Mededeling

Collapse
No announcement yet.

Opstartproblemen start.bat

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Opstartproblemen start.bat

    hallo iedereen,

    Bij het opstarten vindt norton anti-virus een trojan horse c:\start.bat.
    als ik deze opzoek op de c-schijf vindt hij deze niet.
    Ik heb alle manieren al geprobeerd om het te verwijderen, o.a. windows defender, adware etc. maar krijg het niet verwijderd.
    Bij het opstarten wordt ook de firewall uitgeschakeld.
    Zou iemand mij kunnen helpen om dit probleem op te lossen

    hierbij het logje


    Logfile of HijackThis v1.99.1
    scan saved at 11:34:17, on 2-2-2008
    platform: windows xp sp2 (winnt 5.01.2600)
    msie: internet explorer v6.00 sp2 (6.00.2900.2180)
    browser: Mozilla Firefox x.x
    ColorCoder Build: 4136

    browser: internet explorer 6.0
    colorcoder build: 4136


    Running Processes:
    c:\windows\system32\smss.exe
    c:\windows\system32\winlogon.exe
    c:\windows\system32\services.exe
    c:\windows\system32\lsass.exe
    c:\windows\system32\svchost.exe
    c:\program files\windows defender\msmpeng.exe
    c:\windows\system32\svchost.exe
    c:\windows\system32\spoolsv.exe
    c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe
    c:\program files\home cinema\powercinema\kernel\tv\clcapsvc.exe
    c:\program files\home cinema\powercinema\kernel\clml_ntservice\clmlserver.exe
    c:\windows\system32\svchost.exe
    c:\program files\common files\lightscribe\lssrvc.exe
    c:\program files\common files\microsoft shared\vs7debug\mdm.exe
    c:\windows\system32\nvsvc32.exe
    c:\program files\cyberlink\shared files\richvideo.exe
    c:\windows\system32\svchost.exe
    c:\program files\home cinema\powercinema\kernel\tv\clsched.exe
    c:\windows\explorer.exe
    c:\windows\rthdcpl.exe
    c:\program files\medion info display\mdionlcm.exe
    c:\windows\mhotkey.exe
    c:\windows\cnyhkey.exe
    c:\windows\system32\cmucreye.exe
    c:\program files\home cinema\powercinema\pcmservice.exe
    c:\windows\vsnpstd.exe
    c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe
    c:\program files\hewlett-packard\hp software update\hpwuschd2.exe
    c:\program files\quicktime\qttask.exe
    c:\windows\system32\rundll32.exe
    c:\program files\hp\hpcoretech\hpcmpmgr.exe
    c:\program files\windows defender\msascui.exe
    c:\progra~1\common~1\x10\common\x10nets.exe
    c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe
    c:\documents and settings\sharin\mijn documenten\picasa2\picasamediadetector.exe
    c:\windows\system32\ctfmon.exe
    c:\program files\windows media player\wmpnscfg.exe
    c:\program files\toshiba\bluetooth toshiba stack\tosbtmng.exe
    c:\progra~1\incred~1\bin\imapp.exe
    c:\program files\toshiba\bluetooth toshiba stack\tosa2dp.exe
    c:\program files\toshiba\bluetooth toshiba stack\tosbthsp.exe
    c:\progra~1\incred~1\bin\imnotfy.exe
    c:\program files\internet explorer\iexplore.exe
    c:\program files\common files\microsoft shared\windows live\wlloginproxy.exe
    c:\documents and settings\ton\mijn documenten\hjt\hijackthis.exe

