Archief - Schermpjes die openen

Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.

Svenvdb

Legacy Member
Krijg af en toe zo van die schermpjes
die beginnen te laden.Loopt tekst doorheen

Logfile of HijackThis v1.99.1
Scan saved at 23:25:17, on 27/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\LogMeIn\LogMeIn.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\smax4.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\ISP Monitor\isp.exe
C:\Program Files\BMT MouseTracker\MouseTrack.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentC.exe
C:\Program Files\softbar.com\iNetWatcher 5\SentryDog.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentA.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Pinnacle\SHARED~1\Filter\server.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hln.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [PCTVRemote] C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [ISPMonitor] C:\Program Files\ISP Monitor\isp.exe
O4 - HKCU\..\Run: [Mouse Meter] C:\PROGRA~1\MOUSEM~1\MOUSEM~1.EXE
O4 - HKCU\..\Run: [BMT] C:\Program Files\BMT MouseTracker\MouseTrack.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: Alle links in deze pagina openen... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Blokkeer alle plaatjes afkomstig van dezelfde server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Geselecteerde koppelingen converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Geselecteerde koppelingen converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Koppelingdoel converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Koppelingdoel converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Markeren - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open In Nieuwe Avant Browser - C:\Program Files\Avant Browser\OpenInNewBrowser.htm
O8 - Extra context menu item: Selectie converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Selectie converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Toevoegen aan Reclame Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Zoeken - C:\Program Files\Avant Browser\Search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - http://sib1.od2.com/common/Member/ClientInstall/10.20.0002/OCI/setup.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1105804992299
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/1d/player.virtools.com/downloads/player/Install2.1/Installer.exe
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.cartoon-fridge.com/nsvplayx_vp3_mp3.cab
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpbasicdetection3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A2BCAD1-CBF8-4CEA-B563-8A375FA23FD4}: NameServer = 10.0.0.138
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: [Sentry5]Monitor Web-Activities (Sentry5AgentA) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentA.exe
O23 - Service: [Sentry5]Monitor Web-Files (Sentry5AgentB) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentB.exe
O23 - Service: [Sentry5]Data Communication (Sentry5AgentC) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentC.exe
O23 - Service: [Sentry5]Monitor SentryServices (Sentry5Dog) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryDog.exe
O23 - Service: [Sentry5]Internet connection sharing(NAT) (Sentry5NAT) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryNAT.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

Jurgenv1

Legacy Member
* Download en installeer Ewido Anti-Spyware 4.0.

  • Na de installatie, open Ewido Anti-Spyware 4.0:
    * onder "Status", klik op Change state naast "Resident shield".
    * onder "Update", klik op de Start update knop.
    * onder "Scanner", tab "Settings":
    • - onder "How to act?", klik op "Recommended actions" en selecteer Quarantine.
      - onder "Reports", selecteer Automatically generate report after every scan en verwijder het vinkje bij Only if threats were found
    Sluit Ewido. Laat het nog niet scannen.

* Als je Adaware SE nog niet geïnstalleerd hebt, download, installeer en update het dan volgens de richtlijnen
die je kan vinden op: http://users.pandora.be/marcvn/spyware/1414188.htm

* Start je computer op in VEILIGE MODUS

* Voer een volledige scan uit met Adaware en verwijder alles wat gevonden wordt.

  • open ewido en klik op de Scanner tab bovenaan en klik dan op Complete System Scan. Deze scan zal heel je systeem afcannen dus dit kan een tijdje duren
  • Ewido zal alle geïnfecteerde objecten aan de linkerkant tonen. Waneer de scan gedaan is, zal het alles naar de 'Quarantine' optie zetten. klik dan op de Apply all actions knop. Ewido zal dan het volgend bericht tonen aan de rechterkant: "All actions have been applied"
  • Klik dan op "Save Report", en dan op "Save Report As". dit zal een rapport maken Wees zeker dat je het rapport makkelijk kunt terugvinden (ijvoorbeeld op je bureaublad).

* Herstart je computer in normale modus.

* Download ATF cleaner (by Atribune)

Dubbelklik op ATF cleaner om het programma te starten.
Op het tabblad "Main", plaats je een vinkje bij Select All.
Klik op de knop Empty Selected.

Gebruik je ook Firefox als browser:
Klik op tabblad "Firefox", plaats een vinkje bij Select All.
Wil je de door Firefox opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
(dit verwijdert het vinkje bij "Firefox saved passwords")
Klik op de knop Empty Selected.

Gebruik je ook Opera als browser:
Klik op tabblad "Opera", plaats een vinkje bij Select All.
Wil je de door Opera opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
Klik op de knop Empty Selected.
Ga naar het tabblad "Main" en klik op de knop Exit om het programma af te sluiten.

* Post dan een nieuw hijackthis logje hier met het rapport van ewido.

