection.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;Use Combofix only in collaboration with a &lt;em&gt;Qualified Helper&lt;/em&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Please bare in mind that following instructions is for &lt;em&gt;Qualified Helpers&lt;/em&gt;.&lt;br /&gt;If You are not, take counseling at one of the Hijackthis fora.&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Don't try this fix if Your system has a factory MBR or Multiboot.&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Not long ago I came across the &lt;strong&gt;Whistler Bootkit&lt;/strong&gt; in a Hijackthis log.&lt;br /&gt;&lt;br /&gt;This very aggresieve malware takes over the PC.&lt;br /&gt;Gmer, The Avenger 2, Combofix,.. didn't give any solution.&lt;br /&gt;Nor did a System Recovery !&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Next symptoms are visible:&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Kaspersky :&lt;br /&gt;&lt;br /&gt;&lt;em&gt;HEUR: Trojan.Win32.Generic in de C:\System Volume Information folder&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Dr Web :&lt;br /&gt;&lt;br /&gt;&lt;em&gt;smss.exe C:\System Volume Information\Whistler Win32.HLLC.Asdas.8 No recovery.Replaced&lt;/em&gt;&lt;br /&gt;&lt;em&gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;svchost.exe C:\System Volume Information\Whistler Win32.HLLC.Asdas.8 No recovery.Replaced&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;In Hijackthis, one can notice the following:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;&lt;br /&gt;C:\System Volume Information\Whistler\svchost.exe&lt;br /&gt;C:\System Volume Information\Whistler\smss.exe&lt;br /&gt;&lt;br /&gt;or after a system recovery :&lt;br /&gt;&lt;br /&gt;C:\System Volume Information\_restore{d5fffa500b1b}\svchost.exe&lt;br /&gt;C:\System Volume Information\_restore{d5fffa500b1b}\smss.exe&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Combofix shows us :&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;------------------------ Other active processes------------------------&lt;/em&gt;&lt;br /&gt;&lt;em&gt;c:\system volume information\_restore{d5fffa500b1b}\svchost.exe&lt;/em&gt;&lt;br /&gt;&lt;em&gt;c:\system volume information\_restore{d5fffa500b1b}\smss.exe&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;(or C:\System Volume Information\Whistler\svchost.exe&lt;br /&gt;C:\System Volume Information\Whistler\smss.exe )&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;The Startup list of Hijackthis shows the following (if systemrecovery was used)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Windows NT 'Wininit.ini' :&lt;br /&gt;&lt;br /&gt;PendingFileRenameOperations: C:\System Volume Information\_restore{d5fffa500b1b}\svchost.exeC:\System Volume Information\_restore{d5fffa500b1b}\smss.exeC:\System Volume Information\_restore{d5fffa500b1b}\SMSS.EXEC:\System Volume Information\_restore{d5fffa500b1b}\SVCHOST.EXE&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The &lt;strong&gt;PendingFileRenameOperations&lt;/strong&gt; value under [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] &lt;strong&gt;wasn't&lt;/strong&gt; present.&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Combofix&lt;/strong&gt; en &lt;strong&gt;The Avenger&lt;/strong&gt; deletes the two files, but after a reboot they immediately came back..&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Identification:&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Intensive search on Google learns me that I have to deal with a &lt;a href="http://blog.novirusthanks.org/2010/02/whistler-bootkit-a-new-powerful-windows-bootkit/"&gt;Whistler Bootkit&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;&lt;strong&gt;The solution:&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Because this one hides himself in the bootsector , speed and accuracy is of the most importance.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Step 1&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Downloadt &lt;a href="http://www.esagelab.com/files/bootkit_remover.rar"&gt;bootkit_remover.rar&lt;/a&gt; (&lt;a href="http://www.esagelab.com/resources.php?s=bootkit_remover"&gt;&lt;span style="COLOR: rgb(51,102,255)"&gt;INFO&lt;/span&gt;&lt;/a&gt;)&lt;br /&gt;Unzip the file.&lt;br /&gt;Open the directory map bootkitremover en double click on remover.exe.&lt;br /&gt;Post whats appears on the screen. (copy &amp;amp; paste)&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Step 2&lt;/em&gt;&lt;br /&gt;&lt;em&gt;&lt;/em&gt;&lt;br /&gt;A infected bootsector looks like this:&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;span style="font-size:85%;"&gt;Bootkit Remover version 1.0.0.1&lt;br /&gt;(c) 2009 eSage Lab&lt;br /&gt;http://www.esagelab.com/&lt;br /&gt;\\.\C: -&gt;&lt;br /&gt;\\.\PhysicalDrive0&lt;br /&gt;MD5: 274955059efe9236c07688c5ff9242b2&lt;br /&gt;Size Device&lt;br /&gt;Name MBR Status&lt;br /&gt;--------------------------------------------&lt;br /&gt;74 GB&lt;br /&gt;\\.\PhysicalDrive0 Unknown boot code&lt;br /&gt;&lt;br /&gt;Unknown boot code has been found on&lt;br /&gt;some of your physical disks.