Mededeling

Collapse
No announcement yet.

Heel mijn windows map gaat eraan.

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Heel mijn windows map gaat eraan.

    Hey, ik heb een virus. Dat razend snel verspreid in mijn windows mappen en ik kan niks doen =(. hier is mijn log



    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 11:33:39, on 19-1-2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Comodo\Firewall\CPF.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Comodo\Firewall\cmdagent.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\sistray.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\plan delta\Bureaublad\HiJackThis_v2.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: (no name) - {040CF5CF-AFC4-4393-B3AE-30B65A5460C4} - C:\WINDOWS\system32\iifdedb.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\hiwgxmia.dll
    O2 - BHO: (no name) - {DFBBE5A4-FD72-41AF-BC02-F47610C4EBD6} - C:\WINDOWS\system32\awtqo.dll (file missing)
    O2 - BHO: (no name) - {ED4438FD-D4D7-48BB-8484-6E2727575BA2} - C:\WINDOWS\system32\jkkjk.dll (file missing)
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
    O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
    O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp .exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [9cb560ac] rundll32.exe "C:\WINDOWS\system32\rwgmqvvc.dll",b
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://www.msi.com.tw
    O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab
    O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/ocis/SiSAutodetectNT.cab
    O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
    O20 - Winlogon Notify: hiwgxmia - C:\WINDOWS\SYSTEM32\hiwgxmia.dll
    O20 - Winlogon Notify: iifdedb - C:\WINDOWS\SYSTEM32\iifdedb.dll
    O20 - Winlogon Notify: winhld32 - winhld32.dll (file missing)
    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

    --
    End of file - 6934 bytes



    En naar een tijdje kriijg ik een error dat mijn pc onstabiel is. en dan is hij super traag. Kunnen jullie misschien helpen?

  • #2
    Ik heb al de meeste weten te verwijderen maar er zitten er nog steeds

    Comment


    • #3
      Mensen kunnen jullie snel een oplossing zoeken plz, sorry dat ik aandring maar steeds meer .dll bestanden worden geinfected. en heel mijn pc word vol gepompt met bestanden van 5kb maar wel 5000 bestanden al. En ik kan ze niet verwijderen want dan krijg ik een error message.

      Comment


      • #4
        Niet zo ongeduldig aub, iedereen wil graag geholpen worden.

        Download de nieuwste versie van Hijackthis:


        Download Combofix naar je bureaublad

        Indien je Combofix al eerder hebt gebruikt, gelieve die versie te verwijderen en Combofix opnieuw te downloaden via bovenstaande link, want Combofix wordt dagelijks geupdate.

        OPMERKING: indien je, tijdens of na het downloaden van Combofix of tijdens het gebruik van Combofix een melding krijgt van je Antivirus- of een andere realtime scanner, schakel dan deze scanner uit en download Combofix opnieuw. Sommige scanners zien bepaalde componenten die Combofix gebruikt als verdacht en gaan deze blokkeren of verwijderen!

        Dubbelklik op combofix.exe
        Kies voor "Continue" door 1 te typen gevolgd door ENTER.
        Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.

        Wanneer de fix voltooid is en na herstart, zal de log combofix.txt openen.
        Plaats in je volgende antwoord het logje van combofix (combofix.txt) tesamen met een vers Hijackthis log.
        Groet,
        Pimmerd

        Comment


        • #5
          sorry
          ComboFix 08-01-20.1 - plan delta 2008-01-20 15:03:11.2 - NTFSx86 MINIMAL
          Gestart vanuit: C:\Documents and Settings\plan delta\Bureaublad\ComboFix.exe

          WAARSCHUWING - DE RECOVERY CONSOLE IS NIET OP DIT SYSTEEM GEINSTALLEERD !!
          .

          (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
          .