Svenvdb

Legacy Member
Genen tijd gehad om te posten maar hier is het

Logfile of HijackThis v1.99.1
Scan saved at 16:38:44, on 7/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\PROGRA~1\NETSUP~1\client32.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\LogMeIn\LogMeIn.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\smax4.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\NetSupport Manager\Gateway32.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\ISP Monitor\isp.exe
C:\Program Files\BMT MouseTracker\MouseTrack.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\Program Files\Pinnacle\PCTV Stereo\Vision\Vision.exe
C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentC.exe
C:\Program Files\softbar.com\iNetWatcher 5\SentryDog.exe
C:\PROGRA~1\Pinnacle\SHARED~1\Filter\server.exe
C:\PROGRA~1\Pinnacle\SHARED~1\Filter\VBI_SE~1.EXE
C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentA.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hln.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [PCTVRemote] C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [ISPMonitor] C:\Program Files\ISP Monitor\isp.exe
O4 - HKCU\..\Run: [Mouse Meter] C:\PROGRA~1\MOUSEM~1\MOUSEM~1.EXE
O4 - HKCU\..\Run: [BMT] C:\Program Files\BMT MouseTracker\MouseTrack.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: Alle links in deze pagina openen... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Blokkeer alle plaatjes afkomstig van dezelfde server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Geselecteerde koppelingen converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Geselecteerde koppelingen converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Koppelingdoel converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Koppelingdoel converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Markeren - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open In Nieuwe Avant Browser - C:\Program Files\Avant Browser\OpenInNewBrowser.htm
O8 - Extra context menu item: Selectie converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Selectie converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Toevoegen aan Reclame Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Zoeken - C:\Program Files\Avant Browser\Search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - http://sib1.od2.com/common/Member/ClientInstall/10.20.0002/OCI/setup.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1105804992299
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/1d/player.virtools.com/downloads/player/Install2.1/Installer.exe
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.cartoon-fridge.com/nsvplayx_vp3_mp3.cab
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpbasicdetection3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A2BCAD1-CBF8-4CEA-B563-8A375FA23FD4}: NameServer = 10.0.0.138
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Client32 - NetSupport Ltd - C:\PROGRA~1\NETSUP~1\client32.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Gateway32 (PCIGateway) - NetSupport Ltd - C:\Program Files\NetSupport Manager\Gateway32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: [Sentry5]Monitor Web-Activities (Sentry5AgentA) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentA.exe
O23 - Service: [Sentry5]Monitor Web-Files (Sentry5AgentB) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentB.exe
O23 - Service: [Sentry5]Data Communication (Sentry5AgentC) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentC.exe
O23 - Service: [Sentry5]Monitor SentryServices (Sentry5Dog) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryDog.exe
O23 - Service: [Sentry5]Internet connection sharing(NAT) (Sentry5NAT) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryNAT.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Svenvdb

Legacy Member
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 16:33:01 7/10/2006

+ Scan result:



HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Security Plugin 2006 -> Adware.IntCodec : Cleaned with backup (quarantined).
:mozilla.207:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.208:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.209:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.210:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.181:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Adengage : Cleaned with backup (quarantined).
:mozilla.185:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Adengage : Cleaned with backup (quarantined).
:mozilla.823:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup (quarantined).
:mozilla.824:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup (quarantined).
:mozilla.551:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.552:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.553:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.534:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.535:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.536:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.679:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.680:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.831:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.26:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.29:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.31:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.32:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.902:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Gamershell : Cleaned with backup (quarantined).
:mozilla.903:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Gamershell : Cleaned with backup (quarantined).
:mozilla.904:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Gamershell : Cleaned with backup (quarantined).
:mozilla.905:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Gamershell : Cleaned with backup (quarantined).
:mozilla.906:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Gamershell : Cleaned with backup (quarantined).
:mozilla.907:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Gamershell : Cleaned with backup (quarantined).
:mozilla.908:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Gamershell : Cleaned with backup (quarantined).
:mozilla.909:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Gamershell : Cleaned with backup (quarantined).
:mozilla.910:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Gamershell : Cleaned with backup (quarantined).
:mozilla.911:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Gamershell : Cleaned with backup (quarantined).
:mozilla.912:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Gamershell : Cleaned with backup (quarantined).
:mozilla.915:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Gamershell : Cleaned with backup (quarantined).
:mozilla.526:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.957:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.276:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Itrack : Cleaned with backup (quarantined).
:mozilla.277:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Itrack : Cleaned with backup (quarantined).
:mozilla.278:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Itrack : Cleaned with backup (quarantined).
:mozilla.279:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Itrack : Cleaned with backup (quarantined).
:mozilla.280:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Itrack : Cleaned with backup (quarantined).
:mozilla.726:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup (quarantined).
:mozilla.211:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.213:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.214:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.215:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.216:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.218:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.219:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.221:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.563:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Planetactive : Cleaned with backup (quarantined).
:mozilla.584:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.585:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.586:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.587:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.588:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.589:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.590:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.591:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.592:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.593:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.594:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.595:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.596:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.597:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.598:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.599:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.600:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.601:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.602:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.603:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.604:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.605:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.606:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.607:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.608:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.609:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.610:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.611:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.612:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.613:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.614:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.615:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.616:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.617:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.618:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.619:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.620:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.621:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.622:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.623:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.624:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.625:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.626:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.627:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.628:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.629:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.630:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.631:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.632:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.633:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
:mozilla.155:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup (quarantined).
:mozilla.394:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup (quarantined).
:mozilla.395:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup (quarantined).
:mozilla.398:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup (quarantined).
:mozilla.568:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup (quarantined).
:mozilla.895:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup (quarantined).
:mozilla.896:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup (quarantined).
:mozilla.100:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.101:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.104:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.105:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.106:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.107:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.108:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.109:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.110:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.111:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.112:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.113:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.114:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.115:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.116:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.117:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.118:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.119:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.120:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.121:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.122:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.123:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.124:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.125:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.126:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.127:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.128:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.129:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.130:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.133:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.134:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).

