Archief - format C vol pron etc

Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.

mtm

Legacy Member
Logfile of HijackThis v1.99.1
Scan saved at 13:33:45, on 15/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Common Files\Nokia\Services\ServiceLayer.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
D:\Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Gebruiker\Bureaublad\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\RunOnce: [MessengerPlusUninstall] C:\WINDOWS\system32\cmd.exe /C "C:\DOCUME~1\GEBRUI~1\LOCALS~1\Temp\MsgPlusUninst.bat"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O13 - WWW. Prefix: http://ehttp.cc/?
O16 - DPF: symsupportutil - https://www-secure.symantec.com/region/reg_eu/techsupp/activedata/symsupportutil.CAB
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B460F607-2A6E-48BC-A165-DBCDE095E5E5}: NameServer = 195.238.2.22 195.238.2.21
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Jurgenv1

Legacy Member
* Download en installeer AVG Anti-Spyware.

  • Na de installatie, open AVG Anti-Spyware:
    * onder "Status", klik op Change state naast "Resident shield". (wijzig van active naar inactive!)
    * onder "Update", klik op de Start update knop.
    * onder "Scanner", tab "Settings":
    • - onder "How to act?", klik op "Recommended actions" en selecteer Quarantine. (ZEER BELANGRIJK!)
      * onder "Reports", selecteer Automatically generate report after every scan en verwijder het vinkje bij Only if threats were found
    Sluit AVG Anti-Spyware. Laat het nog niet scannen.

* Als je Adaware SE nog niet geïnstalleerd hebt, download, installeer en update het dan volgens de richtlijnen
die je kan vinden op: http://users.pandora.be/marcvn/spyware/1414188.htm
Download link van Ad-aware: http://www.lavasoftusa.com/products/ad-aware_se_personal.php

* Start je computer op in VEILIGE MODUS

* Voer een volledige scan uit met Adaware en verwijder alles wat gevonden wordt.

* Start AVG Anti-Spyware.
  • * Klik op Scan en kies Complete System Scan.
    Na de scan; volg onderstaande instructies :
    BELANGRIJK : Klik niet op de "Save Scan Report" knop vooraleer je de "Apply all Actions" knop hebt aangeklikt !
    * Draag er zorg voor dat Set all elements to: op Quarantine staat (1),
    zoniet klik op de link en kies Quarantine in de popup menu. (2)
    (Dit geldt niet voor cookies, deze worden onveranderlijk gedelete !)
    * Onderaan het venster klik op de Apply all Actions knop. (3)
    ewidoscan.jpg

    * Wanneer je de melding krijgt 'All actions have been applied', klik je onderaan op de knop Save Report.

* Herstart je computer in normale modus.

* Download ATF cleaner (by Atribune)

Dubbelklik op ATF cleaner om het programma te starten.
Op het tabblad "Main", plaats je een vinkje bij Select All.
Klik op de knop Empty Selected.

Gebruik je ook Firefox als browser:
Klik op tabblad "Firefox", plaats een vinkje bij Select All.
Wil je de door Firefox opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
(dit verwijdert het vinkje bij "Firefox saved passwords")
Klik op de knop Empty Selected.

Gebruik je ook Opera als browser:
Klik op tabblad "Opera", plaats een vinkje bij Select All.
Wil je de door Opera opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
Klik op de knop Empty Selected.
Ga naar het tabblad "Main" en klik op de knop Exit om het programma af te sluiten.

