Archief - check even mn logje aub..zit met hoop rommel :(

Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.

casualties

Legacy Member
Heb al minstens 3 virusscanners en talrijke anti-spywares geprobeerd en krijg het maar niet opgelost..Dit is men laatste hoop voor ik een formatje ga doen..

Logfile of HijackThis v1.99.1
Scan saved at 18:38:27, on 13/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_Task.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\laptop\LOCALS~1\Temp\Rar$EX00.969\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com/en/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Domain Helper - {B8A5DE1C-BC13-4DD2-BF00-7BE3C603F9F2} - C:\WINDOWS\system32\DomainHelper.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Add RSS Support Site to VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: archenteric - {d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3} - C:\WINDOWS\system32\impgsje.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

Jurgenv1

Legacy Member
Probeer de volgende mogelijke manieren om New.net te verwijderen, in deze volgorde:

1) Ga naar Configuratiescherm > Software. Kijk of New.net Domains of New.net Application in de softwarelijst staat en, zo ja, deïnstalleer dit.
Staat het niet in de softwarelijst of lukt het deïnstalleren niet, ga dan naar 2).

2) Kijk in de map C:\Program Files\NewDotNet of daarin een uninstaller staat. Die uninstaller heet uninstallX_XX.exe (waarbij de X'en staan voor cijfers). Zo ja, dubbelklik daarop om New.net te verwijderen.
Lukt het op deze manier niet, ga dan naar 3).

3) Kijk in de map C:\Windows of daarin een uninstaller staat. Die uninstaller heet NDNuninstallx_xx.exe (waarbij de X'en staan voor cijfers). Zo ja, dubbelklik daarop om New.net te verwijderen.
Lukt het op deze manier niet, ga dan naar 4).

4) Download deze uninstaller, plaats het op je bureaublad. Dubbelklik op NNuninstall.exe, dat nu op je bureaublad staat, om New.net te verwijderen.

Na het verwijderen van New.net, moet de pc opnieuw worden opgestart.

* Download combofix.exe: http://download.bleepingcomputer.com/sUBs/combofix.exe
Plaats het op je bureaublad.
Dubbelklik er op om het programma te starten.
In het scherm dat verschijnt tik je een Y in om het cleaningsprocess te starten.
Volg de instructies op het scherm.
Als het tooltje klaar is, opent er een logfile (combofix.txt) Post de inhoud van dit bestandje samen met een nieuwe hijackthislog.

casualties

Legacy Member
Duurt wel heel lang he, dat combofix..ik probeer nog even verder..

Jurgenv1

Legacy Member
Het beste is om alle andere programma's te sluiten, ook moet je combofix zijn werk laten doen, ergens ander sop klikken zorgt ervoor dat het tooltje doet vastlopen idd.

casualties

Legacy Member
ok, gelukt...voila


COMBOFIX

laptop - 06-11-13 23:00:16.12 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\laptop\Bureaublad"

((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\dxclib303562752.dll
C:\Documents and Settings\laptop\Application Data\Dxcdmns.dll
C:\Documents and Settings\laptop\Application Data\Dxcknwrd.dll
C:\Documents and Settings\Vicky\Application Data\Dxcknwrd.dll
C:\Program Files\DeluxeCommunications\Dxc.exe
C:\Program Files\DeluxeCommunications\DxcBho.dll
C:\Program Files\DeluxeCommunications\DxcCore.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\laptop\Local Settings\Temporary Internet Files\Content.IE5\4FO1APGN\deskbar_e[1].exe
C:\WINDOWS\system32\components
C:\Program Files\Common Files\{34A58EF0-0724-1043-0817-060518060020}
C:\Program Files\Common Files\{54A58EF0-0724-1043-0817-060518060020}


((((((((((((((((((((((((((((((( Files Created from 2006-10-13 to 2006-11-13 ))))))))))))))))))))))))))))))))))