&lt;br /&gt;To inspect the boot code manually, dump the&lt;br /&gt;master boot sector:remover.exe dump &lt;device_name&gt;[output_file]&lt;br /&gt;To disinfect&lt;br /&gt;the master boot sector, use the following command:remover.exe fix&lt;/device_name&gt;&lt;/span&gt; &lt;device_name&gt;&lt;br /&gt;&lt;/device_name&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;This line gets my immediately attention : &lt;strong&gt;&lt;span style="COLOR: rgb(255,0,0)"&gt;\\.\PhysicalDrive0&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Before moving on with the repair, doublecheck this with MBRcheck:&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Download &lt;a href="http://ad13.geekstogo.com/MBRCheck.exe"&gt;MBRCheck.exe&lt;/a&gt; towards your desktop.&lt;br /&gt;Dblclick MBRCheck.exe.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If You get a message rapport, typ N and Enter.&lt;br /&gt;Enter again.&lt;br /&gt;&lt;br /&gt;On your desktop You will find MBRCheck_mm.dd.yy_hh.mm.ss .&lt;br /&gt;&lt;br /&gt;If it look something like this :&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;\\.\C: --&gt; \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)&lt;br /&gt;&lt;br /&gt;PhysicalDrive0 Model Number: MAXTORSTM380815AS, Rev: 3.AAD&lt;br /&gt;&lt;br /&gt;Size Device Name MBR Status&lt;br /&gt;--------------------------------------------&lt;br /&gt;74 GB \\.\PhysicalDrive0 Windows XP MBR code detected&lt;br /&gt;SHA1: F238F1FE114296B6DC7716517DC1DADB3FF3D5C6&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Done! &lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Then we are done !&lt;br /&gt;&lt;br /&gt;Else, follow the next instructions.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We remove this by writing a batch with a switch for remover.exe :&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;@ECHO OFF&lt;br /&gt;START remover.exe fix \\.\PhysicalDrive0&lt;br /&gt;EXIT&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;By executing this batch, the PC has to reboot &lt;strong&gt;immediately&lt;/strong&gt;.&lt;br /&gt;Its is very important that the TS does this because of the possibility of reinfection.&lt;br /&gt;&lt;br /&gt;One can also implement the DOS command &lt;strong&gt;SHUTDOWN -r&lt;/strong&gt; into the batch:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;@ECHO OFF&lt;br /&gt;START remover.exe fix \\.\PhysicalDrive0&lt;br /&gt;SHUTDOWN -r&lt;br /&gt;EXIT&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;After a reboot, ask the TS to run remover.exe again and let him post the remover.exe log.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If everything was going ok, the log must look like this:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Bootkit Remover version 1.0.0.1&lt;br /&gt;(c) 2009 eSage Lab&lt;br /&gt;http://www.esagelab.com&lt;br /&gt;&lt;br /&gt;\\.\C: -&gt; \\.\PhysicalDrive0&lt;br /&gt;MD5: 6def5ffcbcdbdb4082f1015625e597bd&lt;br /&gt;&lt;br /&gt;Size Device Name MBR Status&lt;br /&gt;--------------------------------------------&lt;br /&gt;74 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found) &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Double check it with Gmer and Hijackthis.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="COLOR: rgb(255,0,0)"&gt;Its recommended to let the TS change his passwords.&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Emphyrio :)&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="font-size:85%;"&gt;Thanks to &lt;a href="http://users.telenet.be/marcvn/spyware/1103093.htm"&gt;&lt;span style="font-size:100%;"&gt;Marckie&lt;/span&gt;&lt;/a&gt; for support me with this difficult infection .&lt;/span&gt;&lt;/em&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-1790517219420944682?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/1790517219420944682/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/06/whistler-bootkit-english.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/1790517219420944682'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/1790517219420944682'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/06/whistler-bootkit-english.html' title='Whistler Bootkit (English)'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-4638851061588647039</id><published>2010-06-22T16:19:00.048+02:00</published><updated>2011-02-08T18:41:41.296+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><category scheme='http://www.blogger.com/atom/ns#' term='Varia'/><title type='text'>HJT Analyst, iets voor jou ?</title><content type='html'>Regelmatig krijg ik de vraag te horen "hoe je een &lt;strong&gt;Hijackthis Analyst&lt;/strong&gt; wordt".&lt;br /&gt;Deze vraag is niet in één-twee-drie te beantwoorden en hangt van een paar factoren af.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Inleiding&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Eigenlijk is de term "&lt;em&gt;Hijackthis Analyst&lt;/em&gt;" voorbijgestreeft en is "&lt;em&gt;Anti Malware Analyst&lt;/em&gt;" meer up-to-date.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Hijackthis Analyst&lt;/em&gt; stamt nog uit de tijd dat de meeste malware met het &lt;em&gt;Hijackthis tool&lt;/em&gt; nog te identificeren en te &lt;em&gt;fixen&lt;/em&gt; was.