* Post dan een nieuw hijackthis logje hier met het rapport van AVG antispyware.

mtm

Legacy Member
Logfile of HijackThis v1.99.1
Scan saved at 14:22:25, on 15/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
D:\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\rundll32.exe
D:\Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Gebruiker\Bureaublad\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O13 - WWW. Prefix: http://ehttp.cc/?
O16 - DPF: symsupportutil - https://www-secure.symantec.com/region/reg_eu/techsupp/activedata/symsupportutil.CAB
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B460F607-2A6E-48BC-A165-DBCDE095E5E5}: NameServer = 195.238.2.22 195.238.2.21
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

mtm

Legacy Member
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 14:16:38 15/10/2006

+ Scan result:



C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem10.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem1B.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem1D.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem1F.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem21.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem24.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem25.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem26.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem27.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem29.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem2B.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem9B.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem9D.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\Rem9F.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\RemA.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\RemA1.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\RemC.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temp\RemE.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Jan\Local Settings\Temp\livevideoplugin.exe -> Dialer.WebDialer : Cleaned with backup (quarantined).
C:\Program Files\Webdialer\livevideoplugin.exe -> Dialer.WebDialer : Cleaned with backup (quarantined).
C:\Documents and Settings\Gebruiker\Local Settings\Temporary Internet Files\Content.IE5\ITWNUPON\MsgPlus-251[1].exe/70000011.exe -> Downloader.Swizzor.af : Cleaned with backup (quarantined).
C:\Program Files\C2Media\Setup.exe -> Downloader.Swizzor.af : Cleaned with backup (quarantined).
C:\Program Files\Messenger Plus! 2\Setup.dat/70000011.exe -> Downloader.Swizzor.af : Cleaned with backup (quarantined).
C:\WINDOWS\AddClass.exe -> Hijacker.StartPage.ef : Cleaned with backup (quarantined).
:mozilla.68:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.87:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\gebruiker@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\gebruiker@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.46:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.47:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.83:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\gebruiker@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Zus\Cookies\[email protected][2].txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.99:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.108:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.109:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Jan\Cookies\[email protected][2].txt -> TrackingCookie.Lop : Cleaned.
C:\Documents and Settings\Pieter\Cookies\[email protected][2].txt -> TrackingCookie.Lop : Cleaned.
:mozilla.45:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.32:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.33:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.34:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.28:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.29:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.30:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.17:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.18:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.110:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.111:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.112:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\lmvuqqx0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end

mtm

Legacy Member
Nog 2 vraagjes:

Vroeger was er een programma dat Microsoft Anti-Spyware heette. Maar ik vind het niet meer terug. Zou jij mij kunnen helpen?

En ik heb de nieuwste versie van AVG Virusscanner gedownload(avg75f_427a816.exe), maar hij vraagt achter een licentienr.
Kan je me hierbij ook helpen?

Alvast bedankt voor je moeite en tijd.

Jurgenv1

Legacy Member
Ik denk dat je de verkeerde AVG gedownload hebt, google eens naar AVG free.

* Download deljob.bat
Sla het bestandje op je bureaublad op en dubbelklik deljob.bat

Herstart dan je pc en post een nieuw hijackthis logje en post ook de inhoud van logit.txt dat nu ook op je bureaublad zal staan.

mtm

Legacy Member
Het antwoord op de eerste vraag hebk gevonde tis nu Windows Defender ofzoiets.
Maar door de format C staat Service Pack 1 terug op de pc en SP2 is nodig. Kun je me hierbij helpen?

mtm

Legacy Member
--------------------------------------------------------
Files In Tasks Dir
.
--------------------------------------------------------
Lop-files Found
.
--------------------------------------------------------
Files After Deletion
.
--------------------------------------------------------

mtm

Legacy Member
Logfile of HijackThis v1.99.1
Scan saved at 14:56:35, on 15/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
D:\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\rundll32.exe
D:\Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Gebruiker\Bureaublad\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O13 - WWW. Prefix: http://ehttp.cc/?
O16 - DPF: symsupportutil - https://www-secure.symantec.com/region/reg_eu/techsupp/activedata/symsupportutil.CAB
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B460F607-2A6E-48BC-A165-DBCDE095E5E5}: NameServer = 195.238.2.22 195.238.2.21
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Jurgenv1

Legacy Member
Fix deze nog eens in hijackthis:

O13 - WWW. Prefix: http://ehttp.cc/?