    (r0) - hkcu\software\microsoft\internet explorer\main,start page = http://www.startpagina.nl/
    (r1) - hklm\software\microsoft\internet explorer\main,default_page_url = http://www.aldi.com/
    (r0) - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername = koppelingen
    (o2) - bho: acroiehlprobj class - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
    (o2) - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
    (o2) - bho: windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
    (o4) - HKLM\..\Run: [nvcpldaemon] rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup
    (o4) - HKLM\..\Run: [nwiz] nwiz.exe /install
    (o4) - HKLM\..\Run: [nvmediacenter] rundll32.exe nvmctray.dll,nvtaskbarinit
    (o4) - HKLM\..\Run: [rthdcpl] rthdcpl.exe
    (o4) - HKLM\..\Run: [alcmtr] alcmtr.exe
    (o4) - HKLM\..\Run: [medionvfd] "c:\program files\medion info display\mdionlcm.exe"
    (o4) - HKLM\..\Run: [chotkey] mhotkey.exe
    (o4) - HKLM\..\Run: [ledpointer] cnyhkey.exe
    (o4) - HKLM\..\Run: [cmucrrun] c:\windows\system32\cmucreye.exe
    (o4) - HKLM\..\Run: [nerofiltercheck] c:\windows\system32\nerocheck.exe
    (o4) - HKLM\..\Run: [imjpmig8.1] "c:\windows\ime\imjp8_1\imjpmig.exe" /spoil /remadvdef /migration32
    (o4) - HKLM\..\Run: [mspy2002] c:\windows\system32\ime\pintlgnt\imscinst.exe /sync
    (o4) - HKLM\..\Run: [phime2002async] c:\windows\system32\ime\tintlgnt\tintsetp.exe /sync
    (o4) - HKLM\..\Run: [phime2002a] c:\windows\system32\ime\tintlgnt\tintsetp.exe /imename
    (o4) - HKLM\..\Run: [antivirusregistration] c:\program files\ca\etrust antivirus\register.exe
    (o4) - HKLM\..\Run: [pcmservice] "c:\program files\home cinema\powercinema\pcmservice.exe"
    (o4) - HKLM\..\Run: [instanton] "c:\program files\cyberlink\powercinema linux\ion_install.exe /c "
    (o4) - HKLM\..\Run: [snpstd] c:\windows\vsnpstd.exe
    (o4) - HKLM\..\Run: [hpdj taskbar utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe
    (o4) - HKLM\..\Run: [hp software update] "c:\program files\hewlett-packard\hp software update\hpwuschd2.exe"
    (o4) - HKLM\..\Run: [quicktime task] "c:\program files\quicktime\qttask.exe" -atboottime
    (o4) - HKLM\..\Run: [bluetoothauthenticationagent] rundll32.exe bthprops.cpl,,bluetoothauthenticationagent
    (o4) - HKLM\..\Run: [hp component manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
    (o4) - HKLM\..\Run: [windows defender] "c:\program files\windows defender\msascui.exe" -hide
    (o4) - HKLM\..\Run: [support audio cool poll] c:\documents and settings\all users\application data\internet spam support audio\soft logo.exe
    (o4) - HKLM\..\Run: [avp] "c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe"
    (o4) - HKLM\..\Run: [picasa media detector] c:\documents and settings\sharin\mijn documenten\picasa2\picasamediadetector.exe
    (o4) - HKCU\..\Run: [incredimail] c:\program files\incredimail\bin\incmail.exe /c
    (o4) - HKCU\..\Run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    (o4) - HKCU\..\Run: [updatemgr] c:\program files\adobe\acrobat 7.0\reader\adobeupdatemanager.exe acrdb7_0_9
    (o4) - HKCU\..\Run: [wmpnscfg] c:\program files\windows media player\wmpnscfg.exe
    (o4) - HKCU\..\Run: [proc spam] c:\docume~1\ton\applic~1\onesty~1\dart bias surf.exe
    (o4) - Global Startup: bluetooth manager.lnk = ?
    (o8) - extra context menu item: e&xporteren naar microsoft excel - res://c:\progra~1\micros~4\office11\excel.exe/3000
    (o9) - extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.5.0_04\bin\npjpi150_04.dll
    (o9) - extra 'tools' menuitem: sun java console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.5.0_04\bin\npjpi150_04.dll
