Mededeling

Collapse
No announcement yet.

Trage werking van de computer

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Trage werking van de computer

    Mijn computer is zeer traag. Krijg geregeld de melding om eventueel "baanbreker" te installeren. Ik zou ongeveer 15000 "foutjes" hebben. Ik heb de C-schijf als eens opgekuist. Maar ik krijg nog altijd de melding dat mijn computer traag is. Weet gij wat te doen?

    Bijgevoegd blog Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 12:50:21, on 16/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Ik ben een bleu in computers

  • #2
    Indien je nog problemen ondervind, kan je eens een volledig Hijackthis logje plaatsen?
    Groet,
    Pimmerd

    Comment


    • #3
      Verdere informatie ivm trage computer.

      Comment


      • #4
        Heb doctor spyware laten lopen op mij computer met de bijgevoegd word.doc ge attached
        Bijgevoegde Bestanden

        Comment


        • #5
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://breedband.telenet.be
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Telenet Internet
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://pac.telenet.be:8080
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
          R3 - URLSearchHook: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul1.dll
          O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: ContextAdvisor - {87E68009-29A8-D669-F7C2-B31D08635C50} - C:\Program Files\ContextAdvisor\ContextAdvisor-2.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
          O2 - BHO: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul1.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul1.dll
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [Snelkoppeling naar eigenschappenvenster voor High Definition Audio] HDAudPropShortcut.exe
          O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
          O4 - HKLM\..\Run: [Dit] Dit.exe
          O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
          O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
          O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
          O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELENE~1\SMARTB~1\MotiveSB.exe
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
          O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [WA6PM_Check] "C:\Program Files\Common Files\DriveCleaner Free\udcwap.exe"
          O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
          O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\SCHIJF~1\ucookw.exe" -start
          O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\SchijfBewaker\strpmon.exe" dm=http://schijfbewaker.com ad=http://schijfbewaker.com sd=http://inlog.schijfbewaker.com
          O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
          O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
          O4 - Startup: PowerReg SchedulerV2.exe
          O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
          O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
          O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
          O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
          O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
          O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: Openen in een nieuwe achtergrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-be\msntabres.dll.mui/229?4e67066dea734ab5b3d2de0cb1df822c
          O8 - Extra context menu item: Openen in een nieuwe voorgrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-be\msntabres.dll.mui/230?4e67066dea734ab5b3d2de0cb1df822c
          O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
          O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
          O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com

          Comment


          • #6
            O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
            O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
            O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://62.100.53.122/activex/AxisCamControl.cab
            O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/74914091/activex/IPSUploader4.cab
            O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.5/installer.exe
            O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
            O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
            O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exeO23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
            O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
            O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
            O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
            O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
            O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
            O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

            Comment


            • #7
              Ik heb nog steeds geen volledig Hijackthis logje, het is belangrijk dat je het hele bestand kopieert wat opent.
              Groet,
              Pimmerd

              Comment


              • #8
                Sorry, nog eens geprobeerd deze keer hoop ik het goed gedaan te hebben

                Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                Scan saved at 18:16:23, on 24/03/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Sygate\SPF\smc.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\System32\SCardSvr.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\RunDll32.exe
                C:\WINDOWS\AGRSMMSG.exe
                C:\WINDOWS\Dit.exe
                C:\WINDOWS\mHotkey.exe
                C:\WINDOWS\CNYHKey.exe
                C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
                C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
                C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
                C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                C:\Program Files\QuickTime\QTTask.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Windows Live\Family Safety\fssui.exe
                C:\Program Files\Spyware Doctor\pctsTray.exe
                C:\Program Files\Messenger\msmsgs.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Windows Media Player\WMPNSCFG.exe
                C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
                C:\WINDOWS\DvzCommon\DvzMsgr.exe
                C:\Program Files\Palm\HOTSYNC.EXE
                C:\WINDOWS\system32\agrsmsvc.exe
                C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
                C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                C:\WINDOWS\system32\nvsvc32.exe
                C:\Program Files\Spyware Doctor\pctsAuxs.exe
                C:\Program Files\Spyware Doctor\pctsSvc.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Windows Media Player\WMPNetwk.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe
                C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\WINDOWS\system32\locator.exe
                C:\WINDOWS\System32\alg.exe
                C:\Program Files\eMule\emule.exe
                C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\pcinstallatie\computer beveiliging\HiJackThis_v2.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://breedband.telenet.be
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Telenet Internet
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://pac.telenet.be:8080
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
                R3 - URLSearchHook: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul1.dll
                O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: ContextAdvisor - {87E68009-29A8-D669-F7C2-B31D08635C50} - C:\Program Files\ContextAdvisor\ContextAdvisor-2.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
                O2 - BHO: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul1.dll
                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul1.dll
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [Snelkoppeling naar eigenschappenvenster voor High Definition Audio] HDAudPropShortcut.exe
                O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                O4 - HKLM\..\Run: [Dit] Dit.exe
                O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
                O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
                O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELENE~1\SMARTB~1\MotiveSB.exe
                O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
                O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
                O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                O4 - HKLM\..\Run: [WA6PM_Check] "C:\Program Files\Common Files\DriveCleaner Free\udcwap.exe"
                O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
                O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\SCHIJF~1\ucookw.exe" -start
                O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
                O4 - Startup: PowerReg SchedulerV2.exe
                O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
                O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
                O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                O8 - Extra context menu item: Openen in een nieuwe achtergrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-be\msntabres.dll.mui/229?4e67066dea734ab5b3d2de0cb1df822c
                O8 - Extra context menu item: Openen in een nieuwe voorgrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-be\msntabres.dll.mui/230?4e67066dea734ab5b3d2de0cb1df822c
                O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
                O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com
                O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
                O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
                O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://62.100.53.122/activex/AxisCamControl.cab
                O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/74914091/activex/IPSUploader4.cab
                O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.5/installer.exe
                O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
                O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
                O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
                O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
                O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
                O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
                O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

                --
                End of file - 14964 bytes

                Comment


                • #9
                  Dat is al prima

                  1. Ga naar start --> configuratiescherm --> software en verwijder daar, indien aanwezig:
                  SweetIM
                  DriveCleaner Free
                  Schijfbewaker


                  Herstart je PC, maak een nieuw Hijackthis logje en plaats die in je volgende post.
                  Groet,
                  Pimmerd

                  Comment


                  • #10
                    Gezocht naar Sweet IM, schijfbewaker en DriveCleaner Free zowel bij software en via alle programma's. Ik heb alleen schijfbewaker gevonden in alle programma's heb heb deze verwijderd. Heb opnieuw Hijack laten lopen. en voeg deze er bij