&lt;br /&gt;&lt;br /&gt;De dag van vandaag is dit niet meer waar.&lt;br /&gt;&lt;br /&gt;Rootkits, bootkits (dikwijls het gevolg/misbruik van exploits),... maken het noodzakelijk naar andere analyse tools te grijpen.&lt;br /&gt;&lt;br /&gt;Combofix &lt;em&gt;&lt;span style="font-size:85%;"&gt;(sUBs)&lt;/span&gt;&lt;/em&gt;, DDS &lt;em&gt;&lt;span style="font-size:85%;"&gt;(sUBs)&lt;/span&gt;&lt;/em&gt;, OTL &lt;em&gt;&lt;span style="font-size:85%;"&gt;(Old Timer)&lt;/span&gt;&lt;/em&gt;, Gmer &lt;em&gt;&lt;span style="font-size:85%;"&gt;(Gmer)&lt;/span&gt;&lt;/em&gt;, The Avenger &lt;em&gt;&lt;span style="font-size:85%;"&gt;(Swandog46)&lt;/span&gt;&lt;/em&gt; om de meest gebruikte maar eens op te noemen.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Functie omschrijving&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Het oplossen van een malware probleem gepost door een topicstarter (TS).&lt;br /&gt;&lt;br /&gt;Analyzeren en interpreteren van logs gepost door de topicstarter of op aanvraag van de analyst .&lt;br /&gt;Op deze basis wordt dan een fix geschreven.&lt;br /&gt;&lt;br /&gt;Het oplossen van een malware probleem gebeurt in de volgende stappen:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;br /&gt;&lt;li&gt;Analyze / diagnose: &lt;em&gt;&lt;span style="color:#ffffcc;"&gt;Het herkennen van symptomen en malware&lt;/span&gt;&lt;/em&gt;.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Behandeling: &lt;em&gt;&lt;span style="color:#ffffcc;"&gt;Het schrijven van de fix&lt;/span&gt;&lt;/em&gt;.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Prognose: &lt;em&gt;&lt;span style="color:#ffffcc;"&gt;Het te verwachten resultaat&lt;/span&gt;&lt;/em&gt;.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Feedback: &lt;em&gt;&lt;span style="color:#ffffcc;"&gt;Bijsturen van de behandeling&lt;/span&gt;&lt;/em&gt;.&lt;/li&gt;&lt;br /&gt;&lt;/ol&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Kwalificaties&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Kunnen lezen !&lt;br /&gt;Maturiteit.&lt;br /&gt;Leergierig.&lt;br /&gt;Kennis van Windows en zijn registers.&lt;br /&gt;Dos (batch) kennis.&lt;br /&gt;Kennis van de gebruikte tools.&lt;br /&gt;Kennis van beveiligingssoftware.&lt;br /&gt;Stressbestendig.&lt;br /&gt;Volharding.&lt;br /&gt;&lt;br /&gt;De kwalificaties die opgesomd worden zijn of aanwezig of aan te leren.&lt;br /&gt;Wanneer je Analist bent wordt verondersteld deze kwalificaties te bezitten.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Cursussen&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Nederlands: &lt;a href="http://www.hijackthis.nl/forum/"&gt;Hijackthis.nl&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Engels: &lt;a href="http://www.bleepingcomputer.com/forums/"&gt;Bleeping Computer&lt;/a&gt;, &lt;a href="http://www.spywareinfoforum.com/index.php?act=idx?s=ead6647122ddc12136ad95d05f788e5a"&gt;SWI&lt;/a&gt; en &lt;a href="http://www.geekstogo.com/forum/forums.html"&gt;Geekstogo&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Tot Slot....&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Het oplossen van malware problemen is een intensieve bezigheid dat wel eens meer tijd in beslag neemt dan je had verwacht.&lt;br /&gt;&lt;br /&gt;Het onderscheid tussen een analyst en een goede analyst, is de kennis die je hebt vergaard om malware een stap voor te zijn en de efficiëntie om het probleem tot een goed einde te brengen..&lt;br /&gt;&lt;br /&gt;De beloning is &lt;strong&gt;de intellectuele overwinning&lt;/strong&gt; dat je hebt behaald en, niet in het minst,&lt;br /&gt;de dankbaarheid van de topicstarter.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Emphyrio :)&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-4638851061588647039?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/4638851061588647039/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/06/hjt-analyst-iets-voor-mij.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/4638851061588647039'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/4638851061588647039'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/06/hjt-analyst-iets-voor-mij.html' title='HJT Analyst, iets voor jou ?'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-5880221482266655659</id><published>2010-05-21T13:26:00.029+02:00</published><updated>2011-01-30T02:56:13.949+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>Whistler Bootkit</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Update :&lt;/strong&gt; Deze infectie wordt verwijderdt door ComboFix.&lt;br /&gt;Het gebruik van Combofix kan je beter in samenwerking met een &lt;em&gt;Gekwalificeerd Helper doen&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;Zie de fora list, rechts.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;For the &lt;strong&gt;English version&lt;/strong&gt; of this explanation,&lt;a href="http://antimalwarehelp.blogspot.com/2010/06/whistler-bootkit-english.html"&gt;&lt;strong&gt;look here&lt;/strong&gt;&lt;/a&gt;.&lt;br /&gt;Don't use Google translation, its teribble.