Svenvdb

Legacy Member
:mozilla.135:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.136:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.137:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.138:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.139:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.140:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.141:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.142:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.143:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.144:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.145:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.146:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.147:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.148:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.149:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.150:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.151:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.314:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.315:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.316:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.317:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.452:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
:mozilla.453:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
:mozilla.454:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
:mozilla.196:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.197:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.198:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.199:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.959:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.960:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.961:C:\Documents and Settings\gebruiker\Application Data\Mozilla\Firefox\Profiles\11wf7vh8.Sven\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


::Report end

Jurgenv1

Legacy Member
* Download SmitfraudFix (by S!Ri)
Unzip het naar je bureaublad.
Lees hier hoe je op de juiste wijze moet unzippen/uitpakken.
Dit zal een nieuwe map op je bureaublad aanmaken met de naam Smitfraudfix
Verder nog niet gebruiken.

* Start nu je pc op in VEILIGE MODE. ( zonder netwerkondersteuning! )
Hoe start ik in veilige mode op.

* Clean de Cache and Cookies in IE:
  • Sluit Internet Explorer.
  • Ga naar Configuratiescherm > Internet Opties > tab Algemeen
  • Klik de "Cookies verwijderen" knop
  • Klik op de "Bestanden verwijderen" knop ernaast
  • Vink aan: "Ook alle off line items verwijderen", klik OK
* Clean de Cache and Cookies in Firefox (In geval Firefox geïnstalleerd is):
  • Go to Extra > Opties.
  • Klik Privacy in het menu.
  • Klik op de knop wissen (Geschiedenis, Cookies, Cache).
  • Klik OK om het venster opnieuw te sluiten.
* Clean andere Temporary files + Prullenbak
  • Ga naar start > uitvoeren en typ: cleanmgr en klik ok.
  • Laat het je systeem scannen op bestanden die moeten verwijderd worden
  • Zorg er wel voor dat je daar enkel maar 'tijdelijke bestanden', 'tijdelijke internetbestanden' en 'prullenbak' staan aangevinkt.
  • Klik daarna op ok.
* Open de SmitfraudFix map en dubbelklik smitfraudfix.cmd
Kies optie #2 - Clean door 2 te typen en op "Enter" te klikken.

Er zal gevraagd worden : "Registry cleaning - Do you want to clean the registry ?"; antwoord "Yes/ja" door Y te typen en daarna op "Enter" te klikken. Dit zal je bureaublad terug herstellen en registersleutels die deze infectie heeft gemaakt terug verwijderen.

Daarna zal de tool nagaan als wininet.dll is geïnfecteerd. Indien dit het geval is, zal er gevraagd worden om de geïnfecteerde wininet.dll te herplaatsen met een niet geïnfecteerde kopie van wininet.dll aanwezig op je computer (indien gevonden); antwoord "Yes/ja" door Y te typen en daarna op Enter te klikken.

De tool zal daarna je computer opnieuw laten opstarten om de restanten te verwijderen;
Indien het niet automatisch opstart, start je pc zelf opnieuw op naar normale mode terug (dus geen veilige mode)
Een log zal openen na het opnieuw opstarten. Deze bevindt zich ook hier: C:\rapport.txt
Ik heb die log later nodig als checkup.

Opgelet : Optie #2 gebruiken op een niet geïnfecteerde computer zal uw bureaublad verwijderen.

* Voer een onlinescan uit met Panda: http://www.pandasoftware.com/products/activescan.htm
Vink aan: All my computer
Zorg ervoor dat alles aangevinkt is in de scanopties.

Na de scan kan je een log laten maken. Bewaar die log naar je bureaublad en kopieer en plak die in je volgend bericht,
samen met een nieuwe HijackThis Log en de log van smitfraudfix ( C:\rapport.txt )

Svenvdb

Legacy Member
Ik mag dit doen ??
Omdat dit er staat in uw bericht

Opgelet : Optie #2 gebruiken op een niet geïnfecteerde computer zal uw bureaublad verwijderen.