Ik zie ook dat je geen bescherming hebt op je pc! Dus installeer een goeie en gratis AV die je pc niet zo belast zoals AVG free, Avast of antivir (Makkelijk te vinden via Google.)

Installeer ook eens een gratis en goeie Firewall zoals Sygate personal firewall, kerio personal firewall of Zonealarm. :)

Daarna herstart je eens je pc. :)

Ga dan naar http://windowsupdate.microsoft.com/ en installeer service pack 2 en de daaropvolgende updates.

Post pas dan een nieuw hijackthis logje hier.

mtm

Legacy Member
Logfile of HijackThis v1.99.1
Scan saved at 17:02:19, on 15/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\AVG Anti-Spyware 7.5\guard.exe
D:\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
D:\ZoneAlarm\zlclient.exe
D:\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Gebruiker\Bureaublad\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "D:\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: symsupportutil - https://www-secure.symantec.com/region/reg_eu/techsupp/activedata/symsupportutil.CAB
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160921233897
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1160922488511
O17 - HKLM\System\CCS\Services\Tcpip\..\{B460F607-2A6E-48BC-A165-DBCDE095E5E5}: NameServer = 195.238.2.22 195.238.2.21
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

mtm

Legacy Member
Ik heb alle updates geinstalleerd via de site die je me gegeven hebt, maar service pack 2 is nog steeds niet geinstalleerd.

mtm

Legacy Member
Logfile of HijackThis v1.99.1
Scan saved at 20:38:17, on 17/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
D:\AVG Anti-Spyware 7.5\guard.exe
D:\Grisoft\AVGFRE~1\avgamsvr.exe
D:\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
D:\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\e3ae9c47fe2d587c4f8623a201f595da\update\update.exe
D:\Firefox\firefox.exe
C:\Documents and Settings\Gebruiker\Bureaublad\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "D:\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Snelle start.lnk = D:\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: symsupportutil - https://www-secure.symantec.com/region/reg_eu/techsupp/activedata/symsupportutil.CAB
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160921233897
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1160922488511
O17 - HKLM\System\CCS\Services\Tcpip\..\{B460F607-2A6E-48BC-A165-DBCDE095E5E5}: NameServer = 195.238.2.22 195.238.2.21
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Jurgenv1

Legacy Member
Download combofix.exe: http://download.bleepingcomputer.com/sUBs/combofix.exe
Plaats het op je bureaublad.
Dubbelklik er op om het programma te starten.
In het scherm dat verschijnt tik je een Y in om het cleaningsprocess te starten.
Volg de instructies op het scherm.
Als het tooltje klaar is, opent er een logfile (combofix.txt) Post de inhoud van dit bestandje samen met een nieuwe hijackthislog.

mtm

Legacy Member
Gebruiker - 06-10-21 11:08:52,06 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Documents and Settings\Gebruiker\Bureaublad"

((((((((((((((((((((((((((((((( Files Created from 2006-09-21 to 2006-10-21 ))))))))))))))))))))))))))))))))))