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;WAARSCHUWING&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Onderstaande is enkel geschikt voor Gekwalificeerde Helpers.&lt;br /&gt;Ga niet op je eentje zitten te fixen !!!&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Gebruik deze fix niet indien het gaat om een factory MBR of Multiboot.&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Onlangs ben ik tegen de &lt;strong&gt;Whistler Bootkit&lt;/strong&gt; gestoten in het behandelen van Hijackthis logs.&lt;br /&gt;&lt;br /&gt;Deze malware neemt aggresief en onmerkbaar bezit van je PC.&lt;br /&gt;Gmer, The Avenger 2, Combofix,.. het heeft niet mogen baten.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ff0000;"&gt;Een Systeem Herstel zal eveneens niet werken !&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Volgende symptomen zijn van toepassing:&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Kaspersky :&lt;br /&gt;&lt;br /&gt;&lt;em&gt;HEUR: Trojan.Win32.Generic in de C:\System Volume Information folder&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Dr Web :&lt;br /&gt;&lt;br /&gt;&lt;em&gt;smss.exe C:\System Volume Information\Whistler Win32.HLLC.Asdas.8 Niet repareerbaar.Verplaatst.&lt;/em&gt;&lt;br /&gt;&lt;em&gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;svchost.exe C:\System Volume Information\Whistler Win32.HLLC.Asdas.8 Niet repareerbaar.Verplaatst.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;In de Hijackthis logs is er het volgende merkbaar :&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;&lt;br /&gt;C:\System Volume Information\Whistler\svchost.exe&lt;br /&gt;C:\System Volume Information\Whistler\smss.exe&lt;br /&gt;&lt;br /&gt;of na een uitgevoerde Systeemherstel :&lt;br /&gt;&lt;br /&gt;C:\System Volume Information\_restore{d5fffa500b1b}\svchost.exe&lt;br /&gt;C:\System Volume Information\_restore{d5fffa500b1b}\smss.exe&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Combofix toont ons :&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;------------------------ Andere Aktieve Processen ------------------------&lt;/em&gt;&lt;br /&gt;&lt;em&gt;c:\system volume information\_restore{d5fffa500b1b}\svchost.exe&lt;/em&gt;&lt;br /&gt;&lt;em&gt;c:\system volume information\_restore{d5fffa500b1b}\smss.exe&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;De Startup List van Hijackthis laat ons volgende zien:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Windows NT 'Wininit.ini' :&lt;br /&gt;&lt;br /&gt;&lt;em&gt;PendingFileRenameOperations: C:\System Volume Information\_restore{d5fffa500b1b}\svchost.exeC:\System Volume Information\_restore{d5fffa500b1b}\smss.exeC:\System Volume Information\_restore{d5fffa500b1b}\SMSS.EXEC:\System Volume Information\_restore{d5fffa500b1b}\SVCHOST.EXE&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;De &lt;strong&gt;PendingFileRenameOperations&lt;/strong&gt; waarde onder [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] was &lt;strong&gt;niet&lt;/strong&gt; aanwezig.&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Combofix&lt;/strong&gt; en &lt;strong&gt;The Avenger&lt;/strong&gt; verwijderen wel de twee bestanden, maar deze komen na een reboot onmiddelijk terug.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Identificatie:&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Dieper en intesiever zoeken op Google leert me&lt;br /&gt;dat we hier te maken hebben met &lt;a href="http://blog.novirusthanks.org/2010/02/whistler-bootkit-a-new-powerful-windows-bootkit/"&gt;Whistler Bootkit&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;&lt;strong&gt;De oplossing:&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Vermits deze infectie zich nestelt in de bootsector, is snelheid en accuratie belangrijk.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Stap 1&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Downloadt &lt;a href="http://www.esagelab.com/files/bootkit_remover.rar"&gt;bootkit_remover.rar&lt;/a&gt; (&lt;a href="http://www.esagelab.com/resources.php?s=bootkit_remover"&gt;&lt;span style="color:#3366ff;"&gt;INFO&lt;/span&gt;&lt;/a&gt;)&lt;br /&gt;Unzip het.&lt;br /&gt;Open de map bootkit_remover en dubbelklik op remover.exe.&lt;br /&gt;Post even wat er in het scherm verschijnt.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Stap 2&lt;/em&gt;&lt;br /&gt;&lt;em&gt;&lt;/em&gt;&lt;br /&gt;Een geinfecteerde bootsector kan er alsvolgd uitzien:&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;span style="font-size:85%;"&gt;Bootkit Remover version 1.0.0.1&lt;br /&gt;(c) 2009 eSage Lab&lt;br /&gt;http://www.esagelab.com/&lt;br /&gt;\\.\C: -&gt;&lt;br /&gt;\\.\PhysicalDrive0&lt;br /&gt;MD5: 274955059efe9236c07688c5ff9242b2&lt;br /&gt;Size Device&lt;br /&gt;Name MBR Status&lt;br /&gt;--------------------------------------------&lt;br /&gt;74 GB&lt;br /&gt;\\.\PhysicalDrive0 Unknown boot code&lt;br /&gt;&lt;br /&gt;Unknown boot code has been found on&lt;br /&gt;some of your physical disks.