    (o9) - extra button: anti-virus voor internet statistieken - {1f460357-8a94-4d71-9ca3-aa4acf32ed8e} - c:\program files\kaspersky lab\kaspersky anti-virus 7.0\scieplgn.dll
    (o9) - extra button: onderzoek - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~4\office11\refiebar.dll
    (o9) - extra button: (no name) - {b205a35e-1fc4-4ce3-818b-899dbbb3388c} - c:\program files\common files\microsoft shared\encarta search bar\encsbar.dll
    (o9) - extra button: messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
    (o9) - extra 'tools' menuitem: windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
    (o14) - iereset.inf: start_page_url=http://www.aldi.com/
    (o16) - dpf: {17492023-c23a-453e-a040-c7c580bbf700} (windows genuine advantage validation tool) - http://go.microsoft.com/fwlink/?linkid=39204
    (o16) - dpf: {4f1e5b1a-2a80-42ca-8532-2d05cb959537} (msn photo upload tool) - http://gfx2.hotmail.com/mail/w2/resources/msnpupld.cab
    (o16) - dpf: {6414512b-b978-451d-a0d8-fcfdf33e833c} (wuwebcontrol class) - http://update.microsoft.com/windowsupdate/v6/v5controls/en/x86/client/wuweb_site.cab?1130364442791
    (o16) - dpf: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (muwebcontrol class) - http://update.microsoft.com/microsoftupdate/v6/v5controls/en/x86/client/muweb_site.cab?1131365030359
    (o16) - dpf: {6e5e167b-1566-4316-b27f-0ddab3484cf7} (image uploader control) - http://www.mijnalbum.nl/skin/v2/system/upload/imageuploader4.cab
    (o16) - dpf: {b38870e4-7ecb-40da-8c6a-595f0a5519ff} (msnmessengersetupdownloadcontrol class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
    (o16) - dpf: {daf94f73-2aa6-44d8-a562-a28831820d34} (pixum easyuploadx control) - http://www.pixum.de/int/easyupload/imguploader.cab
    (o18) - protocol: livecall - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\msnmes~1\msgrap~1.dll
    (o18) - protocol: msnim - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\msnmes~1\msgrap~1.dll
    (o20) - winlogon notify: klogon - c:\windows\system32\klogon.dll
    (o20) - winlogon notify: wgalogon - c:\windows\system32\wgalogon.dll
    (o21) - ssodl: wpdshserviceobj - {aaa288ba-9a4c-45b0-95d7-94d524869db5} - c:\windows\system32\wpdshserviceobj.dll
    (o23) - Service: kaspersky anti virus 7.0 (avp) - unknown owner - c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe" -r (file missing)
    (o23) - Service: cyberlink background capture service (cbcs) (clcapsvc) - unknown owner - c:\program files\home cinema\powercinema\kernel\tv\clcapsvc.exe
    (o23) - Service: cyberlink task scheduler (cts) (clsched) - unknown owner - c:\program files\home cinema\powercinema\kernel\tv\clsched.exe
    (o23) - Service: cyberlink media library service - cyberlink - c:\program files\home cinema\powercinema\kernel\clml_ntservice\clmlserver.exe
    (o23) - Service: google updater service (gusvc) - google - c:\program files\google\common\google updater\googleupdaterservice.exe
    (o23) - Service: installdriver table manager (idrivert) - macrovision corporation - c:\program files\common files\installshield\driver\11\intel 32\idrivert.exe
    (o23) - Service: lightscribeservice direct disc labeling service (lightscribeservice) - hewlett-packard company - c:\program files\common files\lightscribe\lssrvc.exe
    (o23) - Service: nvidia display driver service (nvsvc) - nvidia corporation - c:\windows\system32\nvsvc32.exe
    (o23) - Service: cyberlink richvideo service(crvs) (richvideo) - unknown owner - c:\program files\cyberlink\shared files\richvideo.exe
    (o23) - Service: x10 device network service (x10nets) - x10 - c:\progra~1\common~1\x10\common\x10nets.exe
    copyright nano, created for nationaal computer forum www.nationaalcomputerforum.nl[/hijack]