2006-11-13 18:08 651,776 --a------ C:\WINDOWS\is-V0DAQ.exe
2006-11-13 18:08 651,776 --a------ C:\WINDOWS\is-V0DAQ.exe
2006-11-13 18:08 24,576 --a------ C:\WINDOWS\system32\STKIT432.DLL
2006-11-13 18:08 24,576 --a------ C:\WINDOWS\system32\STKIT432.DLL
2006-11-13 17:15 90,112 --------- C:\WINDOWS\system32\AVASTSS.scr
2006-11-13 17:15 90,112 --------- C:\WINDOWS\system32\AVASTSS.scr
2006-11-13 17:15 87,424 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2006-11-13 17:15 87,424 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2006-11-13 17:15 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2006-11-13 17:15 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2006-11-13 17:15 666,240 --a------ C:\WINDOWS\system32\aswBoot.exe
2006-11-13 17:15 666,240 --a------ C:\WINDOWS\system32\aswBoot.exe
2006-11-13 17:15 36,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2006-11-13 17:15 36,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2006-11-13 17:15 24,560 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2006-11-13 17:15 24,560 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2006-11-13 17:15 16,352 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2006-11-13 17:15 16,352 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2006-11-13 09:35 50,944 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2006-11-13 09:35 50,944 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2006-11-13 09:35 30,560 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2006-11-13 09:35 30,560 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2006-11-12 16:12 58,464 --a------ C:\WINDOWS\system32\drivers\mvstdi5x.sys
2006-11-12 16:12 58,464 --a------ C:\WINDOWS\system32\drivers\mvstdi5x.sys
2006-11-12 16:12 108,480 --a------ C:\WINDOWS\system32\drivers\naiavf5x.sys
2006-11-12 16:12 108,480 --a------ C:\WINDOWS\system32\drivers\naiavf5x.sys
2006-11-12 16:06 2,940 --a------ C:\WINDOWS\system32\fxmngr.exe
2006-11-12 16:06 2,940 --a------ C:\WINDOWS\system32\fxmngr.exe
2006-11-12 16:06 106,496 --a------ C:\WINDOWS\system32\impgsje.dll
2006-11-12 16:06 106,496 --a------ C:\WINDOWS\system32\impgsje.dll
2006-11-12 16:01 101,888 --a------ C:\WINDOWS\system32\drvfob.dll
2006-11-12 16:01 101,888 --a------ C:\WINDOWS\system32\drvfob.dll
2006-11-12 13:45 8,464 --a------ C:\WINDOWS\system32\sporder.dll
2006-11-12 13:45 8,464 --a------ C:\WINDOWS\system32\sporder.dll
2006-11-12 13:45 6,687 --a------ C:\WINDOWS\system32\ldcore.dll
2006-11-12 13:45 6,687 --a------ C:\WINDOWS\system32\ldcore.dll
2006-11-12 13:45 204 --a------ C:\WINDOWS\system32\jdkfjdskfjkdsjf.bat
2006-11-12 13:45 204 --a------ C:\WINDOWS\system32\jdkfjdskfjkdsjf.bat
2006-11-12 13:45 106,496 --a------ C:\WINDOWS\system32\DomainHelper.dll
2006-11-12 13:45 106,496 --a------ C:\WINDOWS\system32\DomainHelper.dll
2006-11-12 13:45 1,335 --a------ C:\WINDOWS\system32\xvhf04a7.sys
2006-11-12 13:45 1,335 --a------ C:\WINDOWS\system32\xvhf04a7.sys
2006-11-12 13:44 32,768 --a------ C:\WINDOWS\system32\setup9X.exe
2006-11-12 13:44 32,768 --a------ C:\WINDOWS\system32\setup9X.exe
2006-11-12 13:44 32,768 --a------ C:\WINDOWS\system32\install.exe
2006-11-12 13:44 32,768 --a------ C:\WINDOWS\system32\install.exe
2006-11-12 13:44 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2006-11-12 13:44 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2006-11-10 21:07 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2006-11-10 21:07 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2006-11-10 21:07 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2006-11-10 21:07 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2006-11-10 21:07 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2006-11-10 21:07 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2006-11-05 22:26 34,308 --a------ C:\WINDOWS\system32\BASSMOD.dll
2006-11-05 22:26 34,308 --a------ C:\WINDOWS\system32\BASSMOD.dll
2006-11-02 19:47 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2006-11-02 19:47 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2006-11-02 17:08 90,112 --a------ C:\WINDOWS\unvise32.exe
2006-11-02 17:08 90,112 --a------ C:\WINDOWS\unvise32.exe
2006-11-02 16:16 315,904 --a------ C:\WINDOWS\IsUn0413.exe
2006-11-02 16:16 315,904 --a------ C:\WINDOWS\IsUn0413.exe
2006-11-02 14:29 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2006-11-02 14:29 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2006-11-02 12:01 26,496 --a------ C:\WINDOWS\system32\drivers\USBSTOR.SYS
2006-11-02 12:01 26,496 --a------ C:\WINDOWS\system32\drivers\USBSTOR.SYS
2006-11-02 11:52 42,496 --------- C:\WINDOWS\system32\wpdshextres.dll
2006-11-02 11:52 42,496 --------- C:\WINDOWS\system32\wpdshextres.dll
2006-10-18 21:47 767,488 --------- C:\WINDOWS\system32\WMVSENCD.dll
2006-10-18 21:47 767,488 --------- C:\WINDOWS\system32\WMVSENCD.dll
2006-10-18 21:47 656,896 --------- C:\WINDOWS\system32\WMVXENCD.dll
2006-10-18 21:47 656,896 --------- C:\WINDOWS\system32\WMVXENCD.dll
2006-10-18 21:47 613,376 --------- C:\WINDOWS\system32\wmpmde.dll
2006-10-18 21:47 613,376 --------- C:\WINDOWS\system32\wmpmde.dll
2006-10-18 21:47 317,440 --------- C:\WINDOWS\system32\MP4SDECD.dll
2006-10-18 21:47 317,440 --------- C:\WINDOWS\system32\MP4SDECD.dll