          C:\Documents and Settings\All Users.WINDOWS\Application Data\storageprotector
          C:\Documents and Settings\All Users.WINDOWS\Application Data\storageprotector\Data\ac
          C:\Documents and Settings\All Users.WINDOWS\Application Data\storageprotector\Data\em
          C:\Documents and Settings\All Users.WINDOWS\Application Data\storageprotector\Data\oid
          C:\Documents and Settings\All Users.WINDOWS\Application Data\storageprotector\Data\user
          C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\StorageProtector
          C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\StorageProtector\Contact Customer Service.lnk
          C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\StorageProtector\StorageProtector.lnk
          C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\StorageProtector\Uninstall StorageProtector.lnk
          C:\Documents and Settings\plan delta\Application Data\storageprotector
          C:\Documents and Settings\plan delta\Application Data\storageprotector\Logs\update.log
          C:\Documents and Settings\plan delta\Mijn documenten\pos1045.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1046.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1047.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1048.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1049.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos104A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos104B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos104C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos104D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos104E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos104F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1050.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1051.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1052.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1053.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1054.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1055.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1056.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1057.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1058.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1059.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos105A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos105B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos105C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos105D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos105E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos105F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1060.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1061.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1062.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1063.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1064.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1065.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1066.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1067.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1068.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1069.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos106A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos106B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos106C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos106D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos106E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos106F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1070.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1071.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1072.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1073.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1074.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1075.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1076.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1077.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1078.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1079.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos107A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos107B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos107C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos107D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos107E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos107F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1080.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1081.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1082.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1083.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1084.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1085.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1086.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1087.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1088.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1089.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos108A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos108B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos108C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos108D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos108E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos108F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1090.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1091.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1092.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1093.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1094.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1095.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1096.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1097.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1098.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1099.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos109A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos109B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos109C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos109D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos109E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos109F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10A0.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10A1.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10A2.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10A3.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10A4.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10A5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10A6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10A7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10A8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10A9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10AA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10AB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10AC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10AD.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10AE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10AF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10B0.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10B1.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10B2.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10B3.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10B4.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10B5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10B6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10B7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10B8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10B9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10BA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10BB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10BC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10BD.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10BE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10BF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10C0.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10C1.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10C2.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10C3.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10C4.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10C5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10C6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10C7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10C8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10C9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10CA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10CB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10CC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10CD.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10CE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10CF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10D0.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10D1.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10D2.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10D3.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10D4.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10D5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10D6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10D7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10D8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10D9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10DA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10DB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10DC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10DD.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10DE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10DF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10E0.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10E1.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10E2.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10E3.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10E4.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10E5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10E6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10E7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10E8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10E9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10EA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10EB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10EC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10ED.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10EE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10EF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10F0.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10F1.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10F2.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10F3.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10F4.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10F5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10F6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10F7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10F8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10F9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10FA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10FB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10FC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10FD.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10FE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos10FF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1100.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1101.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1102.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1103.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1104.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1105.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1106.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1107.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1108.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1109.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos110A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos110B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos110C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos110D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos110E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos110F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1110.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1111.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1112.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1113.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1114.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1115.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1116.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1117.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1118.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1119.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos111A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos111B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos111C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos111D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos111E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos111F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1120.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1121.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1122.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1123.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1124.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1125.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1126.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1127.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1128.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1129.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos112A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos112B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos112C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos112D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos112E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos112F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1130.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1131.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1132.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1133.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1134.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1135.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1136.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1137.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1138.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1139.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos113A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos113B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos113C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos113D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos113E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos113F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1140.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1141.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1142.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1143.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1144.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1145.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1146.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1147.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1148.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1149.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos114A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos114B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos114C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos114D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos114E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos114F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1150.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1151.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1152.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1153.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1154.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1155.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1156.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1157.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1158.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1159.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos115A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos115B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos115C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos115D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos115E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos115F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1160.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1161.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1162.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1163.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1164.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1165.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1166.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1167.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1168.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1169.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos116A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos116B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos116C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos116D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos116E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos116F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1170.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1171.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1172.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1173.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1174.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1175.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1176.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1177.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1178.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1179.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos117A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos117B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos117C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos117D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos117E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos117F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1180.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1181.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1182.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1183.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1184.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1185.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1186.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1187.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1188.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1189.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos118A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos118B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos118C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos118D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos118E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos118F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1190.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1191.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1192.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1193.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1194.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1195.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1196.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1197.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1198.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1199.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos119A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos119B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos119C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos119D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos119E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos119F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11A0.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11A1.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11A2.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11A3.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11A4.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11A5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11A6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11A7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11A8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11A9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11AA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11AB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11AC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11AD.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11AE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11AF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11B0.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11B1.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11B2.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11B3.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11B4.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11B5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11B6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11B7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11B8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11B9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11BA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11BB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11BC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11BD.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11BE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11BF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11C0.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11C1.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11C2.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11C3.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11C4.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11C5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11C6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11C7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11C8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11C9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11CA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11CB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11CC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11CD.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11CE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11CF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11D0.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11D1.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11D2.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11D3.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11D4.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11D5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11D6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11D7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11D8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11D9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11DA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11DB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11DC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11DD.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11DE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11DF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11E0.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11E1.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11E2.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11E3.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11E4.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11E5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11E6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11E7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11E8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11E9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11EA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11EB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11EC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11ED.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11EE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11EF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11F0.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11F1.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11F2.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11F3.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11F4.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11F5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11F6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11F7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11F8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11F9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11FA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11FB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11FC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11FD.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11FE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos11FF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1200.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1201.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1202.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1203.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1204.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1205.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1206.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1207.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1208.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1209.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos120A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos120B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos120C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos120D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos120E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos120F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1210.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1211.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1212.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1213.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1214.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1215.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1216.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1217.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1218.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1219.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos121A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos121B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos121C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos121D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos121E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos121F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1220.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1221.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1222.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1223.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1224.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1225.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1226.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1227.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1228.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1229.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos122A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos122B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos122C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos122D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos122E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos122F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1230.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1231.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1232.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1233.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1234.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1235.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1236.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1237.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1238.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1F5.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1F6.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1F7.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1F8.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1F9.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1FA.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1FB.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1FC.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1FD.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1FE.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos1FF.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos200.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos201.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos202.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos203.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos204.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos205.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos206.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos207.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos208.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos209.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos20A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos20B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos20C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos20D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos20E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos20F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos210.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos211.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos212.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos213.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos214.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos215.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos216.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos217.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos218.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos219.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos21A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos21B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos21C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos21D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos21E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos21F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos220.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos221.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos222.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos223.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos224.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos225.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos226.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos227.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos228.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos229.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos22A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos22B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos22C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos22D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos22E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos22F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos230.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos231.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos232.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos233.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos234.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos235.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos236.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos237.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos238.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos239.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos23A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos23B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos23C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos23D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos23E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos23F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos240.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos241.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos242.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos243.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos244.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos245.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos246.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos247.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos248.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos249.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos24A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos24B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos24C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos24D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos24E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos24F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos250.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos251.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos252.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos253.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos254.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos255.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos256.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos257.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos258.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos259.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos25A.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos25B.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos25C.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos25D.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos25E.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos25F.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos260.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos261.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos262.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos263.tmp
          C:\Documents and Settings\plan delta\Mijn documenten\pos264.tmp

          Comment


          • #6
            en ook zo in /:c al die pos bestanden


            C:\Program Files\Common Files\StorageProtector
            C:\Program Files\Common Files\StorageProtector\strpmon.exe
            C:\Program Files\outerinfo
            C:\Program Files\outerinfo\OiUninstaller.exe
            C:\Program Files\StorageProtector
            C:\Program Files\StorageProtector\atl71.dll
            C:\Program Files\StorageProtector\License.rtf
            C:\Program Files\StorageProtector\mfc71.dll
            C:\Program Files\StorageProtector\msvcp71.dll
            C:\Program Files\StorageProtector\msvcr71.dll
            C:\Program Files\StorageProtector\Readme.rtf
            C:\Program Files\StorageProtector\Res\Main.ico
            C:\Program Files\StorageProtector\Res\RecycleBin.ico
            C:\Program Files\StorageProtector\rm.url
            C:\Program Files\StorageProtector\sr.log
            C:\Program Files\StorageProtector\swupd.log
            C:\Program Files\StorageProtector\SysRep.exe
            C:\Program Files\StorageProtector\SysRep.exe.cer
            C:\Program Files\StorageProtector\SysRep.exe.Log
            C:\Program Files\StorageProtector\SysRep.exe.xml
            C:\Program Files\StorageProtector\SysRep.url
            C:\Program Files\StorageProtector\transpaid.exe
            C:\Program Files\StorageProtector\unins000.dat
            C:\Program Files\StorageProtector\unins000.exe
            C:\Program Files\StorageProtector\urls.ini
            C:\WINDOWS\system32\cvvqmgwr.ini
            C:\WINDOWS\system32\ddcawxy.dll
            C:\WINDOWS\system32\drvdarr.dll
            C:\WINDOWS\system32\hiwgxmia.dll
            C:\WINDOWS\system32\hiwgxmia.dllbox
            C:\WINDOWS\system32\iifdedb.dll
            C:\WINDOWS\system32\kjkkj.ini
            C:\WINDOWS\system32\kjkkj.ini2
            C:\WINDOWS\system32\ljjkhgg.dll
            C:\WINDOWS\system32\oqtwa.ini
            C:\WINDOWS\system32\oqtwa.ini2
            C:\WINDOWS\system32\rwgmqvvc.dll
            C:\WINDOWS\system32\Ultra.dll
            C:\WINDOWS\system32\urqponk.dll
            C:\WINDOWS\system32\wegmcvlt.dll
            C:\WINDOWS\system32\xxyywwx.dll