  • #2
    Je gebruikt een oude versie van HijackThis. Best dat je deze versie gebruikt: http://www.trendsecure.com/portal/en...HJTInstall.exe

    Comment


    • #3
      Sorry,

      Betekend dit dat ik een nieuw logje aan moet maken?

      m.vr.groet
      jac schalk

      Comment


      • #4
        Ja en zonder die kleurtjes graag.

        Comment


        • #5
          Je post je logje hier ook: http://www.nationaalcomputerforum.nl...ad.php?t=36418

          Ga je daar nu een berichtje posten dat je hier al geholpen wordt?

          Comment


          • #6
            sorry,

            uiteraard ga ik daar een melding maken.
            volgens mij is er niemand aanwezig die mij op dit moment kan helpen.

            hierbij het nieuwe logje

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 15:36:09, on 4-2-2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
            C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
            C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\Medion Info Display\MdionLCM.exe
            C:\WINDOWS\mHotkey.exe
            C:\WINDOWS\CNYHKey.exe
            C:\WINDOWS\system32\CmUCReye.exe
            C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
            C:\WINDOWS\vsnpstd.exe
            C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
            C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
            C:\Documents and Settings\Sharin\Mijn documenten\Picasa2\PicasaMediaDetector.exe
            C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Windows Media Player\WMPNSCFG.exe
            C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
            C:\PROGRA~1\INCRED~1\bin\IMApp.exe
            C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
            C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
            C:\PROGRA~1\INCRED~1\bin\ImNotfy.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com/
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
            O4 - HKLM\..\Run: [MedionVFD] "C:\Program Files\Medion Info Display\MdionLCM.exe"
            O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
            O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
            O4 - HKLM\..\Run: [CmUCRRun] C:\WINDOWS\system32\CmUCReye.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
            O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
            O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
            O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
            O4 - HKLM\..\Run: [AntivirusRegistration] C:\Program Files\CA\Etrust Antivirus\Register.exe
            O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
            O4 - HKLM\..\Run: [InstantOn] "C:\Program Files\CyberLink\PowerCinema Linux\ion_install.exe /c "
            O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
            O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
            O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
            O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
            O4 - HKLM\..\Run: [Support audio cool poll] C:\Documents and Settings\All Users\Application Data\INTERNET SPAM SUPPORT AUDIO\soft logo.exe
            O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
            O4 - HKLM\..\Run: [Picasa Media Detector] C:\Documents and Settings\Sharin\Mijn documenten\Picasa2\PicasaMediaDetector.exe
            O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKCU\..\Run: [Proc Spam] C:\DOCUME~1\Ton\APPLIC~1\ONESTY~1\dart bias surf.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: Bluetooth Manager.lnk = ?
            O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
            O9 - Extra button: Anti-Virus voor internet statistieken - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
            O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com/
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1130364442791
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1131365030359
            O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mijnalbum.nl/skin/v2/system/upload/ImageUploader4.cab
            O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
            O16 - DPF: {DAF94F73-2AA6-44D8-A562-A28831820D34} (Pixum EasyUploadX Control) - http://www.pixum.de/int/EasyUpload/ImgUploader.cab
            O23 - Service: Kaspersky Anti Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
            O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
            O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
            O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

            --
            End of file - 9575 bytes

            jac

            Comment


            • #7
              Je moet soms wat geduld hebben jac.
              Dit gebeurt op alle fora op vrijwillige basis.
              Best dat je inderdaad meldt dat we hier proberen de problemen op te lossen, zodat niemand onnodig zijn tijd op dat forum gaat besteden in jouw logje.


              Sluit alle open vensters.
              Start HijackThis nog een keer en plaats een vinkje bij de volgende items:

              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
              O4 - HKLM\..\Run: [Support audio cool poll] C:\Documents and Settings\All Users\Application Data\INTERNET SPAM SUPPORT AUDIO\soft logo.exe
              O4 - HKCU\..\Run: [Proc Spam] C:\DOCUME~1\Ton\APPLIC~1\ONESTY~1\dart bias surf.exe


              Klik daarna op "Fix checked" en sluit HijackThis af.

              Download dit bestand: Deljob.exe
              Plaats het op je bureaublad.
              Dubbelklik Deljob.exe.
              Een logje (logit.txt) zal openen, het bestandje kan je ook terugvinden op je bureaublad.
              Herstart de computer.
              Post de inhoud van logit.txt in je volgende bericht.
              Start HijackThis opnieuw, maak een nieuwe log en post deze.