2006-10-18 21:47 295,936 --------- C:\WINDOWS\system32\wmpeffects.dll
2006-10-18 21:47 295,936 --------- C:\WINDOWS\system32\wmpeffects.dll
2006-10-18 21:47 284,160 --------- C:\WINDOWS\system32\PortableDeviceApi.dll
2006-10-18 21:47 284,160 --------- C:\WINDOWS\system32\PortableDeviceApi.dll
2006-10-18 21:47 259,072 --------- C:\WINDOWS\system32\MPG4DECD.dll
2006-10-18 21:47 259,072 --------- C:\WINDOWS\system32\MPG4DECD.dll
2006-10-18 21:47 259,072 --------- C:\WINDOWS\system32\MP43DECD.dll
2006-10-18 21:47 259,072 --------- C:\WINDOWS\system32\MP43DECD.dll
2006-10-18 21:47 2,603,008 --------- C:\WINDOWS\system32\WpdShext.dll
2006-10-18 21:47 2,603,008 --------- C:\WINDOWS\system32\WpdShext.dll
2006-10-18 21:47 199,168 --------- C:\WINDOWS\system32\PortableDeviceWMDRM.dll
2006-10-18 21:47 199,168 --------- C:\WINDOWS\system32\PortableDeviceWMDRM.dll
2006-10-18 21:47 166,912 --------- C:\WINDOWS\system32\PortableDeviceTypes.dll
2006-10-18 21:47 166,912 --------- C:\WINDOWS\system32\PortableDeviceTypes.dll
2006-10-18 21:47 133,632 --------- C:\WINDOWS\system32\WPDShServiceObj.dll
2006-10-18 21:47 133,632 --------- C:\WINDOWS\system32\WPDShServiceObj.dll
2006-10-18 21:47 132,096 --------- C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
2006-10-18 21:47 132,096 --------- C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
2006-10-18 21:47 130,048 --------- C:\WINDOWS\system32\wmpps.dll
2006-10-18 21:47 130,048 --------- C:\WINDOWS\system32\wmpps.dll
2006-10-18 21:47 101,888 --------- C:\WINDOWS\system32\PortableDeviceClassExtension.dll
2006-10-18 21:47 101,888 --------- C:\WINDOWS\system32\PortableDeviceClassExtension.dll
2006-10-18 21:47 1,574,912 --------- C:\WINDOWS\system32\WMVENCOD.dll
2006-10-18 21:47 1,574,912 --------- C:\WINDOWS\system32\WMVENCOD.dll
2006-10-18 21:47 1,543,680 --------- C:\WINDOWS\system32\WMVDECOD.dll
2006-10-18 21:47 1,543,680 --------- C:\WINDOWS\system32\WMVDECOD.dll
2006-10-18 21:47 1,382,912 --------- C:\WINDOWS\system32\WMVSDECD.dll
2006-10-18 21:47 1,382,912 --------- C:\WINDOWS\system32\WMVSDECD.dll
2006-10-18 20:00 17,408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe
2006-10-18 20:00 17,408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-13 22:39 -------- d-------- C:\Program Files\Common Files
2006-11-13 18:39 -------- d-------- C:\Program Files\Mozilla Firefox
2006-11-13 18:18 -------- d-------- C:\Program Files\MSN Messenger
2006-11-13 18:08 -------- d-------- C:\Program Files\Registry Mechanic
2006-11-13 17:54 -------- d-------- C:\Program Files\Registry Repair 2006
2006-11-13 17:15 -------- d-------- C:\Program Files\Alwil Software
2006-11-13 16:43 -------- d-------- C:\Program Files\SpywareBlaster
2006-11-13 09:49 -------- d-------- C:\Program Files\Spyware Doctor
2006-11-13 09:35 -------- d-------- C:\Documents and Settings\laptop\Application Data\PC Tools
2006-11-12 16:25 -------- d-------- C:\Program Files\Windows NT
2006-11-12 16:24 -------- d-------- C:\Program Files\Outlook Express
2006-11-12 16:12 -------- d-------- C:\Program Files\Network Associates
2006-11-12 16:12 -------- d-------- C:\Program Files\Common Files\Network Associates
2006-11-12 16:12 -------- d-------- C:\Program Files\Common Files\Cisco Systems
2006-11-12 14:18 -------- d-------- C:\Program Files\Windows Media Player
2006-11-12 14:07 -------- d-------- C:\Program Files\Lavasoft
2006-11-12 14:07 -------- d-------- C:\Documents and Settings\laptop\Application Data\Lavasoft
2006-11-12 13:54 -------- d-------- C:\Program Files\LimeWire
2006-11-12 13:47 -------- d-------- C:\Documents and Settings\laptop\Application Data\LimeWire
2006-11-11 18:51 -------- d-------- C:\Documents and Settings\laptop\Application Data\Real
2006-11-11 18:49 -------- d-------- C:\Program Files\Real
2006-11-11 18:49 -------- d-------- C:\Program Files\Common Files\xing shared
2006-11-11 18:49 -------- d-------- C:\Program Files\Common Files\Real
2006-11-11 18:41 -------- d-------- C:\Program Files\Windows Media Connect 2
2006-11-11 18:39 -------- d-------- C:\Program Files\QuickTime
2006-11-11 18:33 -------- d-------- C:\Documents and Settings\laptop\Application Data\Macromedia
2006-11-11 18:32 -------- d-------- C:\Program Files\Java
2006-11-11 13:22 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-11-11 13:21 -------- d-------- C:\Program Files\Microsoft.NET
2006-11-11 13:21 -------- d-------- C:\Program Files\Microsoft Office
2006-11-11 13:21 -------- d-------- C:\Program Files\Common Files\System
2006-11-11 13:21 -------- d-------- C:\Program Files\Common Files\DESIGNER
2006-11-10 21:06 -------- d-------- C:\Program Files\Microsoft Office 2003
2006-11-10 20:47 -------- d-------- C:\Program Files\FILES
2006-11-10 20:45 -------- d-------- C:\Program Files\MagicISO
2006-11-07 22:38 -------- d-------- C:\Program Files\Internet Explorer
2006-11-07 19:47 -------- d-------- C:\Documents and Settings\laptop\Application Data\Sony Corporation
2006-11-03 10:04 8287232 --a------ C:\WINDOWS\system32\wmploc.dll
2006-11-03 10:01 272896 --a------ C:\WINDOWS\system32\wmerror.dll
2006-11-03 10:01 100352 --a------ C:\WINDOWS\system32\wmpshell.dll
2006-11-03 09:59 7680 --a------ C:\WINDOWS\system32\asferror.dll
2006-11-02 20:29 -------- d-------- C:\Program Files\WinRAR