            Comment


            • #7
              (((((((((((((((((((( Bestanden Gemaakt van 2007-12-20 to 2008-01-20 ))))))))))))))))))))))))))))))
              .

              2008-01-20 14:43 . 2008-01-20 14:43 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
              2008-01-20 13:59 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
              2008-01-20 13:48 . 2008-01-20 13:48 <DIR> d-------- C:\Program Files\Trend Micro
              2008-01-19 22:20 . 2004-08-04 13:00 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
              2008-01-19 22:18 . 2004-08-04 13:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
              2008-01-19 22:17 . 2004-08-04 13:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
              2008-01-19 22:16 . 2004-08-04 13:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
              2008-01-19 22:13 . 2008-01-19 22:13 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
              2008-01-19 22:13 . 2008-01-19 22:13 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
              2008-01-19 22:13 . 2008-01-19 22:13 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
              2008-01-19 22:13 . 2008-01-19 22:13 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
              2008-01-19 22:13 . 2008-01-19 22:13 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
              2008-01-19 21:14 . 2004-08-04 13:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
              2008-01-19 20:58 . 2004-08-04 13:00 1,086,058 -ra------ C:\WINDOWS\SET30.tmp
              2008-01-19 20:58 . 2004-08-04 13:00 1,014,139 -ra------ C:\WINDOWS\SET2D.tmp
              2008-01-19 20:58 . 2004-08-04 13:00 14,043 -ra------ C:\WINDOWS\SET3C.tmp
              2008-01-19 20:45 . 2004-08-04 13:00 1,086,058 -ra------ C:\WINDOWS\SET96.tmp
              2008-01-19 20:45 . 2004-08-04 13:00 1,014,139 -ra------ C:\WINDOWS\SET93.tmp
              2008-01-19 20:45 . 2004-08-04 13:00 14,043 -ra------ C:\WINDOWS\SETA2.tmp
              2008-01-19 17:55 . 2008-01-19 18:33 <DIR> d-------- C:\Program Files\Bug Doctor
              2008-01-19 17:52 . 2008-01-19 17:52 <DIR> dr------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SalesMon
              2008-01-18 20:57 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
              2008-01-18 20:57 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
              2008-01-18 20:57 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
              2008-01-18 20:57 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
              2008-01-18 20:57 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
              2008-01-18 20:57 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
              2008-01-18 20:57 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
              2008-01-18 20:57 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
              2008-01-17 20:33 . 2008-01-17 20:33 <DIR> d-------- C:\Documents and Settings\plan delta\Wachtwoord_is_fout
              2008-01-17 20:33 . 2008-01-17 20:33 <DIR> d-------- C:\Documents and Settings\plan delta\Probeer_opnieuw
              2008-01-17 19:07 . 2008-01-18 15:03 <DIR> d-------- C:\Program Files\StuffPlug3
              2008-01-16 17:21 . 2008-01-16 18:15 286 --a------ C:\WINDOWS\wininit.ini
              2008-01-16 15:46 . 2008-01-19 09:27 262,144 --a------ C:\WINDOWS\system32\ElkCtrl .exe
              2008-01-16 15:46 . 2008-01-19 09:27 225,280 --a------ C:\WINDOWS\system32\LVCOMSX .EXE
              2008-01-16 15:46 . 2008-01-17 17:07 12,288 --a------ C:\WINDOWS\system32\wupeng .exe
              2008-01-16 15:44 . 2008-01-19 09:27 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
              2008-01-15 20:33 . 2008-01-15 20:33 24,576 --a------ C:\WINDOWS\system32\winhld32.dll__DELETE_ON_REBOOT
              2008-01-15 20:32 . 2008-01-15 20:32 40,960 --a------ C:\WINDOWS\system32\iifdedb.dll__DELETE_ON_REBOOT
              2008-01-13 13:55 . 2008-01-13 13:55 <DIR> d-------- C:\WINDOWS\vbSkinner
              2008-01-13 12:16 . 2008-01-13 13:56 <DIR> d-------- C:\Program Files\PFConfig
              2008-01-12 18:41 . 2008-01-13 15:12 <DIR> d-------- C:\Program Files\AMX Mod X
              2008-01-09 08:52 . 2008-01-09 08:52 <DIR> d-------- C:\Documents and Settings\plan delta\Application Data\Lavasoft
              2008-01-09 08:46 . 2008-01-19 14:56 <DIR> d-------- C:\Program Files\Spyware Doctor
              2008-01-09 08:46 . 2008-01-09 08:46 <DIR> d-------- C:\Documents and Settings\plan delta\Application Data\PC Tools
              2008-01-09 08:46 . 2008-01-16 18:16 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
              2008-01-09 08:46 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
              2008-01-09 08:46 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
              2008-01-09 08:46 . 2007-12-10 14:53 41,864 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