Svenvdb

Legacy Member
SmitFraudFix v2.105

Scan done at 13:00:34,12, ma 09/10/2006
Run from C:\Documents and Settings\gebruiker\Bureaublad\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [versie 5.1.2600] - Windows_NT
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\gimmygames.dat Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

Svenvdb

Legacy Member
Logfile of HijackThis v1.99.1
Scan saved at 13:22:07, on 9/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\PROGRA~1\NETSUP~1\client32.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\Program Files\LogMeIn\LogMeIn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\NetSupport Manager\Gateway32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\smax4.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\ISP Monitor\isp.exe
C:\Program Files\BMT MouseTracker\MouseTrack.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentC.exe
C:\Program Files\softbar.com\iNetWatcher 5\SentryDog.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentA.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [PCTVRemote] C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [ISPMonitor] C:\Program Files\ISP Monitor\isp.exe
O4 - HKCU\..\Run: [Mouse Meter] C:\PROGRA~1\MOUSEM~1\MOUSEM~1.EXE
O4 - HKCU\..\Run: [BMT] C:\Program Files\BMT MouseTracker\MouseTrack.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [gStart] C:\Garmin\gStart.exe
O8 - Extra context menu item: Alle links in deze pagina openen... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Blokkeer alle plaatjes afkomstig van dezelfde server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Geselecteerde koppelingen converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Geselecteerde koppelingen converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Koppelingdoel converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Koppelingdoel converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Markeren - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open In Nieuwe Avant Browser - C:\Program Files\Avant Browser\OpenInNewBrowser.htm
O8 - Extra context menu item: Selectie converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Selectie converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Toevoegen aan Reclame Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Zoeken - C:\Program Files\Avant Browser\Search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - http://sib1.od2.com/common/Member/ClientInstall/10.20.0002/OCI/setup.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1105804992299
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/1d/player.virtools.com/downloads/player/Install2.1/Installer.exe
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.cartoon-fridge.com/nsvplayx_vp3_mp3.cab
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpbasicdetection3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A2BCAD1-CBF8-4CEA-B563-8A375FA23FD4}: NameServer = 10.0.0.138
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Client32 - NetSupport Ltd - C:\PROGRA~1\NETSUP~1\client32.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Gateway32 (PCIGateway) - NetSupport Ltd - C:\Program Files\NetSupport Manager\Gateway32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: [Sentry5]Monitor Web-Activities (Sentry5AgentA) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentA.exe
O23 - Service: [Sentry5]Monitor Web-Files (Sentry5AgentB) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentB.exe
O23 - Service: [Sentry5]Data Communication (Sentry5AgentC) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentC.exe
O23 - Service: [Sentry5]Monitor SentryServices (Sentry5Dog) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryDog.exe
O23 - Service: [Sentry5]Internet connection sharing(NAT) (Sentry5NAT) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryNAT.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Svenvdb

Legacy Member
Incident Status Location

Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\gebruiker\Local Settings\Temporary Internet Files\Ssk.log
Adware:adware/dollarrevenue Not disinfected c:\windows\keyboard11.dat
Adware:adware/atlas Not disinfected c:\windows\switps.dat
Adware:adware/cws.searchmeup Not disinfected c:\windows\uniq
Spyware:spyware/cws.olehelp Not disinfected Windows Registry
Adware:adware/transponder Not disinfected Windows Registry
Adware:adware/novo Not disinfected Windows Registry
Adware:adware/powerscan Not disinfected Windows Registry
Adware:adware/surfaccuracy Not disinfected Windows Registry
Adware:adware/ncase Not disinfected Windows Registry
Adware:adware/ist.sidefind Not disinfected Windows Registry
Adware:adware/ucmore Not disinfected Windows Registry
Adware:adware/ist.yoursitebar Not disinfected Windows Registry
Virus:trj/dropper.qq Disinfected Operating system
Adware:adware/intcodec Not disinfected Windows Registry
Adware:adware/abox Not disinfected Windows Registry
Spyware:spyware/petro-line Not disinfected Windows Registry
Hacktool:exploit/mhtredir.gen Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11311111-1551-1661-1771-000000000000}

Jurgenv1

Legacy Member
1. Download dit bestand: - combofix.exe
2. Dubbelklik op combofix.exe en volg de instructies die je krijgt.
3. Wanneer het tooltje klaar is zal het een rapport maken voor je, post die log hier met een nieuw hijackthis logje.

Note:
Niet klikken terwijl combofix bezig is, dat zou het tooltje doen vastlopen!

Svenvdb

Legacy Member
gebruiker - 06-10-09 19:01:09,92 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\Documents and Settings\gebruiker\Bureaublad"

((((((((((((((((((((((((((((((( Files Created from 2006-09-09 to 2006-10-09 ))))))))))))))))))))))))))))))))))