                    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                    Scan saved at 16:40:32, on 26/03/2008
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Sygate\SPF\smc.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\System32\SCardSvr.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\RunDll32.exe
                    C:\WINDOWS\AGRSMMSG.exe
                    C:\WINDOWS\Dit.exe
                    C:\WINDOWS\mHotkey.exe
                    C:\WINDOWS\CNYHKey.exe
                    C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
                    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                    C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                    C:\WINDOWS\system32\agrsmsvc.exe
                    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
                    C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
                    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                    C:\Program Files\QuickTime\QTTask.exe
                    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
                    C:\Program Files\Bonjour\mDNSResponder.exe
                    C:\Program Files\Windows Live\Family Safety\fssui.exe
                    C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                    C:\Program Files\Spyware Doctor\pctsTray.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Windows Media Player\WMPNSCFG.exe
                    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
                    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
                    C:\WINDOWS\DvzCommon\DvzMsgr.exe
                    C:\Program Files\Palm\HOTSYNC.EXE
                    C:\Program Files\Spyware Doctor\pctsAuxs.exe
                    C:\Program Files\Spyware Doctor\pctsSvc.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Windows Media Player\WMPNetwk.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                    C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                    C:\WINDOWS\system32\locator.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\pcinstallatie\computer beveiliging\HiJackThis_v2.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://breedband.telenet.be
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Telenet Internet
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://pac.telenet.be:8080
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
                    R3 - URLSearchHook: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul1.dll
                    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: ContextAdvisor - {87E68009-29A8-D669-F7C2-B31D08635C50} - C:\Program Files\ContextAdvisor\ContextAdvisor-2.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
                    O2 - BHO: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul1.dll
                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O3 - Toolbar: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul1.dll
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                    O4 - HKLM\..\Run: [Snelkoppeling naar eigenschappenvenster voor High Definition Audio] HDAudPropShortcut.exe
                    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                    O4 - HKLM\..\Run: [Dit] Dit.exe
                    O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
                    O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
                    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                    O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELENE~1\SMARTB~1\MotiveSB.exe
                    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
                    O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
                    O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                    O4 - HKLM\..\Run: [WA6PM_Check] "C:\Program Files\Common Files\DriveCleaner Free\udcwap.exe"
                    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
                    O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\SCHIJF~1\ucookw.exe" -start
                    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                    O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
                    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
                    O4 - Startup: PowerReg SchedulerV2.exe
                    O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
                    O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
                    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                    O8 - Extra context menu item: Openen in een nieuwe achtergrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-be\msntabres.dll.mui/229?4e67066dea734ab5b3d2de0cb1df822c
                    O8 - Extra context menu item: Openen in een nieuwe voorgrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-be\msntabres.dll.mui/230?4e67066dea734ab5b3d2de0cb1df822c
                    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
                    O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com
                    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                    O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
                    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
                    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://62.100.53.122/activex/AxisCamControl.cab
                    O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/74914091/activex/IPSUploader4.cab
                    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.5/installer.exe
                    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
                    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
                    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
                    O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
                    O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
                    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                    O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
                    O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

                    --
                    End of file - 14841 bytes

                    Comment


                    • #11
                      Volg deze instructies om ComboFix te downloaden:
                      • Voer de instructies op de BleepingComputer pagina uit, inclusief het installeren van de XP Recovery Console
                        Indien je Combofix al eerder hebt gebruikt, gelieve die versie te verwijderen en Combofix opnieuw te downloaden via bovenstaande link, want Combofix wordt dagelijks geupdate.

                        OPMERKING: indien je, tijdens of na het downloaden van Combofix of tijdens het gebruik van Combofix een melding krijgt van je Antivirus- of een andere realtime scanner,
                        schakel dan deze scanner uit en download Combofix opnieuw.
                        Sommige scanners zien bepaalde componenten die Combofix gebruikt als verdacht en gaan deze blokkeren of verwijderen!
                        • Dubbelklik op Combofix.exe
                          Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.
                          Wanneer de fix voltooid is en na herstart, zal de log Combofix.txt openen.


                        Plaats deze log in je volgende post, samen met een vers HijackThis logje.
                      Groet,
                      Pimmerd

                      Comment


                      • #12
                        Heb gedaan wat gevraagd werd zie hier de logboeks

                        1. combifix:log

                        ComboFix 08-03-26.1 - OEM 2008-03-27 16:38:32.1 - NTFSx86
                        Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.229 [GMT 1:00]
                        Gestart vanuit: C:\Documents and Settings\OEM\Bureaublad\ComboFix.exe
                        .

                        (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
                        .

                        C:\Program Files\Common Files\drivecleaner free
                        C:\Program Files\Common Files\drivecleaner free\udcwap.exe

                        .
                        ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                        .

                        -------\Service_NPF


                        (((((((((((((((((((( Bestanden Gemaakt van 2008-02-27 to 2008-03-27 ))))))))))))))))))))))))))))))
                        .