              2008-01-09 08:46 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
              2008-01-09 08:44 . 2008-01-09 08:44 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx
              2008-01-09 08:43 . 2008-01-19 20:00 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
              2008-01-04 19:50 . 2004-08-03 23:10 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
              2008-01-04 19:50 . 2004-08-03 23:10 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
              2008-01-04 19:50 . 2004-08-03 23:10 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
              2008-01-04 19:50 . 2004-08-03 22:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
              2008-01-04 19:45 . 2005-12-09 15:35 245,824 -ra------ C:\WINDOWS\Instexec.exe
              2008-01-04 19:44 . 2008-01-04 19:45 <DIR> d-------- C:\Program Files\Common Files\Logitech
              2008-01-04 19:44 . 2005-12-07 10:25 350,720 --a------ C:\WINDOWS\system32\camcpl.cpl
              2008-01-04 19:44 . 2005-12-07 10:23 323,584 --a------ C:\WINDOWS\system32\CamCplRes.dll
              2008-01-04 19:44 . 2005-12-09 15:31 245,824 -ra------ C:\WINDOWS\system32\InstExec.exe
              2008-01-04 19:44 . 2005-12-07 19:17 86,016 -ra------ C:\WINDOWS\system32\vatee.ax
              2008-01-04 19:44 . 2003-04-18 16:29 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
              2008-01-04 19:44 . 2004-11-01 17:22 57,344 --a------ C:\WINDOWS\system32\ElkCtlPS.dll
              2008-01-04 19:44 . 2005-12-09 15:31 719 -ra------ C:\WINDOWS\system32\InstExec.ini
              2008-01-04 19:43 . 2008-01-04 19:43 <DIR> d-------- C:\Program Files\Logitech
              2008-01-04 19:07 . 2008-01-04 19:04 4,633 --a------ C:\WINDOWS\hpdj3840.hi1
              2008-01-04 19:07 . 2008-01-04 19:04 933 --a------ C:\WINDOWS\hpdj3840.bu1
              2008-01-04 19:04 . 2008-01-04 19:33 831,986 --a------ C:\WINDOWS\hpdj3840.his
              2008-01-04 19:04 . 2008-01-04 19:33 8,986 --a------ C:\WINDOWS\hpdj3840.ini
              2008-01-04 18:58 . 2001-08-17 21:47 12,928 --a------ C:\WINDOWS\system32\drivers\Dot4Prt.sys
              2008-01-03 16:21 . 2008-01-03 16:21 395 --a------ C:\WINDOWS\ODBC.INI
              2008-01-03 15:23 . 2004-08-18 11:07 184,320 --a------ C:\WINDOWS\system32\SiSApCom.dll
              2008-01-03 15:23 . 2004-08-18 11:07 110,592 --a------ C:\WINDOWS\system32\TVMode.dll
              2008-01-03 15:22 . 2008-01-03 15:23 <DIR> d-------- C:\Program Files\SiS VGA Utilities V3.61
              2008-01-03 15:22 . 2004-07-23 22:20 331,776 --a------ C:\WINDOWS\system32\sistray.exe
              2008-01-03 15:22 . 2004-08-18 11:07 106,345 --a------ C:\WINDOWS\VGAsetup.ini
              2008-01-03 15:16 . 2008-01-03 15:16 <DIR> d-------- C:\Documents and Settings\plan delta\WINDOWS
              2008-01-03 15:16 . 1998-01-23 12:20 305,152 --a------ C:\WINDOWS\IsUn0413.exe
              2008-01-03 15:16 . 2004-08-18 11:07 106,496 --a------ C:\WINDOWS\SiSUSBrg.exe
              2008-01-03 15:16 . 2004-08-18 11:07 32,768 --a------ C:\WINDOWS\SIS_LIB.DLL
              2008-01-03 15:16 . 2004-08-18 11:07 3,583 --a------ C:\WINDOWS\SiSport.sys
              2008-01-03 15:09 . 2008-01-03 15:09 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
              2008-01-03 14:14 . 2008-01-03 15:23 102,628 --a------ C:\WINDOWS\system32\VGAunistlog.ini
              2008-01-03 13:36 . 2008-01-03 13:39 <DIR> d-------- C:\Program Files\Winamp
              2008-01-03 13:36 . 2008-01-03 16:55 <DIR> d-------- C:\Documents and Settings\plan delta\Application Data\Winamp
              2008-01-03 13:27 . 2008-01-03 13:27 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SwiftSwitch
              2008-01-03 12:24 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
              2008-01-03 12:06 . 1998-10-02 19:00 327,168 --a------ C:\WINDOWS\IsUninst.exe
              2008-01-03 12:05 . 2006-08-01 15:02 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
              2008-01-03 12:03 . 2008-01-03 12:04 <DIR> d-------- C:\Program Files\Realtek AC97
              2008-01-03 12:03 . 2006-11-17 05:40 18,804,736 --a------ C:\WINDOWS\system32\alsndmgr.cpl
              2008-01-03 12:03 . 2006-12-08 15:20 10,528,768 --a------ C:\WINDOWS\system32\RTLCPL.exe
              2008-01-03 12:03 . 2006-12-04 17:11 4,025,984 --a------ C:\WINDOWS\system32\drivers\alcxwdm.sys
              2008-01-03 12:03 . 2006-11-17 05:42 577,536 --a------ C:\WINDOWS\soundman.exe
              2008-01-03 12:03 . 2006-07-31 11:19 315,392 --a------ C:\WINDOWS\alcupd.exe
              2008-01-03 12:03 . 2006-07-31 11:27 217,088 --a------ C:\WINDOWS\Alcrmv.exe
              2008-01-03 12:03 . 2006-10-18 02:53 147,456 --a------ C:\WINDOWS\system32\RtlCPAPI.dll
              2008-01-03 12:03 . 2002-02-05 13:54 141,016 --a------ C:\WINDOWS\system32\alsndmgr.wav
              2008-01-03 11:56 . 2008-01-03 12:07 <DIR> d-------- C:\Program Files\Setup Files