2006-10-09 13:00 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-10-09 13:00 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-10-09 13:00 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-10-09 13:00 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-10-08 10:40 9,600 -ra------ C:\WINDOWS\system32\drivers\vmnetadapter.sys
2006-10-08 10:40 5,120 -ra------ C:\WINDOWS\system32\vnetinst.dll
2006-10-08 10:40 106,496 --a------ C:\WINDOWS\system32\vmnetdhcp.exe
2006-10-08 10:39 385,024 --a------ C:\WINDOWS\system32\vnetlib.dll
2006-10-08 10:39 15,616 --a------ C:\WINDOWS\system32\drivers\vmnetuserif.sys
2006-10-08 10:39 135,168 --a------ C:\WINDOWS\system32\vmnat.exe
2006-10-08 10:39 10,240 -ra------ C:\WINDOWS\system32\drivers\vmnet.sys
2006-10-06 22:06 356,439 --a------ C:\WINDOWS\system32\GDS32.DLL
2006-10-06 21:40 262,144 --------- C:\WINDOWS\Setup1.exe
2006-10-03 20:04 98,359 --a------ C:\WINDOWS\system32\pcimon.dll
2006-10-03 20:04 73,785 --a------ C:\WINDOWS\system32\clhook4.dll
2006-10-03 20:04 32,823 --a------ C:\WINDOWS\system32\drivers\pcisys.sys
2006-10-03 20:04 28,728 --a------ C:\WINDOWS\system32\pcigina.dll
2006-10-03 20:04 28,672 --a------ C:\WINDOWS\system32\pcimsg.dll
2006-10-03 20:04 25,145 --a------ C:\WINDOWS\system32\gdihook5.dll
2006-10-03 20:04 24,633 --a------ C:\WINDOWS\system32\drivers\gdihook5.sys
2006-10-03 20:04 20,535 --a------ C:\WINDOWS\system32\pcivdd.dll
2006-09-21 22:04 147,318 --a------ C:\WINDOWS\system32\drivers\wlgnat.sys
2006-09-10 19:46 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-09 18:44 -------- d-------- C:\Program Files\Mozilla Thunderbird
2006-10-09 13:19 -------- d-------- C:\Program Files\Windows Defender
2006-10-09 13:19 -------- d-------- C:\Program Files\WhatPulse
2006-10-09 13:19 -------- d-------- C:\Program Files\NetSupport Manager
2006-10-09 13:19 -------- d-------- C:\Program Files\NetLimiter 2 Pro
2006-10-09 13:19 -------- d-------- C:\Program Files\MSN Messenger
2006-10-09 13:19 -------- d-------- C:\Program Files\Messenger Plus! Live
2006-10-09 13:19 -------- d-------- C:\Program Files\LogMeIn
2006-10-09 13:19 -------- d-------- C:\Program Files\ISP Monitor
2006-10-09 13:19 -------- d-------- C:\Program Files\Internet Explorer
2006-10-09 13:19 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-10-09 13:19 -------- d-------- C:\Program Files\Eset
2006-10-09 13:19 -------- d-------- C:\Program Files\DAEMON Tools
2006-10-09 13:19 -------- d-------- C:\Program Files\BMT MouseTracker
2006-10-08 13:22 -------- d-------- C:\Program Files\mIRC
2006-10-08 10:34 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-10-08 10:33 -------- d-------- C:\Program Files\VMware
2006-10-08 10:33 -------- d-------- C:\Program Files\Common Files\VMware
2006-10-08 10:33 -------- d-------- C:\Program Files\Common Files
2006-10-07 18:59 -------- d-------- C:\Program Files\Java
2006-10-07 18:58 -------- d-------- C:\Program Files\Common Files\Java
2006-10-07 18:37 -------- d-------- C:\Program Files\Games
2006-10-06 22:06 -------- d-------- C:\Program Files\FlameRobin
2006-10-06 22:06 -------- d-------- C:\Program Files\Firebird
2006-10-06 21:51 -------- d-------- C:\Program Files\Kas
2006-10-06 21:40 73216 --a------ C:\WINDOWS\ST6UNST.EXE
2006-10-05 14:30 -------- d-------- C:\Program Files\MediaMonkey
2006-10-04 23:22 -------- d-------- C:\Program Files\SpeedFan
2006-10-02 17:55 629264 --a------ C:\WINDOWS\system32\drivers\VetEFile.sys
2006-10-02 17:55 108592 --a------ C:\WINDOWS\system32\drivers\VetEBoot.sys
2006-10-02 08:00 724992 --a------ C:\WINDOWS\iun6002.exe
2006-10-02 08:00 -------- d-------- C:\Program Files\TrafficBar
2006-10-01 16:03 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-09-30 23:48 -------- d-------- C:\Program Files\Ethereal
2006-09-30 20:03 -------- d-------- C:\Program Files\Crazy Browser
2006-09-24 21:14 -------- d-------- C:\Program Files\Novativa Streamster
2006-09-24 11:48 -------- d-------- C:\Documents and Settings\gebruiker\Application Data\Adobe
2006-09-22 21:01 -------- d-------- C:\Program Files\Microchip
2006-09-21 22:53 -------- d-------- C:\Program Files\Oil Tycoon
2006-09-21 22:53 -------- d-------- C:\Program Files\LaCie
2006-09-21 22:52 -------- d-------- C:\Program Files\DialXS Webmaster Monitor
2006-09-21 22:50 -------- d-------- C:\Program Files\CureROM