&lt;br /&gt;To inspect the boot code manually, dump the&lt;br /&gt;master boot sector:remover.exe dump &lt;device_name&gt;[output_file]&lt;br /&gt;To disinfect&lt;br /&gt;the master boot sector, use the following command:remover.exe fix&lt;/span&gt; &lt;device_name&gt;&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Deze trekt meteen onze aandacht : &lt;strong&gt;&lt;span style="color:#ff0000;"&gt;\\.\PhysicalDrive0&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Voor de zekerheid even nachecken met MBRcheck:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Download &lt;a href="http://ad13.geekstogo.com/MBRCheck.exe"&gt;MBRCheck.exe&lt;/a&gt; naar je bureaublad.&lt;br /&gt;Dubbelklik op MBRCheck.exe om het programma te openen.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Als je een melding krijgt, typ dan op &lt;strong&gt;N&lt;/strong&gt; en druk op &lt;strong&gt;Enter&lt;/strong&gt;.&lt;br /&gt;Druk nogmaals op &lt;strong&gt;Enter&lt;/strong&gt;.&lt;br /&gt;Een kladblokbestand genaamd &lt;em&gt;MBRCheck_mm.dd.yy_hh.mm.ss &lt;/em&gt;zal op je bureaublad worden opgeslagen.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;\\.\C: --&gt; \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)&lt;br /&gt;&lt;br /&gt;PhysicalDrive0 Model Number: MAXTORSTM380815AS, Rev: 3.AAD&lt;br /&gt;&lt;br /&gt;Size Device Name MBR Status&lt;br /&gt;--------------------------------------------&lt;br /&gt;74 GB \\.\PhysicalDrive0 Windows XP MBR code detected&lt;br /&gt;SHA1: F238F1FE114296B6DC7716517DC1DADB3FF3D5C6&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Done! &lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Bovenstaande output is dus goed.&lt;br /&gt;Indien niet :&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We gaan deze verwijderen met een batch waarin we een switch voor remover.exe zetten:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;@ECHO OFF&lt;br /&gt;START remover.exe fix \\.\PhysicalDrive0&lt;br /&gt;EXIT&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Bij het uitvoeren van deze batch, moet de PC &lt;strong&gt;ONMIDDELLIJK&lt;/strong&gt; herstart worden.&lt;br /&gt;Dit is uitermate belangrijk, anders geven we de infectie de kans te herinitializeren.&lt;br /&gt;&lt;br /&gt;Je zou hier eveneens het DOS commando &lt;strong&gt;SHUTDOWN -r&lt;/strong&gt; in de batch kunnen implementeren.&lt;br /&gt;De batch wordt dan :&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;@ECHO OFF&lt;br /&gt;START remover.exe fix \\.\PhysicalDrive0&lt;br /&gt;SHUTDOWN -r&lt;br /&gt;EXIT&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Eveneens vragen we na een herstart om de remover.exe log.&lt;br /&gt;Je laat dus remover.exe, na de herstart, terug uitvoeren en vraagt om de output.&lt;br /&gt;&lt;br /&gt;Als alles goed is gegaan, krijg je dit :&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Bootkit Remover version 1.0.0.1&lt;br /&gt;(c) 2009 eSage Lab&lt;br /&gt;http://www.esagelab.com&lt;br /&gt;&lt;br /&gt;\\.\C: -&gt; \\.\PhysicalDrive0&lt;br /&gt;MD5: 6def5ffcbcdbdb4082f1015625e597bd&lt;br /&gt;&lt;br /&gt;Size Device Name MBR Status&lt;br /&gt;--------------------------------------------&lt;br /&gt;74 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found) &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Voor de zekerheid en ter controle, even nachecken met Gmer en Hijackthis.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ff0000;"&gt;Het is eveneens aan te raden de paswoorden te veranderen.&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Emphyrio :)&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="font-size:85%;"&gt;Met dank aan &lt;a href="http://users.telenet.be/marcvn/spyware/1103093.htm"&gt;&lt;span style="font-size:100%;"&gt;Marckie&lt;/span&gt;&lt;/a&gt; voor de ondersteuning in deze toch wel moeilijke infectie.&lt;/span&gt;&lt;/em&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-5880221482266655659?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/5880221482266655659/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/05/whistler-bootkit.html#comment-form' title='3 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5880221482266655659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5880221482266655659'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/05/whistler-bootkit.html' title='Whistler Bootkit'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-7358470145459430512</id><published>2010-04-22T22:54:00.005+02:00</published><updated>2010-04-23T17:56:24.431+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>Wereldwijd PC's onklaar door McAfee update</title><content type='html'>De zogenoemde &lt;em&gt;DAT update 5958.0000&lt;/em&gt; van McAfee Antivirus tool, zorgde ervoor dat het Windows Systeembestand &lt;strong&gt;svchost.exe&lt;/strong&gt; verkeerdelijk werdt aanzien als virus.&lt;br /&gt;&lt;br /&gt;Het gevolg is een onbruikbaar Operating Systeem waardoor je PC niet meer naar behoren functioneert.&lt;br /&gt;&lt;br /&gt;McAfee AV tool zet dit bestand (in het beste geval) in quarantine.&lt;br /&gt;Indien je nog in Windows geraakt, kan je dit best terugplaatsen.