              Comment


              • #8
                uhhh sorry volgens mij heb ik het door elkaar gezet =(

                hopelijk kom je er nog wel uit =(

                ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-01-18 14:09 --------- d-----w C:\Program Files\EPN werkboek-i
                2008-01-17 18:07 --------- d-----w C:\Program Files\MSN Messenger
                2008-01-17 06:54 --------- d-----w C:\Program Files\Hitman Pro
                2008-01-16 15:28 --------- d-----w C:\Program Files\SpywareBlaster
                2008-01-03 12:55 --------- d-----w C:\Program Files\Messenger Plus! Live
                2008-01-02 22:45 --------- d-----w C:\Program Files\Comodo
                2007-12-21 17:51 --------- d-----w C:\Program Files\LimeWire
                2007-11-23 06:31 --------- d-----w C:\Program Files\SurfRight
                2007-11-21 14:51 --------- d-----w C:\Program Files\LegacyGamers
                2003-07-25 17:46 24,576 -c--a-w C:\Program Files\Common Files\ldrbtl.exe
                .
                Code:
                <pre>
                ----a-w            79,224 2008-01-19 08:27:31  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
                ----a-w         1,115,728 2008-01-19 08:27:33  C:\Program Files\Comodo\Firewall\CPF .exe
                ----a-w            75,520 2008-01-19 08:27:27  C:\Program Files\Java\jre1.5.0_11\bin\jusched .exe
                ----a-w            73,728 2008-01-19 08:27:30  C:\Program Files\Logitech\Video\InstallHelper .exe
                ----a-w         1,103,752 2008-01-16 17:16:13  C:\Program Files\Spyware Doctor\pctsTray .exe
                ----a-w           160,256 2008-01-18 06:13:39  C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
                ----a-w            15,360 2008-01-19 08:27:41  C:\WINDOWS\system32\ctfmon .exe
                ----a-w           262,144 2008-01-19 08:27:32  C:\WINDOWS\system32\ElkCtrl .exe
                ----a-w           225,280 2008-01-19 08:27:28  C:\WINDOWS\system32\LVCOMSX .EXE
                ----a-w            12,288 2008-01-17 16:07:42  C:\WINDOWS\system32\wupeng .exe
                </pre>

                ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                REGEDIT4
                *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
                "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04 1415824]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 88363 C:\WINDOWS\AGRSMMSG.exe]
                "COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2008-01-19 09:35 1115728]
                "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
                "ucookw"="C:\PROGRA~1\STORAG~1\ucookw.exe" [ ]
                "avp"="C:\WINDOWS\avp .exe" [ ]
                "SoundMan"="SOUNDMAN.EXE" [2006-11-17 05:42 577536 C:\WINDOWS\soundman.exe]

                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]

                C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\Opstarten\
                Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2008-01-03 15:22:51 331776]

                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
                C:\Program Files\Spyware Doctor\pctsTray.exe

                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraAssistant]
                --a------ 2005-12-07 10:26 489472 C:\Program Files\Logitech\Video\CameraAssistant.exe

                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NI.UGA6PM_0001_N122M3010]
                C:\Documents and Settings\plan delta\Bureaublad\install_nl.exe

                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]
                --a------ 2004-08-18 11:07 106496 C:\WINDOWS\SiSUSBrg.exe

                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
                --a------ 2008-01-12 16:24 1266936 e:\steam\steam.exe

                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Winupdate Engine]
                C:\WINDOWS\system32\wupeng.exe

                S3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-12-09 15:37]
                S3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2006-02-14 16:02]

                .
                **************************************************************************

                catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-01-20 15:58:57
                Windows 5.1.2600 Service Pack 2 NTFS

                scannen van verborgen processen ...

                scannen van verborgen autostart items ...

                scannen van verborgen bestanden ...

                Scan succesvol afgerond
                verborgen bestanden: 0

                **************************************************************************
                .
                Voltooingstijd: 2008-01-20 16:05:54 - machine was rebooted [plan delta]
                ComboFix-quarantined-files.txt 2008-01-20 15:05:47
                .
                2008-01-20 13:50:18 --- E O F ---

                Comment


                • #9
                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 18:55:47, on 20-1-2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\AGRSMMSG.exe
                  C:\Program Files\Comodo\Firewall\CPF.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINDOWS\SOUNDMAN.EXE
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                  C:\Program Files\Comodo\Firewall\cmdagent.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\MSN Messenger\usnsvc.exe
                  C:\Program Files\Winamp\winamp.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
                  C:\Program Files\MSN Messenger\msnmsgr.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
                  O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                  O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                  O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\STORAG~1\ucookw.exe" -start
                  O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp .exe
                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
                  O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                  O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O15 - Trusted Zone: http://www.msi.com.tw
                  O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab
                  O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/ocis/SiSAutodetectNT.cab
                  O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
                  O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                  O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                  O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

                  --
                  End of file - 5267 bytes

                  Comment


                  • #10
                    Open Kladblok, kopiëer en plak het volgende (vetgedrukte tekst) in een leeg venster:

                    File::
                    C:\WINDOWS\system32\iifdedb.dll__DELETE_ON_REBOOT
                    C:\WINDOWS\system32\winhld32.dll__DELETE_ON_REBOOT
                    C:\WINDOWS\wininit.ini

                    RENV::
                    C:\Program Files\Alwil Software\Avast4\ashDisp .exe
                    C:\Program Files\Comodo\Firewall\CPF .exe
                    C:\Program Files\Java\jre1.5.0_11\bin\jusched .exe
                    C:\Program Files\Logitech\Video\InstallHelper .exe
                    C:\Program Files\Spyware Doctor\pctsTray .exe
                    C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
                    C:\WINDOWS\system32\ctfmon .exe
                    C:\WINDOWS\system32\ElkCtrl .exe
                    C:\WINDOWS\system32\LVCOMSX .EXE
                    C:\WINDOWS\system32\wupeng .exe

                    Sla dit op op je Bureaublad als CFScript.txt

                    Sleep CFScript.txt in ComboFix.exe zoals getoond in onderstaand voorbeeld :



                    Dit zal ComboFix doen herstarten.
                    Start opnieuw op als daarom gevraagd wordt,
                    en post de inhoud van de Combofix.txt in je volgende antwoord samen met een nieuw HijackThislogje.
                    Last edited by Pimmerd; 20-01-08, 21:43.
                    Groet,
                    Pimmerd

                    Comment


                    • #11
                      combofix

                      ComboFix 08-01-20.1 - plan delta 2008-01-21 16:32:20.3 - NTFSx86
                      Gestart vanuit: C:\Documents and Settings\plan delta\Bureaublad\ComboFix.exe
                      Command switches used :: C:\Documents and Settings\plan delta\Bureaublad\CFScript.txt
                      * Nieuw herstelpunt werd aangemaakt

                      WAARSCHUWING - DE RECOVERY CONSOLE IS NIET OP DIT SYSTEEM GEINSTALLEERD !!