2006-11-02 20:24 -------- d---s---- C:\Documents and Settings\laptop\Application Data\Microsoft
2006-11-02 20:00 -------- d-------- C:\Program Files\Winamp
2006-11-02 19:44 -------- d-------- C:\Documents and Settings\laptop\Application Data\Mozilla
2006-11-02 19:34 -------- d-------- C:\Documents and Settings\laptop\Application Data\Sun
2006-11-02 17:25 -------- d-------- C:\Program Files\RegCleaner
2006-11-02 17:10 -------- d-------- C:\Program Files\MP3ext
2006-11-02 17:08 -------- d-------- C:\Program Files\DivX
2006-11-02 17:00 -------- d-------- C:\Program Files\XviD
2006-11-02 16:41 -------- d-------- C:\Documents and Settings\laptop\Application Data\VanDale
2006-11-02 16:39 -------- d-------- C:\Program Files\Sony
2006-11-02 16:07 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-02 16:07 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-11-02 15:55 -------- d-------- C:\Documents and Settings\laptop\Application Data\Adobe
2006-11-02 14:34 -------- d-------- C:\Program Files\Common Files\SWF Studio
2006-11-02 14:34 -------- d-------- C:\Documents and Settings\laptop\Application Data\sony
2006-11-02 14:09 -------- d-------- C:\Documents and Settings\laptop\Application Data\Toshiba
2006-10-18 21:58 8704 --a------ C:\WINDOWS\system32\wdfmgr.exe
2006-10-18 21:58 8704 --a------ C:\WINDOWS\system32\uwdf.exe
2006-10-18 21:47 991744 --a------ C:\WINDOWS\system32\drmv2clt.dll
2006-10-18 21:47 937984 --a------ C:\WINDOWS\system32\WMNetMgr.dll
2006-10-18 21:47 757248 --a------ C:\WINDOWS\system32\wmadmod.dll
2006-10-18 21:47 63488 --a------ C:\WINDOWS\system32\wpdmtpus.dll
2006-10-18 21:47 629760 --a------ C:\WINDOWS\system32\wpd_ci.dll
2006-10-18 21:47 603648 --a------ C:\WINDOWS\system32\WMSPDMOD.dll
2006-10-18 21:47 542720 --a------ C:\WINDOWS\system32\blackbox.dll
2006-10-18 21:47 535040 --a------ C:\WINDOWS\system32\wmdrmsdk.dll
2006-10-18 21:47 429056 --a------ C:\WINDOWS\system32\wmdrmdev.dll
2006-10-18 21:47 414208 --a------ C:\WINDOWS\system32\msscp.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\WMVADVE.DLL
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\WMVADVD.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wdfapi.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\MPG4DMOD.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\MP4SDMOD.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\MP43DMOD.dll
2006-10-18 21:47 37376 --a------ C:\WINDOWS\system32\wmdmps.dll
2006-10-18 21:47 35840 --a------ C:\WINDOWS\system32\wpdconns.dll
2006-10-18 21:47 356352 --a------ C:\WINDOWS\system32\wpdsp.dll
2006-10-18 21:47 348672 --a------ C:\WINDOWS\system32\wmdrmnet.dll
2006-10-18 21:47 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll
2006-10-18 21:47 321536 --a------ C:\WINDOWS\system32\mswmdm.dll
2006-10-18 21:47 314880 --a------ C:\WINDOWS\system32\wmpdxm.dll
2006-10-18 21:47 276992 --a------ C:\WINDOWS\system32\audiodev.dll
2006-10-18 21:47 27136 --a------ C:\WINDOWS\system32\mspmsnsv.dll
2006-10-18 21:47 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-10-18 21:47 242688 --a------ C:\WINDOWS\system32\wmpasf.dll
2006-10-18 21:47 229376 --a------ C:\WINDOWS\system32\cewmdm.dll
2006-10-18 21:47 222208 --a------ C:\WINDOWS\system32\wmasf.dll
2006-10-18 21:47 212992 --a------ C:\WINDOWS\system32\MFPLAT.dll
2006-10-18 21:47 211456 --a------ C:\WINDOWS\system32\qasf.dll
2006-10-18 21:47 204288 --a------ C:\WINDOWS\system32\wmpsrcwp.dll
2006-10-18 21:47 179712 --a------ C:\WINDOWS\system32\msnetobj.dll
2006-10-18 21:47 175616 --a------ C:\WINDOWS\system32\mspmsp.dll
2006-10-18 21:47 1661440 --a------ C:\WINDOWS\system32\wmpencen.dll
2006-10-18 21:47 157184 --a------ C:\WINDOWS\system32\wmidx.dll
2006-10-18 21:47 154624 --a------ C:\WINDOWS\system32\wpdmtp.dll
2006-10-18 21:47 1329152 --a------ C:\WINDOWS\system32\WMSPDMOE.dll
2006-10-18 21:47 11264 --a------ C:\WINDOWS\system32\LAPRXY.dll
2006-10-18 21:47 1117696 --a------ C:\WINDOWS\system32\WMADMOE.dll
2006-10-18 20:03 100864 --a------ C:\WINDOWS\system32\logagent.exe
2006-10-18 20:00 38528 --a------ C:\WINDOWS\system32\drivers\wpdusb.sys
2006-10-18 20:00 249856 --a------ C:\WINDOWS\system32\drmupgds.exe
2006-10-02 15:28 312128 --------- C:\WINDOWS\system32\msdelta.dll
2006-09-28 20:13 95344 --------- C:\WINDOWS\system32\WUDFCoinstaller.dll
2006-09-28 19:00 82944 --------- C:\WINDOWS\system32\drivers\WudfRd.sys
2006-09-28 18:56 55808 --------- C:\WINDOWS\system32\WudfSvc.dll
2006-09-28 18:56 316416 --------- C:\WINDOWS\system32\WUDFx.dll
2006-09-28 18:56 165376 --------- C:\WINDOWS\system32\WudfPlatform.dll
2006-09-28 18:56 146432 --------- C:\WINDOWS\system32\WudfHost.exe
2006-09-28 18:55 77568 --------- C:\WINDOWS\system32\drivers\WudfPf.sys
2006-09-25 17:58 23856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2006-09-13 06:07 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-08-25 16:51 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-25 04:47 115880 --------- C:\WINDOWS\system32\pxinsi64.exe
2006-08-21 13:28 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 10:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 12:59 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
2006-08-02 12:40 62 --ahs---- C:\Documents and Settings\laptop\Application Data\desktop.ini