&lt;br /&gt;&lt;br /&gt;Ondertussen heeft McAfee ook &lt;a href="http://service.mcafee.com/faqdocument.aspx?id=TS100969&amp;amp;lang=en_US&amp;amp;prior_tid=2&amp;amp;AnswerID=16777216&amp;amp;turl==http%3A%2F%2Fkb.mcafee.com%2Finfocenter%2Findex%3Fpage%3Dcontent%26id%3DTS100969%26actp%3Dsearch"&gt;een oplossing op het Web gezet &lt;/a&gt;en zou de bewuste update gewraakt zijn.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-7358470145459430512?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/7358470145459430512/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/04/wereldwijd-pcs-onklaar-door-mcafee.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/7358470145459430512'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/7358470145459430512'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/04/wereldwijd-pcs-onklaar-door-mcafee.html' title='Wereldwijd PC&apos;s onklaar door McAfee update'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-3963707147853362303</id><published>2010-03-24T16:29:00.024+01:00</published><updated>2010-03-24T17:28:45.368+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>Avira AntiVir 10 (Free) is uit !</title><content type='html'>Vandaag biedt &lt;a href="http://www.free-av.com/en/download/index.html"&gt;Avira&lt;/a&gt; zijn nieuwste gratis antivirustool aan &lt;a href="http://techblog.avira.com/en/"&gt;AntiVir 10&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Er zijn twee mogelijkheden om deze tool te installeren:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Je hebt reeds AntiVir op je PC staan....&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;In dat geval doe je het volgende:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Rechtsklik op het Systeem icoontje van Antivir en kies &lt;em&gt;Start AntiVir&lt;/em&gt;.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Ga naar het tabblad &lt;em&gt;Updates&lt;/em&gt; en selecteer &lt;em&gt;Start Product Update&lt;/em&gt;.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;AntiVir zal beginnen met de update.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Als deze product update achter de rug is, rechtsklik je op AntiVir en kies je voor &lt;em&gt;Start update&lt;/em&gt;.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Je AntiVir is nu bijgewerkt.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Je hebt géén AntiVir, maar je zou deze willen installeren.....&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Eerst en vooral diendt opgemerkt te worden, dat AntiVir een actieve (real-time) scanner is.&lt;br /&gt;Daarom is het vereist dat AntiVir het enigste, actieve Antivirus tool op je PC is.&lt;br /&gt;Heb je bv. een Suite (Firewall + Antivirus + Antispyware + ...) dan kan je AntiVir best &lt;strong&gt;&lt;span style="font-size:130%;"&gt;niet&lt;/span&gt;&lt;/strong&gt; op je PC zetten.&lt;br /&gt;&lt;br /&gt;De reden hiervoor is, dat twee (of meerdere) actieve antivirustools elkaar kunnen &lt;em&gt;tegenwerken&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;Voorbeelden van zo'n suite zijn &lt;strong&gt;Norton Internet Security&lt;/strong&gt;, &lt;strong&gt;Zone Alarm Security Suite&lt;/strong&gt;, ...&lt;br /&gt;&lt;br /&gt;In alle andere gevallen download je &lt;a href="http://download.cnet.com/Avira-AntiVir-Personal-Free-Antivirus/3000-2239_4-10322935.html?part=dl-10322935&amp;amp;subj=dl&amp;amp;tag=button&amp;amp;cdlPid=11012914"&gt;avira_antivir_personal_en&lt;/a&gt; op je bureaublad.&lt;br /&gt;Dubbelklik erop en de installatie zal automatisch voltooid worden.&lt;br /&gt;Na de installatie zal om een herstart gevraagd worden, doe dit ook.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ff0000;"&gt;Opmerking &lt;/span&gt;&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;Voor beide gevallen geldt dat je op je PC beheerder met alle rechten bent.&lt;br /&gt;Zet je Firewall tijdelijk even uit.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-3963707147853362303?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/3963707147853362303/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/03/avira-antivir-10-free-is-uit.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/3963707147853362303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/3963707147853362303'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/03/avira-antivir-10-free-is-uit.html' title='Avira AntiVir 10 (Free) is uit !'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-6184705016475720137</id><published>2010-03-21T23:47:00.003+01:00</published><updated>2010-03-22T13:35:01.135+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>BitDefender geeft een foutieve update uit.</title><content type='html'>Lezers die een&lt;strong&gt; Windows 64 bits&lt;/strong&gt; systeem en &lt;strong&gt;BitDefender&lt;/strong&gt; op hun PC draaien hebben, moeten uitkijken.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;BitDefender&lt;/em&gt; heeft een foutieve update uitgebracht die de 64 bits systemen in de war kan brengen.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;BitDefender&lt;/em&gt; zet namelijk systeembestanden in quarantine waardoor je PC systeem corrupt geraakt.&lt;br /&gt;&lt;br /&gt;Inmiddels heeft &lt;em&gt;BD&lt;/em&gt; dit probleem onderkent en &lt;a href="http://www.bitdefender.com/site/KnowledgeBase/consumer/#638"&gt;&lt;span style="color:#ff0000;"&gt;een patch&lt;/span&gt; &lt;/a&gt;uitgegeven.