2006-09-21 22:05 -------- d-------- C:\Program Files\WinPcap
2006-09-21 22:04 -------- d-------- C:\Program Files\softbar.com
2006-09-21 21:07 -------- d-------- C:\Program Files\maxplus2
2006-09-21 21:02 -------- d-------- C:\Program Files\max2work
2006-09-16 10:30 -------- d-------- C:\Program Files\WinRAR
2006-09-14 18:06 -------- d-------- C:\Program Files\Winamp
2006-09-13 12:13 -------- d-------- C:\Program Files\Screen Recorder
2006-09-10 19:43 -------- d-------- C:\Program Files\Sony Corporation
2006-09-06 21:04 -------- d-------- C:\Program Files\MP3-Database
2006-08-21 14:28 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 11:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 11:14 128896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-20 23:06 -------- d-------- C:\Documents and Settings\gebruiker\Application Data\ColorImpact3
2006-08-20 16:03 -------- d-------- C:\Program Files\Globe7
2006-08-18 02:35 73728 --a------ C:\WINDOWS\system32\MPLBCOMM.dll
2006-08-17 17:11 -------- d-------- C:\Documents and Settings\gebruiker\Application Data\ATI
2006-08-17 17:07 -------- d-------- C:\Program Files\ATI Technologies
2006-08-11 16:08 -------- d-------- C:\Program Files\AudioShell
2006-08-10 18:10 -------- d-------- C:\Program Files\Opera
2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-27 15:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 13:15 9576 --a------ C:\WINDOWS\system32\LMImirr2.dll
2006-07-21 13:15 23016 --a------ C:\WINDOWS\system32\LMImirr.dll
2006-07-21 13:15 11496 --a------ C:\WINDOWS\system32\LMIinit.dll
2006-07-21 10:29 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-19 04:58 258048 --------- C:\WINDOWS\system32\ati2dvag.dll
2006-07-19 04:53 77824 --a------ C:\WINDOWS\system32\Oemdspif.dll
2006-07-19 04:53 26112 --a------ C:\WINDOWS\system32\Ati2mdxx.exe
2006-07-19 04:53 114688 --a------ C:\WINDOWS\system32\atipdlxx.dll
2006-07-19 04:52 86016 --a------ C:\WINDOWS\system32\ati2evxx.dll
2006-07-19 04:52 41984 --a------ C:\WINDOWS\system32\ati2edxx.dll
2006-07-19 04:51 53248 --a------ C:\WINDOWS\system32\ATIDDC.DLL
2006-07-19 04:51 401408 --a------ C:\WINDOWS\system32\ati2evxx.exe
2006-07-19 04:44 2732608 --a------ C:\WINDOWS\system32\ati3duag.dll
2006-07-19 04:39 1744416 --a------ C:\WINDOWS\system32\ativvaxx.dll
2006-07-19 04:27 204800 --a------ C:\WINDOWS\system32\atikvmag.dll
2006-07-19 04:26 17408 --a------ C:\WINDOWS\system32\atitvo32.dll
2006-07-19 04:23 307200 --a------ C:\WINDOWS\system32\atiiiexx.dll
2006-07-19 04:22 6684672 --a------ C:\WINDOWS\system32\atioglx1.dll
2006-07-19 04:22 286720 --------- C:\WINDOWS\system32\ati2cqag.dll
2006-07-19 04:21 290816 --a------ C:\WINDOWS\system32\ATIDEMGR.dll
2006-07-19 04:13 5136384 --a------ C:\WINDOWS\system32\atioglxx.dll
2006-07-18 21:05 520192 --------- C:\WINDOWS\system32\ati2sgag.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\" /WinStart"
"WhatPulse"="C:\\PROGRA~1\\WHATPU~1\\WHATPU~1.EXE"
"ISPMonitor"="C:\\Program Files\\ISP Monitor\\isp.exe"
"Mouse Meter"="C:\\PROGRA~1\\MOUSEM~1\\MOUSEM~1.EXE"
"BMT"="C:\\Program Files\\BMT MouseTracker\\MouseTrack.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"gStart"="C:\\Garmin\\gStart.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\SoundMAX\\SMax4PNP.exe"
"SoundMAX"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\smax4.exe\" /tray"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"
"AME_CSA"="rundll32 amecsa.cpl,RUN_DLL"
"PCTVRemote"="C:\\Program Files\\Pinnacle\\PCTV Stereo\\Remote\\Remoterm.exe"
"LogMeIn GUI"="\"C:\\Program Files\\LogMeIn\\LogMeInSystray.exe\""
"CaAvTray"="\"C:\\Program Files\\CA\\eTrust EZ Armor\\eTrust EZ Antivirus\\CAVTray.exe\""
"CAVRID"="\"C:\\Program Files\\CA\\eTrust EZ Armor\\eTrust EZ Antivirus\\CAVRID.exe\""
"Adobe Version Cue CS2"="C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\ControlPanel\\VersionCueCS2Tray.exe"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideo[inspector]"="C:\\Program Files\\Logitech\\Video\\InstallHelper.exe /inspect"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\CLIStart.exe\""
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=hex:91,00,00,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"AllowLegacyWebView"=dword:00000001
"AllowUnhashedWebView"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run]