2006-10-20 17:27 41,984 --------- C:\WINDOWS\Ctregrun.exe
2006-10-20 17:24 44,032 --------- C:\WINDOWS\system32\CTSVCCDA.EXE
2006-10-20 17:24 25,088 --------- C:\WINDOWS\system32\CTSVCCTL.EXE
2006-10-20 17:19 149,504 --a------ C:\WINDOWS\UNWISE.EXE
2006-10-18 13:18 121,856 --------- C:\WINDOWS\system32\xmllite.dll
2006-10-17 20:49 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2006-10-15 17:24 11,776 --------- C:\WINDOWS\system32\spnpinst.exe
2006-10-15 16:41 614,912 --a------ C:\WINDOWS\system32\h323msp.dll
2006-10-15 16:41 39,936 --a------ C:\WINDOWS\system32\mf3216.dll
2006-10-15 16:41 332,288 --a------ C:\WINDOWS\system32\ipnathlp.dll
2006-10-15 16:23 85,376 --a------ C:\WINDOWS\system32\drivers\nabtsfec.sys
2006-10-15 16:23 83,456 --a------ C:\WINDOWS\system32\dpvsetup.exe
2006-10-15 16:23 825,344 --a------ C:\WINDOWS\system32\d3dim700.dll
2006-10-15 16:23 82,432 --a------ C:\WINDOWS\system32\dmscript.dll
2006-10-15 16:23 8,192 --a------ C:\WINDOWS\system32\d3d8thk.dll
2006-10-15 16:23 733,696 --a------ C:\WINDOWS\system32\qedwipes.dll
2006-10-15 16:23 72,192 --a------ C:\WINDOWS\system32\dsdmoprp.dll
2006-10-15 16:23 70,656 --a------ C:\WINDOWS\system32\amstream.dll
2006-10-15 16:23 7,552 --a------ C:\WINDOWS\system32\drivers\mskssrv.sys
2006-10-15 16:23 619,008 --a------ C:\WINDOWS\system32\dx7vb.dll
2006-10-15 16:23 61,440 --a------ C:\WINDOWS\system32\dmcompos.dll
2006-10-15 16:23 60,928 --a------ C:\WINDOWS\system32\dpnhupnp.dll
2006-10-15 16:23 59,904 --a------ C:\WINDOWS\system32\devenum.dll
2006-10-15 16:23 57,856 --a------ C:\WINDOWS\system32\dpwsockx.dll
2006-10-15 16:23 562,688 --a------ C:\WINDOWS\system32\qedit.dll
2006-10-15 16:23 51,328 --a------ C:\WINDOWS\system32\drivers\msdv.sys
2006-10-15 16:23 51,200 --a------ C:\WINDOWS\system32\wstdecod.dll
2006-10-15 16:23 5,504 --a------ C:\WINDOWS\system32\drivers\mstee.sys
2006-10-15 16:23 5,376 --a------ C:\WINDOWS\system32\drivers\mspclock.sys
2006-10-15 16:23 48,640 --a------ C:\WINDOWS\system32\drivers\stream.sys
2006-10-15 16:23 46,592 --a------ C:\WINDOWS\system32\dxdllreg.exe
2006-10-15 16:23 4,992 --a------ C:\WINDOWS\system32\drivers\mspqm.sys
2006-10-15 16:23 4,352 --a------ C:\WINDOWS\system32\drivers\swenum.sys
2006-10-15 16:23 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2006-10-15 16:23 385,536 --a------ C:\WINDOWS\system32\qdvd.dll
2006-10-15 16:23 375,296 --a------ C:\WINDOWS\system32\dpnet.dll
2006-10-15 16:23 367,616 --a------ C:\WINDOWS\system32\dsound.dll
2006-10-15 16:23 363,520 --a------ C:\WINDOWS\system32\psisdecd.dll
2006-10-15 16:23 35,840 --a------ C:\WINDOWS\system32\dmloader.dll
2006-10-15 16:23 35,328 --a------ C:\WINDOWS\system32\mciqtz32.dll
2006-10-15 16:23 35,328 --a------ C:\WINDOWS\system32\dpnhpast.dll
2006-10-15 16:23 30,208 --a------ C:\WINDOWS\system32\dplaysvr.exe
2006-10-15 16:23 3,584 --a------ C:\WINDOWS\system32\dpnlobby.dll
2006-10-15 16:23 3,584 --a------ C:\WINDOWS\system32\dpnaddr.dll
2006-10-15 16:23 28,672 --a------ C:\WINDOWS\system32\dmband.dll
2006-10-15 16:23 279,040 --a------ C:\WINDOWS\system32\qdv.dll
2006-10-15 16:23 27,136 --a------ C:\WINDOWS\system32\ddrawex.dll
2006-10-15 16:23 266,240 --a------ C:\WINDOWS\system32\ddraw.dll
2006-10-15 16:23 24,064 --a------ C:\WINDOWS\system32\dpmodemx.dll
2006-10-15 16:23 229,888 --a------ C:\WINDOWS\system32\dplayx.dll
2006-10-15 16:23 212,480 --a------ C:\WINDOWS\system32\dpvoice.dll
2006-10-15 16:23 21,504 --a------ C:\WINDOWS\system32\dpvacm.dll