                      FILE
                      C:\WINDOWS\system32\iifdedb.dll__DELETE_ON_REBOOT
                      C:\WINDOWS\system32\winhld32.dll__DELETE_ON_REBOOT
                      C:\WINDOWS\wininit.ini
                      .

                      (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      C:\WINDOWS\system32\iifdedb.dll__DELETE_ON_REBOOT
                      C:\WINDOWS\system32\winhld32.dll__DELETE_ON_REBOOT
                      C:\WINDOWS\wininit.ini

                      .
                      (((((((((((((((((((( Bestanden Gemaakt van 2007-12-21 to 2008-01-21 ))))))))))))))))))))))))))))))
                      .

                      2008-01-21 16:25 . 2008-01-21 16:25 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
                      2008-01-20 13:59 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
                      2008-01-20 13:48 . 2008-01-20 13:48 <DIR> d-------- C:\Program Files\Trend Micro
                      2008-01-19 22:20 . 2004-08-04 13:00 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
                      2008-01-19 22:18 . 2004-08-04 13:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
                      2008-01-19 22:17 . 2004-08-04 13:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
                      2008-01-19 22:16 . 2004-08-04 13:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
                      2008-01-19 22:13 . 2008-01-19 22:13 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
                      2008-01-19 22:13 . 2008-01-19 22:13 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
                      2008-01-19 22:13 . 2008-01-19 22:13 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
                      2008-01-19 22:13 . 2008-01-19 22:13 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
                      2008-01-19 22:13 . 2008-01-19 22:13 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
                      2008-01-19 21:14 . 2004-08-04 13:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
                      2008-01-19 20:58 . 2004-08-04 13:00 1,086,058 -ra------ C:\WINDOWS\SET30.tmp
                      2008-01-19 20:58 . 2004-08-04 13:00 1,014,139 -ra------ C:\WINDOWS\SET2D.tmp
                      2008-01-19 20:58 . 2004-08-04 13:00 14,043 -ra------ C:\WINDOWS\SET3C.tmp
                      2008-01-19 20:45 . 2004-08-04 13:00 1,086,058 -ra------ C:\WINDOWS\SET96.tmp
                      2008-01-19 20:45 . 2004-08-04 13:00 1,014,139 -ra------ C:\WINDOWS\SET93.tmp
                      2008-01-19 20:45 . 2004-08-04 13:00 14,043 -ra------ C:\WINDOWS\SETA2.tmp
                      2008-01-19 17:55 . 2008-01-19 18:33 <DIR> d-------- C:\Program Files\Bug Doctor
                      2008-01-19 17:52 . 2008-01-19 17:52 <DIR> dr------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SalesMon
                      2008-01-18 20:57 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
                      2008-01-18 20:57 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
                      2008-01-18 20:57 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
                      2008-01-18 20:57 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
                      2008-01-18 20:57 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
                      2008-01-18 20:57 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
                      2008-01-18 20:57 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
                      2008-01-18 20:57 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
                      2008-01-18 07:13 . 2008-01-18 07:13 160,256 --a--c--- C:\WINDOWS\system32\dllcache\msconfig.exe
                      2008-01-17 20:33 . 2008-01-17 20:33 <DIR> d-------- C:\Documents and Settings\plan delta\Wachtwoord_is_fout
                      2008-01-17 20:33 . 2008-01-17 20:33 <DIR> d-------- C:\Documents and Settings\plan delta\Probeer_opnieuw
                      2008-01-17 19:07 . 2008-01-20 16:24 <DIR> d-------- C:\Program Files\StuffPlug3
                      2008-01-16 15:46 . 2008-01-19 09:27 262,144 --a------ C:\WINDOWS\system32\ElkCtrl.exe
                      2008-01-16 15:46 . 2008-01-19 09:27 225,280 --a------ C:\WINDOWS\system32\LVCOMSX.EXE
                      2008-01-16 15:46 . 2008-01-17 17:07 12,288 --a------ C:\WINDOWS\system32\wupeng.exe
                      2008-01-16 15:44 . 2008-01-19 09:27 15,360 --a--c--- C:\WINDOWS\system32\dllcache\ctfmon.exe
                      2008-01-16 15:44 . 2008-01-19 09:27 15,360 --a------ C:\WINDOWS\system32\ctfmon.exe
                      2008-01-13 13:55 . 2008-01-13 13:55 <DIR> d-------- C:\WINDOWS\vbSkinner
                      2008-01-13 12:16 . 2008-01-13 13:56 <DIR> d-------- C:\Program Files\PFConfig
                      2008-01-12 18:41 . 2008-01-13 15:12 <DIR> d-------- C:\Program Files\AMX Mod X
                      2008-01-09 08:52 . 2008-01-09 08:52 <DIR> d-------- C:\Documents and Settings\plan delta\Application Data\Lavasoft
                      2008-01-09 08:46 . 2008-01-21 16:32 <DIR> d-------- C:\Program Files\Spyware Doctor
                      2008-01-09 08:46 . 2008-01-09 08:46 <DIR> d-------- C:\Documents and Settings\plan delta\Application Data\PC Tools
                      2008-01-09 08:46 . 2008-01-16 18:16 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
                      2008-01-09 08:46 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
                      2008-01-09 08:46 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