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=hex:91,00,00,00

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=hex:91,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Adobe Acrobat Snelle start.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Start\\Programma's\\Opstarten\\Adobe Acrobat Snelle start.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Acrobat Snelle start.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\WINDOWS\\Installer\\{AC76BA86-1030-D700-7760-100000000002}\\SC_Acrobat.exe "
"item"="Adobe Acrobat Snelle start"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Adobe Gamma.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Start\\Programma's\\Opstarten\\Adobe Gamma.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Start\\Programma's\\Opstarten\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^AutoCAD Startup Accelerator.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Start\\Programma's\\Opstarten\\AutoCAD Startup Accelerator.lnk"
"backup"="C:\\WINDOWS\\pss\\AutoCAD Startup Accelerator.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\AUTODE~1\\ACSTAR~1.EXE "
"item"="AutoCAD Startup Accelerator"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Image Transfer.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Start\\Programma's\\Opstarten\\Image Transfer.lnk"
"backup"="C:\\WINDOWS\\pss\\Image Transfer.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\SONYCO~1\\IMAGET~1\\SonyTray.exe "
"item"="Image Transfer"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Pinnacle Scheduler.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Start\\Programma's\\Opstarten\\Pinnacle Scheduler.lnk"
"backup"="C:\\WINDOWS\\pss\\Pinnacle Scheduler.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Pinnacle\\SHARED~1\\Programs\\SCHEDU~1\\PCLESC~1.EXE "
"item"="Pinnacle Scheduler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Servicebeheer.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Start\\Programma's\\Opstarten\\Servicebeheer.lnk"
"backup"="C:\\WINDOWS\\pss\\Servicebeheer.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MI6841~1\\80\\Tools\\Binn\\sqlmangr.exe /n"
"item"="Servicebeheer"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Snelstart HP Image Zone.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Start\\Programma's\\Opstarten\\Snelstart HP Image Zone.lnk"
"backup"="C:\\WINDOWS\\pss\\Snelstart HP Image Zone.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\HEWLET~1\\DIGITA~1\\bin\\hpqthb08.exe -s"
"item"="Snelstart HP Image Zone"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^gebruiker^Menu Start^Programma's^Opstarten^TickerBar.lnk]
"path"="C:\\Documents and Settings\\gebruiker\\Menu Start\\Programma's\\Opstarten\\TickerBar.lnk"
"backup"="C:\\WINDOWS\\pss\\TickerBar.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\TICKER~1\\TICKER~1.EXE "
"item"="TickerBar"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^gebruiker^Menu Start^Programma's^Opstarten^Xfire.lnk]
"path"="C:\\Documents and Settings\\gebruiker\\Menu Start\\Programma's\\Opstarten\\Xfire.lnk"
"backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\Xfire\\Xfire.exe "
"item"="Xfire"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Acrobat Assistant 7.0]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Acrotray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Adobe\\Adobe Acrobat 7.0\\Distillr\\Acrotray.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Adobe Version Cue CS2]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VersionCueCS2Tray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\ControlPanel\\VersionCueCS2Tray.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Anti-Blaxx Manager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Anti-Blaxx"
"hkey"="HKLM"
"command"="C:\\Program Files\\Anti-Blaxx\\Anti-Blaxx.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\CaISSDT]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="caissdt"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CA\\eTrust Internet Security Suite\\caissdt.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\DAEMON Tools-1033]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033 -lock"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\eTrustPPAP]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PPActiveDetection"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CA\\eTrust Internet Security Suite\\eTrust PestPatrol Anti-Spyware\\PPActiveDetection.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\GreenHorseTickerBar]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TickerBar"
"hkey"="HKLM"
"command"="C:\\Program Files\\Tickerbar\\TickerBar.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\gStart]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="gStart"
"hkey"="HKCU"
"command"="C:\\Garmin\\gStart.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\HP Software Update]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HPWuSchd2"
"hkey"="HKLM"
"command"="C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\HPHmon04]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hphmon04"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\hphmon04.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\HPHUPD04]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hphupd04"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\HP Photosmart 11\\hphinstall\\UniPatch\\hphupd04.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\LogitechCameraAssistant]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CameraAssistant"
"hkey"="HKLM"
"command"="C:\\Program Files\\Logitech\\Video\\CameraAssistant.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\LogitechCameraService(E)]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ElkCtrl"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\ElkCtrl.exe /automation"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Power Scan]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="powerscan"
"hkey"="HKLM"
"command"="C:\\Program Files\\Power Scan\\powerscan.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Realtime Audio Engine]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mmrtkrnl"
"hkey"="HKLM"
"command"="mmrtkrnl.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Share-to-Web Namespace Daemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hpgs2wnd"
"hkey"="HKLM"
"command"="C:\\Program Files\\Hewlett-Packard\\HP Share-to-Web\\hpgs2wnd.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SPAMfighter Agent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SFAgent"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\SPAMfighter\\SFAgent.exe\" update delay 60"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\StatBar]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="StatBar"
"hkey"="HKCU"
"command"="C:\\Program Files\\Globe Software\\StatBar\\StatBar.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SurfAccuracy]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SAcc"
"hkey"="HKLM"
"command"="C:\\Program Files\\SurfAccuracy\\SAcc.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SwQxuWr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="pnbkoks"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\pnbkoks.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\WebSpecials]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="webspec"
"hkey"="HKLM"
"command"="rundll32 \"C:\\Program Files\\WebSpecials\\webspec.dll\",run"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\WinampAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="winampa"
"hkey"="HKLM"
"command"="C:\\Program Files\\Winamp\\winampa.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Windows Defender]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MSASCui"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\zzzHPSETUP]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RESET"
"hkey"="HKLM"
"command"="D:\\Setup.exe \\RESET"
"inimapping"="0"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll



~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

backup-20060731-183421-419
O21 - SSODL: cholecyst - {ee2975b6-e8d5-405e-8448-8fe9590f6cfb} - (no file)
backup-20060731-183421-971
O2 - BHO: (no name) - {5753791b-f607-48ca-814e-91c14d081f9e} - C:\Program Files\IntCodec\isaddon.dll
backup-20060623-090501-169
R3 - URLSearchHook: (no name) - - (no file)

Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job

Completion time: Mon 09/10/2006 19:04:24.87
ComboFix.txt

Jurgenv1

Legacy Member
* Download Killbox.
Klik op killbox.exe.
Kies de optie: "Delete on reboot".