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"VAIOCameraUtility"="\"C:\\Program Files\\Sony\\VAIO Camera Utility\\VCUServe.exe\""
"SonyPowerCfg"="\"C:\\Program Files\\Sony\\VAIO Power Management\\SPMgr.exe\""
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"=""
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"Spyware Doctor"=""

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"Spyware Doctor"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"
"{d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3}"="archenteric"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
"archenteric"="{d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeluxeCommunications]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Dxc"
"hkey"="HKLM"
"command"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NEWDOT~2"
"hkey"="HKLM"
"command"="rundll32 C:\\PROGRA~1\\NEWDOT~1\\NEWDOT~2.DLL,ClientStartup -s"
"inimapping"="0"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Completion time: 06-11-13 23:01:11.84
C:\ComboFix.txt ... 06-11-13 23:01
C:\ComboFix2.txt ... 06-11-13 22:41
C:\ComboFix3.txt ... 06-11-13 21:49

casualties

Legacy Member
HIJACK THIS

Logfile of HijackThis v1.99.1
Scan saved at 23:08:54, on 13/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\laptop\LOCALS~1\Temp\Rar$EX00.562\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com/en/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Domain Helper - {B8A5DE1C-BC13-4DD2-BF00-7BE3C603F9F2} - C:\WINDOWS\system32\DomainHelper.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Add RSS Support Site to VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: archenteric - {d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3} - C:\WINDOWS\system32\impgsje.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe


Alvast bedankt voor de hulp!

Jurgenv1

Legacy Member
* Download SmitfraudFix (by S!Ri)
Unzip het naar je bureaublad.
Lees hier hoe je op de juiste wijze moet unzippen/uitpakken.
Dit zal een nieuwe map op je bureaublad aanmaken met de naam Smitfraudfix
Verder nog niet gebruiken.

* Start nu je pc op in VEILIGE MODE. ( zonder netwerkondersteuning! )
Hoe start ik in veilige mode op.

* Clean de Cache and Cookies in IE:
  • Sluit Internet Explorer.
  • Ga naar Configuratiescherm > Internet Opties > tab Algemeen
  • Klik de "Cookies verwijderen" knop
  • Klik op de "Bestanden verwijderen" knop ernaast
  • Vink aan: "Ook alle off line items verwijderen", klik OK
* Clean de Cache and Cookies in Firefox (In geval Firefox geïnstalleerd is):
  • Go to Extra > Opties.
  • Klik Privacy in het menu.
  • Klik op de knop wissen (Geschiedenis, Cookies, Cache).
  • Klik OK om het venster opnieuw te sluiten.
* Clean andere Temporary files + Prullenbak
  • Ga naar start > uitvoeren en typ: cleanmgr en klik ok.
  • Laat het je systeem scannen op bestanden die moeten verwijderd worden
  • Zorg er wel voor dat je daar enkel maar 'tijdelijke bestanden', 'tijdelijke internetbestanden' en 'prullenbak' staan aangevinkt.
  • Klik daarna op ok.
* Open de SmitfraudFix map en dubbelklik smitfraudfix.cmd
Kies optie #2 - Clean door 2 te typen en op "Enter" te klikken.