              Comment


              • #8
                natuurlijk heb ik geduld. ik waardeer het namelijk zeer dat jullie mensen willen helpen.
                sorry als ik verkeerd overkom.

                hierbij logit.txt

                --------------------------------------------------------
                File(s) moved to C:\deljob

                ACCAF21191856E41.job
                B1597A3B9396EB2B.job
                --------------------------------------------------------
                Files remaining after cleaning

                MP Scheduled Scan.job
                Symantec NetDetect.job
                --------------------------------------------------------
                App data folders

                De volumenaam van station C is BOOT
                Het volumenummer is 404E-7453

                Map van C:\Documents and Settings\Ton\Application Data

                04-02-2008 14:10 <DIR> .
                04-02-2008 14:10 <DIR> ..
                28-01-2007 22:22 <DIR> Adobe
                29-01-2007 18:50 <DIR> AdobeUM
                12-06-2007 19:01 <DIR> Ahead
                07-11-2005 12:30 <DIR> CYBERL~1 CyberLink
                30-10-2006 19:05 <DIR> Google
                03-04-2006 20:13 <DIR> Help
                26-10-2005 22:27 <DIR> IDENTI~1 Identities
                16-02-2006 14:32 <DIR> Lavasoft
                07-11-2005 13:08 <DIR> MACROM~1 Macromedia
                01-04-2007 16:34 <DIR> MICROS~1 Microsoft
                20-01-2008 11:15 <DIR> ONESTY~1 ONESTYLEDATE
                07-11-2005 11:35 <DIR> Real
                07-11-2005 10:44 <DIR> Sun
                27-04-2006 19:31 <DIR> Symantec
                0 bestand(en) 0 bytes
                16 map(pen) 75.141.218.304 bytes beschikbaar
                De volumenaam van station C is BOOT
                Het volumenummer is 404E-7453

                Map van C:\Documents and Settings\All Users\Application Data

                21-01-2008 18:51 <DIR> .
                21-01-2008 18:51 <DIR> ..
                27-10-2005 01:08 <DIR> Adobe
                27-10-2005 00:57 <DIR> Ahead
                07-11-2005 11:31 <DIR> APPLEC~1 Apple Computer
                07-11-2005 12:30 <DIR> CYBERL~1 CyberLink
                18-02-2007 16:13 <DIR> Google
                04-02-2008 12:04 <DIR> KASPER~1 Kaspersky Lab
                15-11-2006 18:10 <DIR> MESSEN~1 Messenger Plus!
                05-01-2008 18:19 <DIR> MICROS~1 Microsoft
                27-10-2005 01:31 <DIR> MUVEET~1 muvee Technologies
                26-10-2005 22:47 <DIR> NVIDIA
                03-03-2006 17:19 <DIR> QUICKT~1 QuickTime
                27-10-2005 02:09 <DIR> SBSI
                16-01-2008 20:16 <DIR> Symantec
                06-01-2008 11:03 <DIR> TNTPOS~1 TNT Post Fotoservice
                26-10-2005 23:11 <DIR> WINDOW~1 Windows Genuine Advantage
                07-09-2006 20:58 <DIR> Zylom
                0 bestand(en) 0 bytes
                18 map(pen) 75.141.218.304 bytes beschikbaar
                --------------------------------------------------------