                        2008-03-20 18:58 . 2008-03-20 18:58 <DIR> d-------- C:\Program Files\Type Expert Junior
                        2008-03-19 17:04 . 2008-03-19 17:41 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
                        2008-03-19 17:04 . 2008-03-19 17:04 <DIR> d-------- C:\Documents and Settings\OEM\Application Data\SUPERAntiSpyware.com
                        2008-03-19 17:04 . 2008-03-19 17:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
                        2008-03-18 19:17 . 2008-03-18 19:17 <DIR> d-------- C:\Program Files\svcdplaza
                        2008-03-16 18:37 . 2008-03-27 16:32 <DIR> d-------- C:\Program Files\Spyware Doctor
                        2008-03-16 18:37 . 2008-03-16 18:37 <DIR> d-------- C:\Documents and Settings\OEM\Application Data\PC Tools
                        2008-03-16 18:37 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
                        2008-03-16 18:37 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
                        2008-03-16 18:37 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
                        2008-03-16 18:37 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
                        2008-03-15 15:05 . 2008-03-15 15:05 <DIR> d-------- C:\Documents and Settings\OEM\Application Data\schijfbewaker
                        2008-03-15 15:02 . 2008-03-15 15:02 <DIR> dr------- C:\Documents and Settings\All Users\Application Data\schijfbewaker
                        2008-03-15 15:01 . 2008-03-15 15:01 <DIR> dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
                        2008-03-15 15:00 . 2008-03-19 20:14 <DIR> d-------- C:\Program Files\Common Files\SchijfBewaker
                        2008-03-15 14:54 . 2008-03-15 14:54 260,384 --a------ C:\Documents and Settings\OEM\Application Data\setup_nl[1].exe
                        2008-03-15 13:59 . 2007-10-17 13:53 43,816 --a------ C:\WINDOWS\system32\drivers\fssfltr.sys
                        2008-03-15 13:55 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
                        2008-03-15 13:53 . 2008-03-15 13:53 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
                        2008-03-15 13:22 . 2008-03-17 19:39 <DIR> d-------- C:\Program Files\Windows Live
                        2008-03-15 13:22 . 2008-03-15 13:38 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
                        2008-03-15 13:22 . 2008-03-15 13:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
                        2008-03-15 12:24 . 2008-03-15 12:24 <DIR> d-------- C:\Program Files\InfinitySW
                        2008-03-15 12:19 . 2008-03-15 12:22 <DIR> d-------- C:\Program Files\Handmark
                        2008-03-13 18:03 . 2008-03-14 10:48 <DIR> d-------- C:\Program Files\Registry Defender
                        2008-03-01 13:17 . 2008-03-01 13:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\My Games
                        2008-03-01 06:46 . 2008-03-04 21:16 <DIR> d-------- C:\Program Files\VirtualDJ
                        2008-02-29 14:57 . 2008-02-29 14:57 <DIR> d-------- C:\Documents and Settings\OEM\.GalleryRemote
                        2008-02-27 18:12 . 2008-02-27 18:19 <DIR> d-------- C:\Documents and Settings\OEM\Application Data\PowerChallenge