Er zal gevraagd worden : "Registry cleaning - Do you want to clean the registry ?"; antwoord "Yes/ja" door Y te typen en daarna op "Enter" te klikken. Dit zal je bureaublad terug herstellen en registersleutels die deze infectie heeft gemaakt terug verwijderen.

Daarna zal de tool nagaan als wininet.dll is geïnfecteerd. Indien dit het geval is, zal er gevraagd worden om de geïnfecteerde wininet.dll te herplaatsen met een niet geïnfecteerde kopie van wininet.dll aanwezig op je computer (indien gevonden); antwoord "Yes/ja" door Y te typen en daarna op Enter te klikken.

De tool zal daarna je computer opnieuw laten opstarten om de restanten te verwijderen;
Indien het niet automatisch opstart, start je pc zelf opnieuw op naar normale mode terug (dus geen veilige mode)
Een log zal openen na het opnieuw opstarten. Deze bevindt zich ook hier: C:\rapport.txt
Ik heb die log later nodig als checkup.

Opgelet : Optie #2 gebruiken op een niet geïnfecteerde computer zal uw bureaublad verwijderen.

* Voer een onlinescan uit met Panda: http://www.pandasoftware.com/products/activescan.htm
Vink aan: All my computer
Zorg ervoor dat alles aangevinkt is in de scanopties.

Na de scan kan je een log laten maken. Bewaar die log naar je bureaublad en kopieer en plak die in je volgend bericht,
samen met een nieuwe HijackThis Log en de log van smitfraudfix ( C:\rapport.txt )

casualties

Legacy Member
SmitFraudFix v2.120

Scan done at 0:13:38,89, di 14/11/2006
Run from C:\Documents and Settings\laptop\Bureaublad\SmitfraudFix
OS: Microsoft Windows XP [versie 5.1.2600] - Windows_NT
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3}"="archenteric"

[HKEY_CLASSES_ROOT\CLSID\{d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3}\InProcServer32]
@="C:\WINDOWS\system32\impgsje.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3}\InProcServer32]
@="C:\WINDOWS\system32\impgsje.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

C:\WINDOWS\system32\impgsje.dll -> Hoax.Win32.Renos.gen.i
C:\WINDOWS\system32\impgsje.dll -> Deleted


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

casualties

Legacy Member
Logfile of HijackThis v1.99.1
Scan saved at 0:59:08, on 14/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_Task.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\laptop\LOCALS~1\Temp\Rar$EX00.516\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Domain Helper - {B8A5DE1C-BC13-4DD2-BF00-7BE3C603F9F2} - C:\WINDOWS\system32\DomainHelper.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Add RSS Support Site to VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

casualties

Legacy Member
De panda test kan ik niet doen.. :confused: Ik werk met firefox en die test moet via IE en als ik IE opstart krijg ik volgende melding:

Commonshell

I need ResXX/McShield.dll



en krijg bijgevolg IE niet opgestart want elke keer krijg ik zo dat venster als pop up..

Ook bij het opstarten van windows krijg ik nog een venster popup dat een of ander programma gesloten is aangezien dat noodzakelijk was enzo..

casualties

Legacy Member
Man man, stomme 30000 tekens regel..altijd juist 31000..stomme cut/paste zever :angry:


Incident Status Location

Adware:Adware/ActiveSearch Not disinfected C:\Documents and Settings\All Users\Application Data\AutoSearch.dll
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\laptop\Application Data\Mozilla\Firefox\Profiles\wns6aq6j.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/MetriWeb Not disinfected C:\Documents and Settings\laptop\Application Data\Mozilla\Firefox\Profiles\wns6aq6j.default\cookies.txt[.metriweb.be/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\laptop\Application Data\Mozilla\Firefox\Profiles\wns6aq6j.default\cookies.txt[.com.com/]
Potentially unwanted tool:Application/AKeyLogger Not disinfected C:\Documents and Settings\laptop\Bureaublad\15313.rar[aik_trial.exe][smode.dll]
Potentially unwanted tool:Application/Ardamax Not disinfected C:\Documents and Settings\laptop\Bureaublad\setup_akl.exe[WGV.004]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\laptop\Bureaublad\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\laptop\Bureaublad\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Adware:Adware/SuperSpider Not disinfected C:\Documents and Settings\laptop\Bureaublad\spyware_doctor_keygen.exe
Spyware:Cookie/MetriWeb Not disinfected C:\Documents and Settings\laptop\Cookies\laptop@metriweb[1].txt
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\Spytector 1.3.1(4).rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\A Lot Like Love 2006 DVDRip Xvid.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Acala DVD Audio Ripper v.2.4.2.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Acala DVD PSP Ripper v.2.4.6.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Acala DVD Ripper v.2.4.5.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Accepted HD DVDRip Xvid.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Acme CAD Converter v.7.01.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Adobe Audition 2.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Adobe Premiere Pro 2.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Adware Spyware Be Gone v2.53.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Age Of Emipres 2 The Conquerors.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Age Of Emipres 2 The Conquerors.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\AirStrike 3D Operation W.A.T v1.68.rar[Setup.exe]