                en het logje van hijackthis

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 15:58:02, on 4-2-2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Windows Defender\MsMpEng.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
                C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
                C:\WINDOWS\RTHDCPL.EXE
                C:\Program Files\Medion Info Display\MdionLCM.exe
                C:\WINDOWS\mHotkey.exe
                C:\WINDOWS\CNYHKey.exe
                C:\WINDOWS\system32\CmUCReye.exe
                C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
                C:\WINDOWS\vsnpstd.exe
                C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
                C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                C:\Program Files\QuickTime\qttask.exe
                C:\WINDOWS\system32\rundll32.exe
                C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                C:\Documents and Settings\Sharin\Mijn documenten\Picasa2\PicasaMediaDetector.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Windows Media Player\WMPNSCFG.exe
                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
                C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
                C:\PROGRA~1\INCRED~1\bin\ImNotfy.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com/
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                O4 - HKLM\..\Run: [MedionVFD] "C:\Program Files\Medion Info Display\MdionLCM.exe"
                O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
                O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
                O4 - HKLM\..\Run: [CmUCRRun] C:\WINDOWS\system32\CmUCReye.exe
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                O4 - HKLM\..\Run: [AntivirusRegistration] C:\Program Files\CA\Etrust Antivirus\Register.exe
                O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
                O4 - HKLM\..\Run: [InstantOn] "C:\Program Files\CyberLink\PowerCinema Linux\ion_install.exe /c "
                O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
                O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
                O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
                O4 - HKLM\..\Run: [Picasa Media Detector] C:\Documents and Settings\Sharin\Mijn documenten\Picasa2\PicasaMediaDetector.exe
                O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O4 - Global Startup: Bluetooth Manager.lnk = ?
                O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                O9 - Extra button: Anti-Virus voor internet statistieken - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
                O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com/
                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1130364442791
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1131365030359
                O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mijnalbum.nl/skin/v2/system/upload/ImageUploader4.cab
                O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                O16 - DPF: {DAF94F73-2AA6-44D8-A562-A28831820D34} (Pixum EasyUploadX Control) - http://www.pixum.de/int/EasyUpload/ImgUploader.cab
                O23 - Service: Kaspersky Anti Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
                O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
                O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

                --
                End of file - 9144 bytes

                het opstarten ging nu probleemloos

                m.vr.groet
                jac schalk

                Comment


                • #9
                  Hallo Jac,

                  Doe dit nog:

                  Open een kladblokbestand.
                  Kopieer onderstaande (alles wat vetgedrukt is) in dit kladblokbestand.

                  @ECHO OFF
                  IF EXIST log.txt DEL log.txt
                  ECHO Deleting folders>>log.txt
                  FOR %%I in (
                  "C:\Documents and Settings\All Users\Application Data\INTERNET SPAM SUPPORT AUDIO"
                  "C:\Documents and Settings\Ton\Application Data\ONESTYLEDATE"
                  C:\deljob) DO (
                  IF EXIST %%I (
                  RD /S /Q %%I
                  IF EXIST %%I (
                  ECHO %%I not deleted>>log.txt
                  ) ELSE (
                  ECHO %%I deleted>>log.txt)
                  ) ELSE (
                  ECHO %%I not found>>log.txt))
                  START NOTEPAD.EXE log.txt

                  Ga naar Bestand - Opslaan als.
                  Bij "Opslaan in" kies je: Bureaublad
                  Bij "Bestandsnaam" zet je: del.bat
                  Bij "Opslaan als type" selecteer je: Alle bestanden (*.*).
                  Klik op de knop Opslaan.

                  Dubbelklik op del.bat en post de inhoud van de logfile die opent.

                  Comment


                  • #10
                    het volgende logje

                    Deleting folders
                    "C:\Documents and Settings\All Users\Application Data\INTERNET SPAM SUPPORT AUDIO" not found
                    "C:\Documents and Settings\Ton\Application Data\ONESTYLEDATE" deleted
                    C:\deljob deleted

                    jac

                    Comment


                    • #11
                      Mooi.

                      Alle problemen zijn opgelost Jac?

                      Scan de computer met een geupdate Ad-Aware 2007. Instructies vind je hier.
                      Deze scan doe je bij voorkeur in veilige modus.
                      Laat Ad-Aware 2007 verwijderen wat het vindt aan geïnfecteerde bestanden of malware gerelateerde registersleutels.

                      Zijn er nog andere accounts aanwezig op deze computer?

                      Comment


                      • #12
                        geweldig.

                        heel hartelijk bedankt.
                        in totaal maken 4 mensen gebruik van een eigen account.
                        moet ik hiervoor nog een aktie uitvoeren

                        jac

                        Comment


                        • #13
                          Laat Ad-aware eerst scannen, daarna maak je een logje (één per één) van de andere accounts.

                          Comment


                          • #14
                            moet dit een logje van hijackthis zijn

                            Comment


                            • #15
                              Ja. De log van Ad-Aware die heb ik niet nodig.

                              Comment

                              Sorry, you are not authorized to view this page
                              Working...
                              X