2006-10-15 16:23 204,800 --a------ C:\WINDOWS\system32\mswebdvd.dll
2006-10-15 16:23 20,480 --a------ C:\WINDOWS\system32\encapi.dll
2006-10-15 16:23 2,113,536 --a------ C:\WINDOWS\system32\dxdiagn.dll
2006-10-15 16:23 192,512 --a------ C:\WINDOWS\system32\qcap.dll
2006-10-15 16:23 19,456 --a------ C:\WINDOWS\system32\dswave.dll
2006-10-15 16:23 19,328 --a------ C:\WINDOWS\system32\drivers\wstcodec.sys
2006-10-15 16:23 181,760 --a------ C:\WINDOWS\system32\dsdmo.dll
2006-10-15 16:23 181,248 --a------ C:\WINDOWS\system32\dmime.dll
2006-10-15 16:23 18,432 --a------ C:\WINDOWS\system32\dpnsvr.exe
2006-10-15 16:23 17,408 --a------ C:\WINDOWS\system32\msyuv.dll
2006-10-15 16:23 17,024 --a------ C:\WINDOWS\system32\drivers\ccdecode.sys
2006-10-15 16:23 15,360 --a------ C:\WINDOWS\system32\drivers\streamip.sys
2006-10-15 16:23 15,360 --a------ C:\WINDOWS\system32\drivers\mpe.sys
2006-10-15 16:23 140,928 --a------ C:\WINDOWS\system32\drivers\ks.sys
2006-10-15 16:23 14,336 --a------ C:\WINDOWS\system32\msdmo.dll
2006-10-15 16:23 116,736 --a------ C:\WINDOWS\system32\dpvvox.dll
2006-10-15 16:23 11,776 --a------ C:\WINDOWS\system32\drivers\bdasup.sys
2006-10-15 16:23 11,136 --a------ C:\WINDOWS\system32\drivers\slip.sys
2006-10-15 16:23 105,984 --a------ C:\WINDOWS\system32\dmstyle.dll
2006-10-15 16:23 104,448 --a------ C:\WINDOWS\system32\dmusic.dll
2006-10-15 16:23 103,424 --a------ C:\WINDOWS\system32\dmsynth.dll
2006-10-15 16:23 10,880 --a------ C:\WINDOWS\system32\drivers\ndisip.sys
2006-10-15 16:23 1,689,088 --a------ C:\WINDOWS\system32\d3d9.dll
2006-10-15 16:23 1,432,576 --a------ C:\WINDOWS\system32\msvidctl.dll
2006-10-15 16:23 1,298,432 --a------ C:\WINDOWS\system32\dxdiag.exe
2006-10-15 16:23 1,294,336 --a------ C:\WINDOWS\system32\dsound3d.dll
2006-10-15 16:23 1,227,264 --a------ C:\WINDOWS\system32\dx8vb.dll
2006-10-15 16:23 1,179,648 --a------ C:\WINDOWS\system32\d3d8.dll
2006-10-15 16:21 1,092,096 --a------ C:\WINDOWS\system32\esent.dll
2006-10-15 16:17 778,656 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-10-15 16:17 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2006-10-15 16:17 4,288 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-10-15 16:17 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2006-10-15 16:17 27,904 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-10-15 16:17 23,104 --a------ C:\WINDOWS\system32\drivers\avgmfrs.sys
2006-10-15 16:13 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2006-10-15 16:10 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2006-10-15 16:10 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2006-10-15 16:10 351,232 --a------ C:\WINDOWS\system32\winhttp.dll
2006-10-15 16:10 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2006-10-15 16:07 466,200 --a------ C:\WINDOWS\system32\wuapi.dll
2006-10-15 16:07 41,240 --a------ C:\WINDOWS\system32\wups.dll
2006-10-15 16:07 194,840 --a------ C:\WINDOWS\system32\wuaueng1.dll
2006-10-15 16:07 18,200 --a------ C:\WINDOWS\system32\wups2.dll
2006-10-15 16:07 174,360 --a------ C:\WINDOWS\system32\wuauclt1.exe
2006-10-15 16:07 128,280 --a------ C:\WINDOWS\system32\wucltui.dll
2006-10-15 13:38 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-15 13:08 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2006-10-15 13:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2006-10-15 12:54 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2006-10-15 12:54 249,856 --------- C:\WINDOWS\Setup1.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-20 17:53 -------- d-------- C:\Documents and Settings\Gebruiker\Application Data\Xfire