casualties

Legacy Member
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Alcohol.120.1.9.x.ON.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Amara AIO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Ashampoo Photo Commander v5.10.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\ATV Mud Racer.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Audio Edit Magic v.9.2.1.346.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Audio Jukebox 1.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Bandwidth Meter Pro v2.1.491.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\BearShare Pro 5.2.5.3.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Borat CAM Xvid.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Burnout Revenge XBOX iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\BWMeter 2.6.1.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Caesar 4-RELOADED iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Chameleon Clock ver.3.7.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\CineCap Standard V1.40.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Color7 Video Converter v7.9.0.3.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Comanche 4 iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Combat Wings Battle of Britain iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Combat Wings Battle of Britain iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Comic Book Manager 1.12.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Company of Heroes iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Conan the Barbarian 1982 Collectors Edition DIVX.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Confessions Of A Dangerous Mind DVDRIP XVID-TEG.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\CyberLink MagicSports ver.3.00.0925.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Death Of A President 2006 LiMiTED DVDRip Xvid-iMBT.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\DigitSoft DiskShop v2.9.1767.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Dragon NaturallySpeaking Preferred 9.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\DVDFab Platinum v3.0.3.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\DVDFab Platinum v3.0.3.5.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\EximiousSoft GIF Creator v.3.37.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Far Cry Instincts XBOX iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Farstone Virtual Drive Pro 10.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\FasterFox 2.0.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Flags of Our Fathers 2006 TS Xvid.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Folder Lock 5.6.3.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Font Fitting RoomDeluxe v.2.8.1.5.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Football Manager 2007 iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\FotoBatch ver. 5.0.3 build 6420.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Ghetto Fights 2 DVDRip Xvid.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Ghost Recon Advanced Warfighter (NTSC) (PS2).rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Goldfish Aquarium v2.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\GoldWave v5.16.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\GTA Vice City Stories PSP iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Halo 2 XBOX iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Handy Password 3.9.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\HDD Regenerator v1.51.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\HDGuard 4.0.0.6.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Hirens BootCD 8.6.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Hitman Blood Money XBOX iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Hokkabaz 2006 CAM Xvid HQ.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Ideal DVD Copy 2.1.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Idpack Pro 7.5.59 Options.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Internet Download Accelerator 5.1.1.1045.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Intervideo WinDVD Platinum 8.0.6.24.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Jaws 7.10.500.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\John Tucker Must Die DVDRip Xvid-ALLiANCE.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Just Checking 3.07.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Kingdia DVD Audio Ripper v3.0.3.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Little Man 2006 DVDRip Xvid.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Macromedia Studio 8.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Mafia Winter Edition iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Mafia Winter Edition iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Magic DVD Creator v7.9.0.3.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Magix Music Maker 2006.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Makeinst 8.8.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Mass Downloader 3.2 Build 661 Vista Co.rar[Setup.exe]

casualties

Legacy Member
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Mass Downloader 3.2.661.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Mdm Zinc 2.5.0.24.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Medal Of Honor Allied Assault.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Medieval II Total War-RELOADED iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Medieval II Total War-RELOADED iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Melissa P. DVDRip Xvid-aXXo (Italiano).rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Microsoft Office 2007 Enterprise iSO-WiNK.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Microsoft Windows Vista Final iSO-BillGates.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Mortal Kombat Armageddon (NTSC) (PS2).rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Movie DVD Maker v.1.7.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\My Notes Keeper 1.62.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\My Screen Recorder Pro 2.43.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\n00zn00zn00zn00z.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\NATURAL CITY DVDRip Xvid.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Navicat MySQL 7.2.8.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\NBA 2K6 XBOX iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Neo Contra (NTSC) (PS2).rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Nero 7 Premium Reloaded 7.5.7.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Nik Color Efex Pro 2.0 - complete edition.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\NOD32 Antivirus 2.70.12 RC1.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\NOD32 Antivirus System v2.70.12 RC1.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Okoker ISO Maker 1.7.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Open Season (NTSC) (PS2).rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Pacific Storm iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Paragon Hard Disk Manager Pro 8.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\PC Auto Shutdown 3.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\PDF Creator Plus 3.0.0.4.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\PDF Creator Plus v3.0.0.4.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\PDF2Word v 2.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Perfume The Story of a Murderer TC Xvid-PUKKA.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Phantasy Star Universe-RECHARGED iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Photo Crop Editor 1.05.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Photolightning 4.52.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Pinnacle Studio MediaSuite 10.6.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Pinnacle Studio Plus 9.4.3.56.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Pizza LiMITED DVDRip Xvid-ALLiANCE.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Premium Clock 2.4.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Pro Evolution Soccer 6 (English Version).rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Project Engine Server And Client Enterprise Edition 2006.14.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Reatrded Animal Babies DVDR.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Registry Mechanic 6.0.0.750.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Registry Mechanic v6.00.750.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\RegistryFix ver.5.5.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Repro Pro 2.3.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Resident Evil 4 (PS2).rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Shut Down Expert 4.93.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Silent Hill 2006 DVDRip Xvid.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Slither DVDRip Xvid.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Smart PC Professional 4.2.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\SolSuite v.6.11.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\SoundEdit Pro 2.1.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Splinter Cell Double Agent (PS2).rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Splinter Cell Double Agent PC DVD9 iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\SpyRemover v2.64.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Spyware Doctor 4.0.0.2620.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Super Internet TV 6.8.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Symantec AntiVirus Corporate Edition v10.1.5.5000 Retai.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Symantec AntiVirus Corporate Edition v10.1.5.5000 Retail iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\The Godfather The Game PC iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\The Godfather The Game XBOX iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\The Guild 2-RELOADED iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\The Hill Have Eyes DVDRip Xvid.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\The Illusionist 2006 TC XViD-BeStDivX.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\The Legend of Spyro A New Beginning (PS2 - PAL).rar[Setup.exe]