Kopieer het volgende vetgedrukt deel:

C:\Documents and Settings\gebruiker\Local Settings\Temporary Internet Files\Ssk.log
c:\windows\switps.dat
c:\windows\keyboard11.dat


Open 'file' in het killboxmenu bovenaan en kies: Paste from clipboard

Je zal zien, het bovenstaande vetgedrukte zal staan in het "Full Path of File to Delete"-veld.
Er is een klein pijltje naast dat veld. Als je daarop klikt zal je al die bovenstaande lijntjes (indien bestanden aanwezig) die je gekopieerd hebt zien staan (dit is alvast de bedoeling)

Klik op de knop: All files (!Belangrijk!)

Daarna, Klik op de rode cirkel met het wit kruisje erin.
Killbox zal zeggen dat deze file zal verwijderd worden on reboot.. vraagt om nu te rebooten. Klik YES.

Je pc moet nu rebooten.

Open Kladblok.
Kopieer de onderstaande vetgedrukte tekst en plak deze in een nieuw document.

Code:
REGEDIT4

[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11311111-1551-1661-1771-000000000000}]

Kies Bestand -> Opslaan
Selecteer bij "Opslaan in": Bureaublad
Vul bij "Bestandsnaam" in: fix.reg
Selecteer bij "Opslaan als type": Alle bestanden
Klik op "Opslaan".

Dubbelklik op fix.reg, dat nu op je bureaublad staat.
Ga ermee akkoord dat deze gegevens aan het register worden toegevoegd.
Start de pc opnieuw op en post een nieuw hijackthis logje hier

* Post dan een nieuw hijackthis logje hier.

Svenvdb

Legacy Member
Logfile of HijackThis v1.99.1
Scan saved at 21:03:36, on 9/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
c:\windows\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
c:\windows\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\PROGRA~1\NETSUP~1\client32.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\Program Files\LogMeIn\LogMeIn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\NetSupport Manager\Gateway32.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\smax4.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\ISP Monitor\isp.exe
C:\Program Files\BMT MouseTracker\MouseTrack.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\HDD Health\hddhealth.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentC.exe
C:\Program Files\softbar.com\iNetWatcher 5\SentryDog.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentA.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [PCTVRemote] C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [ISPMonitor] C:\Program Files\ISP Monitor\isp.exe
O4 - HKCU\..\Run: [Mouse Meter] C:\PROGRA~1\MOUSEM~1\MOUSEM~1.EXE
O4 - HKCU\..\Run: [BMT] C:\Program Files\BMT MouseTracker\MouseTrack.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [gStart] C:\Garmin\gStart.exe
O4 - HKCU\..\Run: [HDDHealth] C:\Program Files\HDD Health\hddhealth.exe -wl
O8 - Extra context menu item: Alle links in deze pagina openen... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Blokkeer alle plaatjes afkomstig van dezelfde server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Geselecteerde koppelingen converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Geselecteerde koppelingen converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Koppelingdoel converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Koppelingdoel converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Markeren - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open In Nieuwe Avant Browser - C:\Program Files\Avant Browser\OpenInNewBrowser.htm
O8 - Extra context menu item: Selectie converteren naar Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Selectie converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Toevoegen aan Reclame Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Zoeken - C:\Program Files\Avant Browser\Search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - http://sib1.od2.com/common/Member/ClientInstall/10.20.0002/OCI/setup.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1105804992299
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/1d/player.virtools.com/downloads/player/Install2.1/Installer.exe
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.cartoon-fridge.com/nsvplayx_vp3_mp3.cab
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpbasicdetection3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A2BCAD1-CBF8-4CEA-B563-8A375FA23FD4}: NameServer = 10.0.0.138
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Client32 - NetSupport Ltd - C:\PROGRA~1\NETSUP~1\client32.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Gateway32 (PCIGateway) - NetSupport Ltd - C:\Program Files\NetSupport Manager\Gateway32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: [Sentry5]Monitor Web-Activities (Sentry5AgentA) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentA.exe
O23 - Service: [Sentry5]Monitor Web-Files (Sentry5AgentB) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentB.exe
O23 - Service: [Sentry5]Data Communication (Sentry5AgentC) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryAgentC.exe
O23 - Service: [Sentry5]Monitor SentryServices (Sentry5Dog) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryDog.exe
O23 - Service: [Sentry5]Internet connection sharing(NAT) (Sentry5NAT) - Unknown owner - C:\Program Files\softbar.com\iNetWatcher 5\SentryNAT.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Svenvdb

Legacy Member
Heb nog altijd die vensterkes
Ze komen niet vaak,maar toch komen ze nog

Svenvdb

Legacy Member
Heb nog altijd die vensterkes
Ze komen niet vaak,maar toch komen ze nog

Jurgenv1

Legacy Member
Hernoem hijackthis.exe naar hjt.exe en post dan een nieuw hijackthis logje hier.
Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.
Terug
Bovenaan