&lt;br /&gt;&lt;br /&gt;Na het uitvoeren van deze patch, worden de update signatures juist gezet en kan je de files uit de quarantine herstellen.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-6184705016475720137?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/6184705016475720137/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/03/bitdefender-geeft-een-foutieve-update.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6184705016475720137'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6184705016475720137'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/03/bitdefender-geeft-een-foutieve-update.html' title='BitDefender geeft een foutieve update uit.'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-6615196227570307221</id><published>2010-03-12T15:57:00.051+01:00</published><updated>2010-06-23T13:29:35.068+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><title type='text'>CCleaner terugkerende registerwaarde....</title><content type='html'>&lt;strong&gt;&lt;span style="font-size:large;"&gt;Symptomen :&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;p&gt;In de Optie &lt;em&gt;register&lt;/em&gt; en dan scan problemen wordt een probleem gevonden, namelijk &lt;em&gt;niet gebruikte bestandsextensie&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;Deze laat zich wel herstellen maar als ik dan opnieuw kijk of het probleem weg is dan staat het er weer. Het gaat hier over de volgende, steeds terugkerende, waarde:&lt;/p&gt;&lt;p align="center"&gt;&lt;br /&gt;&lt;em&gt;&lt;strong&gt;HKCR\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79} &lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:large;"&gt;Oplossing :&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Dit is een bestandsextensie van &lt;strong&gt;AntiVir 9&lt;/strong&gt;.&lt;br /&gt;We moeten hiervoor even het bestand C:\Program Files\CCleaner\&lt;strong&gt;ccleaner.ini&lt;/strong&gt; opzoeken.&lt;br /&gt;&lt;br /&gt;Om deze te vinden moeten we eerst een instelling in &lt;strong&gt;Ccleaner&lt;/strong&gt; aanzetten:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Open Ccleaner&lt;/li&gt;&lt;li&gt;Klik op Opties&lt;/li&gt;&lt;li&gt;Klik op geavanceerd&lt;/li&gt;&lt;li&gt;Vink aan Bewaar alle instellingen als INI-bestand&lt;/li&gt;&lt;li&gt;Sluit Ccleaner.&lt;/li&gt;&lt;/ul&gt;Vervolgens ga je naar de map C:\Program Files\CCleaner&lt;br /&gt;Rechtsklik je op &lt;strong&gt;ccleaner.ini&lt;/strong&gt;&lt;br /&gt;Kies voor &lt;em&gt;Openen met kladblok&lt;/em&gt;.&lt;br /&gt;Je ziet nu zoiets zoals :&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-size:xx-small;"&gt;[Options]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;(App)DNS Cache=False&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;(App)IIS Log Files=False&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;(App)Old Prefetch data=False&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;(App)Windows Error Reporting=False&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;(App)Windows Log Files=False&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;BackupPrompt=0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;CookiesToSave=google&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;DelayTemp=0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;Exclude1=REG¦HKCR\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;HideWarnings=1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;Language=1043&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;MSG_CONFIRMCLEAN=False&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;UpdateKey=01/03/2010 08:27:47 AM&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;WINDOW_HEIGHT=450&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;WINDOW_LEFT=180&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;WINDOW_MAX=1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;WINDOW_TOP=122&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;"&gt;WINDOW_WIDTH=620&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:large;"&gt;Een woordje uitleg....&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;Merk de volgende regel op:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Exclude1=REG¦HKCR\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Bij jou zal deze daar &lt;span style="color:red;"&gt;niet&lt;/span&gt; staan, hetgeen meteen ook de reden is waarom je die steeds terugkerende melding krijgt. &lt;em&gt;Exclude is engels en betekend uitsluiten.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Eigenlijk staat daar dus : &lt;em&gt;Sluit de volgende CLSID uit&lt;/em&gt;.&lt;br /&gt;Vermits ik enkel één waarde heb uitgesloten (dit kan ook een map of bestand zijn), staat daar Exclude1. De Excludes verhogen dus in nummering.&lt;br /&gt;Kijk dus eerst hoeveel Excludes je daar hebt staan of beter, wat de hoogste nummering is.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:large;"&gt;De Exclude regel toevoegen.