casualties

Legacy Member
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\The Omen 2006 DVDRip Xvid-A4O.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\The Print Shop 21 Deluxe.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\The Return (2006).rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\The Return CAM VCD-CAMERA.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\The Scorpion King (PS2).rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\The.illusionist.tc-bestDivX Options.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Tom Clancys - Ghost Recon Advanced Warfighter XBOX iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\TomTom Mobile v5.20.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Tony Hawks Project 8 XBOX iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Total Overdose A Gunslingers Tale in Mexico XBOX iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Tuneup Utilities 2006 v5.0.2335.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Twitches 2005 DVDRip Xvid.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Ulead Burn Now ver.1.50.13.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Ulead DVD MovieFactory 5.3 Plus.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Ultimate Defrag 1.29.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\UltimateDefrag 1.29.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Ultra DVD Creator ver.1.7.2.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Unreal Championship 2 XBOX iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Unreleased Notorious B.I.G. Acapella.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Urban Chaos Riot Response XBOX iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Utawareru Mono PS2 DVD iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Virtual Cd V.8.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Virtutech Simics 3.0.22.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Visual Business Cards v4.16.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\VueScan Pro ver.8.3.77.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\VueScan v.8.3.78.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Webroot Window Washer 6.0.5.409.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Wild Arms - Altercode F (PS2 ISO DVD9.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Winclear 1.0.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Windows Live Messenger 8.1.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\WinXP Manager 5.0.2.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\WWII Battle Over The Pacific-iRRM iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\WWII Battle Over The Pacific-iRRM iSO.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Xilisoft DVD Ripper Platinum 4.0.58.11.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\XSite Pro 1.54.rar[Setup.exe]
Virus:W32/Sdbot.HLL.worm Disinfected C:\Documents and Settings\laptop\Shared\_\Yamato 2005 DVDRip Xvid-CiNE0S.rar[Setup.exe]
Adware:Adware/Zenosearch Not disinfected C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun2.exe
Virus:Trj/Downloader.KNM Disinfected C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun3.exe
Virus:Trj/Downloader.KNM Disinfected C:\Documents and Settings\LocalService\Local Settings\Temp\~ds39990.tmp
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\eltobs7x.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/MetriWeb Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\eltobs7x.default\cookies.txt[.metriweb.be/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\eltobs7x.default\cookies.txt[.bluestreak.com/]
Virus:Trj/Downloader.LAF Disinfected C:\WINDOWS\system32\ldcore.dll
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe



alles wat in die c/D&S/laptop/Shared staat zijn allemaal dingen waar ik van verschiet :o allemaal games en appz die ik NOOIT gedownload heb of eender wat..Zeer raar.

Alvast nog eens bedankt al voor de hulp!! :)

Jurgenv1

Legacy Member
Dat van de shared map komt door een worm die je bandbreedte heeft gebruikt om warez te downloaden etc... ;)

* Download en unzip Killbox naar je bureaublad.
Klik op killbox.exe.
Selecteer de optie "Delete on reboot".
In het veld "Full Path of File to Delete" kopieer en plak je het volgende:

C:\Documents and Settings\All Users\Application Data\AutoSearch.dll

Klik op de knop: single file (!Belangrijk!)

Daarna, Klik op de rode cirkel met het wit kruisje erin.
Killbox zal zeggen dat deze file zal verwijderd worden on reboot.. vraagt om nu te rebooten. Klik YES.

Je pc moet nu rebooten.

* Download ATF cleaner (by Atribune)

Dubbelklik op ATF cleaner om het programma te starten.
Op het tabblad "Main", plaats je een vinkje bij Select All.
Klik op de knop Empty Selected.

Gebruik je ook Firefox als browser:
Klik op tabblad "Firefox", plaats een vinkje bij Select All.
Wil je de door Firefox opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
(dit verwijdert het vinkje bij "Firefox saved passwords")
Klik op de knop Empty Selected.

Gebruik je ook Opera als browser:
Klik op tabblad "Opera", plaats een vinkje bij Select All.
Wil je de door Opera opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
Klik op de knop Empty Selected.
Ga naar het tabblad "Main" en klik op de knop Exit om het programma af te sluiten.

* Post dan een nieuw hijackthis logje hier en vertel hoe alles verder werkt.

casualties

Legacy Member
Nog steeds dezelfde foutmelding bij het opstarten van XP..
http://i15.tinypic.com/2yuxbug.jpg

Logfile of HijackThis v1.99.1
Scan saved at 18:08:05, on 14/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_Task.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Documents and Settings\laptop\Bureaublad\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Domain Helper - {B8A5DE1C-BC13-4DD2-BF00-7BE3C603F9F2} - C:\WINDOWS\system32\DomainHelper.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Add RSS Support Site to VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.
Terug
Bovenaan