                      2008-01-09 08:46 . 2007-12-10 14:53 41,864 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
                      2008-01-09 08:46 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
                      2008-01-09 08:44 . 2008-01-09 08:44 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx
                      2008-01-09 08:43 . 2008-01-19 20:00 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
                      2008-01-04 19:50 . 2004-08-03 23:10 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
                      2008-01-04 19:50 . 2004-08-03 23:10 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
                      2008-01-04 19:50 . 2004-08-03 23:10 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
                      2008-01-04 19:50 . 2004-08-03 22:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
                      2008-01-04 19:45 . 2005-12-09 15:35 245,824 -ra------ C:\WINDOWS\Instexec.exe
                      2008-01-04 19:44 . 2008-01-04 19:45 <DIR> d-------- C:\Program Files\Common Files\Logitech
                      2008-01-04 19:44 . 2005-12-07 10:25 350,720 --a------ C:\WINDOWS\system32\camcpl.cpl
                      2008-01-04 19:44 . 2005-12-07 10:23 323,584 --a------ C:\WINDOWS\system32\CamCplRes.dll
                      2008-01-04 19:44 . 2005-12-09 15:31 245,824 -ra------ C:\WINDOWS\system32\InstExec.exe
                      2008-01-04 19:44 . 2005-12-07 19:17 86,016 -ra------ C:\WINDOWS\system32\vatee.ax
                      2008-01-04 19:44 . 2003-04-18 16:29 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
                      2008-01-04 19:44 . 2004-11-01 17:22 57,344 --a------ C:\WINDOWS\system32\ElkCtlPS.dll
                      2008-01-04 19:44 . 2005-12-09 15:31 719 -ra------ C:\WINDOWS\system32\InstExec.ini
                      2008-01-04 19:43 . 2008-01-04 19:43 <DIR> d-------- C:\Program Files\Logitech
                      2008-01-04 19:07 . 2008-01-04 19:04 4,633 --a------ C:\WINDOWS\hpdj3840.hi1
                      2008-01-04 19:07 . 2008-01-04 19:04 933 --a------ C:\WINDOWS\hpdj3840.bu1
                      2008-01-04 19:04 . 2008-01-04 19:33 831,986 --a------ C:\WINDOWS\hpdj3840.his
                      2008-01-04 19:04 . 2008-01-04 19:33 8,986 --a------ C:\WINDOWS\hpdj3840.ini
                      2008-01-04 18:58 . 2001-08-17 21:47 12,928 --a------ C:\WINDOWS\system32\drivers\Dot4Prt.sys
                      2008-01-03 16:21 . 2008-01-03 16:21 395 --a------ C:\WINDOWS\ODBC.INI
                      2008-01-03 15:23 . 2004-08-18 11:07 184,320 --a------ C:\WINDOWS\system32\SiSApCom.dll
                      2008-01-03 15:23 . 2004-08-18 11:07 110,592 --a------ C:\WINDOWS\system32\TVMode.dll
                      2008-01-03 15:22 . 2008-01-03 15:23 <DIR> d-------- C:\Program Files\SiS VGA Utilities V3.61
                      2008-01-03 15:22 . 2004-07-23 22:20 331,776 --a------ C:\WINDOWS\system32\sistray.exe
                      2008-01-03 15:22 . 2004-08-18 11:07 106,345 --a------ C:\WINDOWS\VGAsetup.ini
                      2008-01-03 15:16 . 2008-01-03 15:16 <DIR> d-------- C:\Documents and Settings\plan delta\WINDOWS
                      2008-01-03 15:16 . 1998-01-23 12:20 305,152 --a------ C:\WINDOWS\IsUn0413.exe
                      2008-01-03 15:16 . 2004-08-18 11:07 106,496 --a------ C:\WINDOWS\SiSUSBrg.exe
                      2008-01-03 15:16 . 2004-08-18 11:07 32,768 --a------ C:\WINDOWS\SIS_LIB.DLL
                      2008-01-03 15:16 . 2004-08-18 11:07 3,583 --a------ C:\WINDOWS\SiSport.sys
                      2008-01-03 15:09 . 2008-01-03 15:09 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
                      2008-01-03 14:14 . 2008-01-03 15:23 102,628 --a------ C:\WINDOWS\system32\VGAunistlog.ini
                      2008-01-03 13:36 . 2008-01-03 13:39 <DIR> d-------- C:\Program Files\Winamp
                      2008-01-03 13:36 . 2008-01-03 16:55 <DIR> d-------- C:\Documents and Settings\plan delta\Application Data\Winamp
                      2008-01-03 13:27 . 2008-01-03 13:27 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SwiftSwitch
                      2008-01-03 12:24 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
                      2008-01-03 12:06 . 1998-10-02 19:00 327,168 --a------ C:\WINDOWS\IsUninst.exe
                      2008-01-03 12:05 . 2006-08-01 15:02 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
                      2008-01-03 12:03 . 2008-01-03 12:04 <DIR> d-------- C:\Program Files\Realtek AC97
                      2008-01-03 12:03 . 2006-11-17 05:40 18,804,736 --a------ C:\WINDOWS\system32\alsndmgr.cpl
                      2008-01-03 12:03 . 2006-12-08 15:20 10,528,768 --a------ C:\WINDOWS\system32\RTLCPL.exe
                      2008-01-03 12:03 . 2006-12-04 17:11 4,025,984 --a------ C:\WINDOWS\system32\drivers\alcxwdm.sys
                      2008-01-03 12:03 . 2006-11-17 05:42 577,536 --a------ C:\WINDOWS\soundman.exe
                      2008-01-03 12:03 . 2006-07-31 11:19 315,392 --a------ C:\WINDOWS\alcupd.exe
                      2008-01-03 12:03 . 2006-07-31 11:27 217,088 --a------ C:\WINDOWS\Alcrmv.exe
                      2008-01-03 12:03 . 2006-10-18 02:53 147,456 --a------ C:\WINDOWS\system32\RtlCPAPI.dll
                      2008-01-03 12:03 . 2002-02-05 13:54 141,016 --a------ C:\WINDOWS\system32\alsndmgr.wav
                      2008-01-03 11:56 . 2008-01-03 12:07 <DIR> d-------- C:\Program Files\Setup Files
                      2008-01-03 11:36 . 2008-01-03 11:58 <DIR> d-------- C:\Program Files\sisagp