                        .
                        ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        2008-03-27 15:42 17,408 ----a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS
                        2008-03-27 15:35 --------- d-----w C:\Program Files\ContextAdvisor
                        2008-03-27 15:33 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
                        2008-03-25 18:42 --------- d-----w C:\Documents and Settings\OEM\Application Data\Ahead
                        2008-03-25 03:44 --------- d-----w C:\Program Files\eMule
                        2008-03-19 15:59 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
                        2008-03-19 15:59 --------- d-----w C:\Program Files\Common Files\Real
                        2008-03-17 18:35 --------- d-----w C:\Program Files\Realspace3_at
                        2008-03-17 18:24 --------- d-----w C:\Program Files\LimewirePlus
                        2008-03-17 18:22 --------- d-----w C:\Program Files\Zylom Games
                        2008-03-16 09:14 --------- d-----w C:\Program Files\Palm
                        2008-03-16 07:22 --------- d-----w C:\Documents and Settings\OEM\Application Data\LimeWirePlus
                        2008-03-15 13:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
                        2008-03-15 11:25 --------- d-----w C:\Program Files\Kinoma
                        2008-03-15 11:16 --------- d-----w C:\Program Files\Documents To Go
                        2008-03-07 16:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
                        2008-03-02 09:54 --------- d-----w C:\Documents and Settings\OEM\Application Data\Zylom
                        2008-02-27 19:44 --------- d-----w C:\Program Files\Common Files\Adobe
                        2008-02-23 06:28 --------- d-----w C:\Program Files\iTunes
                        2008-02-23 06:27 --------- d-----w C:\Program Files\iPod
                        2008-02-23 06:22 --------- d-----w C:\Program Files\QuickTime
                        2008-02-22 19:41 --------- d-----w C:\Documents and Settings\OEM\Application Data\U3
                        2008-02-17 15:25 47,962 -c--a-w C:\Documents and Settings\OEM\Application Data\wklnhst.dat
                        2008-01-30 18:31 --------- d-----w C:\Program Files\Microsoft Silverlight
                        2008-01-30 17:54 --------- d-----w C:\Documents and Settings\OEM\Application Data\BSplayer
                        2007-03-27 10:37 79,432 -c--a-w C:\Documents and Settings\OEM\Application Data\GDIPFONTCACHEV1.DAT
                        2003-01-13 09:12 278,528 ------w C:\Program Files\internet explorer\plugins\PanoViewer.dll
                        1999-04-30 14:00 98,304 ------w C:\Program Files\internet explorer\plugins\UPjpeg.dll
                        2004-10-08 08:54 8 -csh--r C:\WINDOWS\system32\E1D3DFE4A3.sys
                        2004-10-08 08:54 5,224 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
                        .

                        ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        REGEDIT4
                        *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

                        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
                        2007-12-17 11:12 56360 --a------ C:\Program Files\Windows Live\Family Safety\fssbho.dll

                        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87E68009-29A8-D669-F7C2-B31D08635C50}]
                        2007-12-30 21:48 1019904 --a------ C:\Program Files\ContextAdvisor\ContextAdvisor-2.dll

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
                        "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
                        "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2006-06-06 10:07 40960]
                        "BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
                        "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 21:53 204288]
                        "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-11-06 20:00 8523776]
                        "nwiz"="nwiz.exe" [2007-11-06 20:00 1626112 C:\WINDOWS\system32\nwiz.exe]
                        "Snelkoppeling naar eigenschappenvenster voor High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 15:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
                        "Cmaudio"="cmicnfg.cpl"
                        "AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 15:00 88363 C:\WINDOWS\AGRSMMSG.exe]
                        "Dit"="Dit.exe" [2004-07-20 17:18 90112 C:\WINDOWS\Dit.exe]
                        "CHotkey"="mHotkey.exe" [2004-02-24 13:05 508416 C:\WINDOWS\mHotkey.exe]
                        "ledpointer"="CNYHKey.exe" [2004-02-03 16:15 5794816 C:\WINDOWS\CNYHKey.exe]
                        "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
                        "PCMService"="C:\Program Files\Home Cinema\PowerCinema\PCMService.exe" [2004-10-29 20:34 81920]
                        "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 22:42 176128]
                        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
                        "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2006-06-06 10:07 40960]
                        "avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-10 16:01 249896]
                        "Motive SmartBridge"="C:\PROGRA~1\TELENE~1\SMARTB~1\MotiveSB.exe" [ ]
                        "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-07-14 15:09 57344]
                        "Ulead AutoDetector"="C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-11-19 12:03 45056]
                        "mmtask"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2006-01-17 12:03 53248]
                        "SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
                        "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
                        "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
                        "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
                        "fssui"="C:\Program Files\Windows Live\Family Safety\fssui.exe" [2007-12-17 11:12 243240]
                        "ucookw"="C:\PROGRA~1\SCHIJF~1\ucookw.exe" [ ]