&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;In je openstaande kladboek bestand (die met de ccleaner.ini), kopie en plak je dit (na de laatste regel) :&lt;br /&gt;&lt;br /&gt;Exclude1=REG¦HKCR\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}&lt;br /&gt;&lt;br /&gt;Had of heb je daar nog Excludes staan, vergeet dan niet om deze de hoogste nummer te geven.&lt;br /&gt;Stonden er bij jou nog een aantal Excludes (Exclude1, Exclude2,..), dan wordt dit Exclude3.&lt;br /&gt;&lt;br /&gt;Ga naar Bestand - Opslaan als.&lt;br /&gt;Bij "Opslaan in" kies je: C:\Program Files\CCleaner&lt;br /&gt;Bij "Bestandsnaam" zet je: ccleaner.ini&lt;br /&gt;Bij "Opslaan als type" selecteer je: Alle bestanden (*.*).&lt;br /&gt;&lt;br /&gt;Klik op de knop Opslaan.Indien je een melding krijgt dat dit bestand overscheven wordt, laat je dit toe.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-6615196227570307221?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/6615196227570307221/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/03/ccleaner-terugkerende-registerwaarde.html#comment-form' title='2 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6615196227570307221'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/6615196227570307221'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/03/ccleaner-terugkerende-registerwaarde.html' title='CCleaner terugkerende registerwaarde....'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-5300182307987190175</id><published>2010-03-07T17:00:00.010+01:00</published><updated>2010-03-13T22:38:58.524+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Toolbars'/><category scheme='http://www.blogger.com/atom/ns#' term='Beveiliging'/><title type='text'>De Ask Toolbar</title><content type='html'>Laatste tijd is de dubieuze &lt;strong&gt;Ask Toolbar&lt;/strong&gt; meer en meer terug te vinden in de hijackthis logs die ik analyzeer.&lt;br /&gt;In de softwarelijst is deze dikwijls terug te vinden onder verschillende namen.&lt;br /&gt;&lt;br /&gt;Je kan deze op de volgende wijze verwijderen:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: red;"&gt;XP: &lt;/span&gt;&lt;/strong&gt;via start &amp;gt; Configuratiescherm &amp;gt; Software.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: red;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: red;"&gt;VISTA:&lt;/span&gt;&lt;/strong&gt; via start &amp;gt; Standaardprogramma's &amp;gt; Programma's en onderdelen.&lt;br /&gt;&lt;br /&gt;Vervolgens verwijder je één van deze namen:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;AskBar&lt;/li&gt;&lt;li&gt;Vuze&lt;/li&gt;&lt;li&gt;AskTBar&lt;/li&gt;&lt;li&gt;AskBarDis&lt;/li&gt;&lt;li&gt;Ask.com&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Herstart hierna je PC.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-5300182307987190175?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/5300182307987190175/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/03/de-ask-toolbar.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5300182307987190175'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/5300182307987190175'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/03/de-ask-toolbar.html' title='De Ask Toolbar'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1652215597704667757.post-8689647152355739966</id><published>2010-03-06T02:08:00.005+01:00</published><updated>2010-03-14T13:55:57.653+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Reacties'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti Malware Help Feedback'/><category scheme='http://www.blogger.com/atom/ns#' term='Feedback'/><title type='text'>Anti Malware Help is vernieuwd !</title><content type='html'>Vanaf vandaag heeft U met deze blog de mogelijkheid Uw reacties en opmerkingen, met betrekking tot de site, te plaatsen.&lt;br /&gt;&lt;br /&gt;Wees echter wel zo vriendelijk om de feedbacks met betrekking tot de website&lt;br /&gt;&lt;a href="http://www.emphyrio.be/"&gt;&lt;strong&gt;Anti Malware Help&lt;/strong&gt;&lt;/a&gt; onder deze item te zetten.&lt;br /&gt;&lt;br /&gt;Verdere info vind je aan de rechterzijde, waar je uiteraard ook mag op reageren.&lt;br /&gt;&lt;br /&gt;Hartelijk dank !&lt;div class="blogger-post-footer"&gt;&lt;a href="http://antimalwarehelp.blogspot.com/"&gt;Emphyrio's Security Blog&lt;/a&gt; &lt;a href="http://www.emphyrio.be/index.html"&gt;Anti Malware Help&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1652215597704667757-8689647152355739966?l=antimalwarehelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://antimalwarehelp.blogspot.com/feeds/8689647152355739966/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/03/anti-malware-help-is-vernieuwd.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/8689647152355739966'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1652215597704667757/posts/default/8689647152355739966'/><link rel='alternate' type='text/html' href='http://antimalwarehelp.blogspot.com/2010/03/anti-malware-help-is-vernieuwd.html' title='Anti Malware Help is vernieuwd !'/><author><name>Emphyrio</name><uri>http://www.blogger.com/profile/07958641763720608142</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_kf8wLmr_a8w/SyiLD8HJt4I/AAAAAAAAAAw/R4wPKBu1WdM/S220/Emphyrio.gif'/></author><thr:total>0</thr:total></entry></feed>