2006-10-20 17:26 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-10-20 17:26 -------- d-------- C:\Program Files\Creative
2006-10-20 17:15 -------- d-------- C:\Program Files\Common Files\InstallShield
2006-10-19 17:29 -------- d-------- C:\Program Files\Common Files\Stardock
2006-10-19 17:29 -------- d-------- C:\Program Files\Common Files
2006-10-18 15:13 -------- d-------- C:\Documents and Settings\Gebruiker\Application Data\AdobeUM
2006-10-18 13:33 -------- d-------- C:\Documents and Settings\Gebruiker\Application Data\Sun
2006-10-18 13:25 -------- d-------- C:\Program Files\Internet Explorer
2006-10-18 12:32 -------- d-------- C:\Program Files\Messenger
2006-10-18 12:31 -------- d-------- C:\Program Files\Outlook Express
2006-10-18 12:31 -------- d-------- C:\Program Files\Common Files\System
2006-10-18 12:27 -------- d---s---- C:\Documents and Settings\Gebruiker\Application Data\Microsoft
2006-10-18 12:27 -------- d-------- C:\Program Files\MSN Messenger
2006-10-17 20:48 -------- d-------- C:\Program Files\Windows Media Player
2006-10-17 20:48 -------- d-------- C:\Program Files\Movie Maker
2006-10-17 20:42 -------- d-------- C:\Program Files\Windows NT
2006-10-17 20:42 -------- d-------- C:\Program Files\NetMeeting
2006-10-17 16:52 -------- d-------- C:\Documents and Settings\Gebruiker\Application Data\Adobe
2006-10-17 16:49 869 --a------ C:\Documents and Settings\Gebruiker\Application Data\AdobeDLM.log
2006-10-17 16:49 0 --a------ C:\Documents and Settings\Gebruiker\Application Data\dm.ini
2006-10-17 16:49 -------- d-------- C:\Program Files\Adobe
2006-10-17 16:46 -------- d-------- C:\Program Files\Common Files\Adobe
2006-10-17 16:43 -------- d-------- C:\Documents and Settings\Gebruiker\Application Data\Talkback
2006-10-15 16:17 -------- d-------- C:\Program Files\Grisoft
2006-10-15 16:17 -------- d-------- C:\Documents and Settings\Gebruiker\Application Data\AVG7
2006-10-15 16:07 -------- d--h----- C:\Program Files\WindowsUpdate
2006-10-15 15:44 -------- d-------- C:\Program Files\Java
2006-10-15 15:42 -------- d-------- C:\Program Files\Common Files\Java
2006-10-15 14:34 44288 --a------ C:\WINDOWS\system32\drivers\cdr4_xp.sys
2006-10-15 14:16 -------- d-------- C:\Program Files\C2Media
2006-10-15 13:30 -------- d-------- C:\Program Files\Messenger Plus! Live
2006-10-15 13:13 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-10-15 13:13 -------- d-------- C:\Documents and Settings\Gebruiker\Application Data\Lavasoft
2006-10-15 13:12 -------- d-------- C:\Program Files\Hewlett-Packard
2006-10-15 13:11 -------- d-------- C:\Program Files\Webdialer
2006-10-15 13:11 -------- d-------- C:\Program Files\Common Files\Nokia
2006-10-15 12:22 -------- d-------- C:\Documents and Settings\Gebruiker\Application Data\Macromedia
2006-10-15 12:16 -------- d-------- C:\Documents and Settings\Gebruiker\Application Data\Mozilla
2006-09-13 07:07 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-08-25 17:51 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-23 00:31 5906432 --------- C:\WINDOWS\system32\ieframe.dll
2006-08-23 00:31 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-08-23 00:31 457728 --------- C:\WINDOWS\system32\msfeeds.dll
2006-08-23 00:31 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-08-23 00:31 225792 --a------ C:\WINDOWS\system32\webcheck.dll