                      .
                      ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2008-01-18 14:09 --------- d-----w C:\Program Files\EPN werkboek-i
                      2008-01-17 18:07 --------- d-----w C:\Program Files\MSN Messenger
                      2008-01-17 06:54 --------- d-----w C:\Program Files\Hitman Pro
                      2008-01-16 15:28 --------- d-----w C:\Program Files\SpywareBlaster
                      2008-01-03 12:55 --------- d-----w C:\Program Files\Messenger Plus! Live
                      2008-01-02 22:45 --------- d-----w C:\Program Files\Comodo
                      2007-12-21 17:51 --------- d-----w C:\Program Files\LimeWire
                      2007-11-23 06:31 --------- d-----w C:\Program Files\SurfRight
                      2007-11-21 14:51 --------- d-----w C:\Program Files\LegacyGamers
                      2003-07-25 17:46 24,576 -c--a-w C:\Program Files\Common Files\ldrbtl.exe
                      .

                      ((((((((((((((((((((((((((((( [email protected]_16.04.54.82 )))))))))))))))))))))))))))))))))))))))))
                      .
                      - 2008-01-20 13:00:20 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
                      + 2008-01-21 15:31:20 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
                      - 2008-01-20 13:00:20 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
                      + 2008-01-21 15:31:20 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
                      - 2008-01-20 13:00:20 1,417,216 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
                      + 2008-01-21 15:31:20 1,417,216 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
                      - 2008-01-20 13:00:20 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
                      + 2008-01-21 15:31:20 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
                      - 2008-01-20 13:00:21 6,115,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
                      + 2008-01-21 15:31:20 6,115,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
                      - 2008-01-20 13:00:21 106,496 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
                      + 2008-01-21 15:31:20 106,496 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
                      - 2004-08-04 12:00:00 160,256 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe
                      + 2008-01-18 06:13:39 160,256 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\MSConfig.exe
                      + 2008-01-21 15:40:49 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_560.dat
                      .
                      ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      REGEDIT4
                      *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-19 09:27 15360]
                      "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04 1415824]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 88363 C:\WINDOWS\AGRSMMSG.exe]
                      "COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2008-01-19 09:27 1115728]
                      "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-01-19 09:27 79224]
                      "ucookw"="C:\PROGRA~1\STORAG~1\ucookw.exe" [ ]
                      "avp"="C:\WINDOWS\avp .exe" [ ]
                      "SoundMan"="SOUNDMAN.EXE" [2006-11-17 05:42 577536 C:\WINDOWS\soundman.exe]

                      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                      "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-01-19 09:27 15360]

                      C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\Opstarten\
                      Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2008-01-03 15:22:51 331776]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
                      --a------ 2008-01-16 18:16 1103752 C:\Program Files\Spyware Doctor\pctsTray.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraAssistant]
                      --a------ 2005-12-07 10:26 489472 C:\Program Files\Logitech\Video\CameraAssistant.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NI.UGA6PM_0001_N122M3010]
                      C:\Documents and Settings\plan delta\Bureaublad\install_nl.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]
                      --a------ 2004-08-18 11:07 106496 C:\WINDOWS\SiSUSBrg.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
                      --a------ 2008-01-12 16:24 1266936 e:\steam\steam.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Winupdate Engine]
                      --a------ 2008-01-17 17:07 12288 C:\WINDOWS\system32\wupeng.exe

                      R3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-12-09 15:37]
                      R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2006-02-14 16:02]

                      .
                      **************************************************************************

                      catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2008-01-21 16:41:35
                      Windows 5.1.2600 Service Pack 2 NTFS

                      scannen van verborgen processen ...

                      scannen van verborgen autostart items ...

                      scannen van verborgen bestanden ...

                      Scan succesvol afgerond
                      verborgen bestanden: 0

                      **************************************************************************
                      .
                      Voltooingstijd: 2008-01-21 17:06:29 - machine was rebooted
                      ComboFix-quarantined-files.txt 2008-01-21 16:06:22
                      ComboFix2.txt 2008-01-20 15:05:54
                      .
                      2008-01-21 06:58:19 --- E O F ---

                      Comment


                      • #12
                        het andere logje

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 17:22:57, on 21-1-2008
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                        C:\Program Files\Comodo\Firewall\cmdagent.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\AGRSMMSG.exe
                        C:\Program Files\Comodo\Firewall\CPF.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\WINDOWS\SOUNDMAN.EXE
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\WINDOWS\system32\sistray.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\WINDOWS\system32\notepad.exe
                        C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
                        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                        O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\STORAG~1\ucookw.exe" -start
                        O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp .exe
                        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
                        O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                        O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O15 - Trusted Zone: http://www.msi.com.tw
                        O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab
                        O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/ocis/SiSAutodetectNT.cab
                        O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
                        O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

                        --
                        End of file - 5124 bytes

                        Comment


                        • #13
                          Indien je WinPCDoctor nog geinstalleerd hebt staan, kun je deze dan verwijderen via configuratiescherm --> software? Deze heeft namelijk een slechte reputatie

                          Teatimer van Spybot is actief, deze kan de fix hinderen dus schakelen we deze tijdelijk uit.
                          - Start Spybot
                          - Ga naar Mode > selecteer Advanced Mode
                          - Ga naar Tools en klik op het Resident-icoon in de lijst
                          - Haal het vinkje weg bij Resident TeaTimer en klik OK
                          - Herstart de computer
                          - Download vervolgens ResetTeaTimer.bat naar je Bureaublad.
                          Dubbelklik op ResetTeaTimer.bat om alle entries in TeaTimer te verwijderen.

                          Start Hijackthis, kies voor 'Do a system scan only' en vink onderstaande regels aan:

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                          O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp .exe


                          Sluit nu alle openstaande vensters, behalve Hijackthis en klik op Fix Checked.

                          Verwijder daarna onderstaand bestand:
                          C:\WINDOWS\avp.exe

                          Plaats een Hijackthis logfile ter controle.
                          Hoe is het met je problemen?
                          Groet,
                          Pimmerd

                          Comment


                          • #14
                            Nou het gaat al stukken beter. En wat is avp.exe dan want iemand zei laast kaspersky ofzow :P. Maar ik zoek ook nog betere virus scanner dan avast. En bedankt nog ik doe nou even die dingen uitvoeren die jij zei.


                            grtz,

                            Comment


                            • #15
                              hey, nog keer bedankt he =)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 21:22:37, on 21-1-2008
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                              C:\WINDOWS\AGRSMMSG.exe
                              C:\Program Files\Comodo\Firewall\CPF.exe
                              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              C:\WINDOWS\SOUNDMAN.EXE
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Comodo\Firewall\cmdagent.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
                              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                              O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                              O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\STORAG~1\ucookw.exe" -start
                              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
                              O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                              O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O15 - Trusted Zone: http://www.msi.com.tw
                              O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab
                              O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/ocis/SiSAutodetectNT.cab
                              O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
                              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                              O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
                              O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                              O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                              O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

                              --
                              End of file - 4868 bytes


                              Maar weet jij toevallig betere virus scanner dan avast ?

                              grtz,

                              Comment

                              Sorry, you are not authorized to view this page
                              Working...
                              X