2006-08-23 00:31 175616 --------- C:\WINDOWS\system32\ieui.dll
2006-08-23 00:31 152064 --a------ C:\WINDOWS\system32\msls31.dll
2006-08-23 00:18 78336 --a------ C:\WINDOWS\system32\ieencode.dll
2006-08-23 00:18 206336 --------- C:\WINDOWS\system32\WinFXDocObj.exe
2006-08-23 00:17 40448 --a------ C:\WINDOWS\system32\licmgr10.dll
2006-08-23 00:17 105472 --a------ C:\WINDOWS\system32\url.dll
2006-08-23 00:17 100352 --a------ C:\WINDOWS\system32\occache.dll
2006-08-23 00:16 16896 --a------ C:\WINDOWS\system32\corpol.dll
2006-08-23 00:14 378368 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-08-23 00:14 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-08-23 00:13 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-08-23 00:13 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-08-23 00:13 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-08-23 00:13 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-08-23 00:13 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-08-23 00:13 122880 --a------ C:\WINDOWS\system32\advpack.dll
2006-08-23 00:13 11776 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-08-23 00:11 12288 --------- C:\WINDOWS\system32\msfeedssync.exe
2006-08-23 00:10 61440 --------- C:\WINDOWS\system32\icardie.dll
2006-08-23 00:10 35328 --a------ C:\WINDOWS\system32\imgutil.dll
2006-08-23 00:09 262656 --------- C:\WINDOWS\system32\iertutil.dll
2006-08-23 00:07 45568 --a------ C:\WINDOWS\system32\mshta.exe
2006-08-22 23:37 48128 --a------ C:\WINDOWS\system32\mshtmler.dll
2006-08-22 23:36 380928 --------- C:\WINDOWS\system32\ieapfltr.dll
2006-08-22 23:30 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-08-21 14:28 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 11:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 11:14 128896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-16 13:59 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-27 15:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 10:29 72704 --a------ C:\WINDOWS\system32\hlink.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"
"NVIEW"="rundll32.exe nview.dll,nViewLoadHook"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"Creative Detector"="D:\\Creative\\Creative Zen Micro\\Detector\\CTDetect.exe /R"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"AdaptecDirectCD"="C:\\Program Files\\Adaptec\\Easy CD Creator 5\\DirectCD\\DirectCD.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"SoundMan"="SOUNDMAN.EXE"
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Alcatel\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_08\\bin\\jusched.exe\""
"Zone Labs Client"="\"D:\\ZoneAlarm\\zlclient.exe\""
"Windows Defender"="\"D:\\Windows Defender\\MSASCui.exe\" -hide"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Mijn huidige introductiepagina"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,c4,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,c4,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,c4,02,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"
"AVG7_Run"="D:\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"
"AVG7_Run"="D:\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"
"{553858A7-4922-4e7e-B1C1-97140C1C16EF}"="IE Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgcc"
"hkey"="HKLM"
"command"="D:\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job

Completion time: 06-10-21 11:09:47.14
C:\ComboFix.txt ... 06-10-21 11:09
Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.
Terug
Bovenaan