                        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                        "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]

                        C:\Documents and Settings\OEM\Menu Start\Programma's\Opstarten\
                        HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2003-10-14 10:54:12 299008]
                        PowerReg SchedulerV2.exe [2006-07-02 08:34:14 233472]

                        [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
                        "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
                        C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                        "%windir%\\system32\\sessmgr.exe"=
                        "%WinDir%\\system32\\fxsclnt.exe"=
                        "%ProgramFiles%\\CA\\eTrust Antivirus\\InocIT.exe"=
                        "%ProgramFiles%\\CA\\eTrust Antivirus\\Realmon.exe"=
                        "%ProgramFiles%\\CA\\eTrust Antivirus\\InoRpc.exe"=
                        "%ProgramFiles%\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
                        "C:\\Program Files\\Messenger\\msmsgs.exe"=
                        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                        "C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
                        "C:\\Program Files\\LimeWire Plus\\LimeWire.exe"=
                        "C:\\Program Files\\eMule\\emule.exe"=
                        "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                        "C:\\Program Files\\iTunes\\iTunes.exe"=
                        "C:\\Program Files\\Palm\\HOTSYNC.EXE"=
                        "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                        "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

                        R2 fssfltr;FssFltr;C:\WINDOWS\system32\DRIVERS\fssfltr.sys [2007-10-17 13:53]
                        R2 fsssvc;Windows Live OneCare Family Safety;"C:\Program Files\Windows Live\Family Safety\fsssvc.exe" [2007-12-17 11:13]
                        R2 LogWatch;Event Log Watch;"C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe" [2002-09-19 19:29]
                        R3 Cap7134;MEDION (7134) WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2003-06-05 09:04]
                        R3 cmudax;C-Media High Definition Audio Interface;C:\WINDOWS\system32\drivers\cmudax.sys [2005-05-12 13:39]
                        R3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2003-06-12 09:47]
                        R3 wbscr;Winbond Smartcard Reader for I/O;C:\WINDOWS\system32\drivers\wbscr.sys [2002-04-24 11:07]
                        S3 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" [2007-12-05 12:26]
                        S3 CA_LIC_CLNT;CA License Client;"C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe" [2002-09-19 19:27]
                        S3 CA_LIC_SRVR;CA License Server;"C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe" [2002-09-19 19:41]
                        S3 CardReaderFilter;Card Reader Filter;C:\WINDOWS\system32\Drivers\USBCRFT.SYS [2008-03-27 16:42]
                        S3 UKBFLT;UKBFLT;C:\WINDOWS\system32\DRIVERS\UKBFLT.sys [2003-12-19 16:13]

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
                        \Shell\AutoRun\command - H:\LaunchU3.exe -a

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2b6701e5-9534-11dc-a99a-00110957644c}]
                        \Shell\AutoRun\command - J:\LaunchU3.exe -a

                        .
                        Inhoud van de 'Gedeelde Taken' map
                        "2007-12-31 08:06:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
                        - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
                        "2008-03-26 18:12:01 C:\WINDOWS\Tasks\Controleren op updates voor Windows Live Toolbar.job"
                        - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
                        .
                        **************************************************************************

                        catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2008-03-27 16:44:42
                        Windows 5.1.2600 Service Pack 2 NTFS

                        scannen van verborgen processen ...

                        scannen van verborgen autostart items ...

                        scannen van verborgen bestanden ...

                        Scan succesvol afgerond
                        verborgen bestanden: 0

                        **************************************************************************

                        [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
                        "ImagePath"=""
                        .
                        ------------------------ Other Running Processes ------------------------
                        .
                        C:\Program Files\Sygate\SPF\smc.exe
                        C:\WINDOWS\System32\SCardSvr.exe
                        C:\WINDOWS\system32\agrsmsvc.exe
                        C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                        C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                        C:\WINDOWS\system32\RunDll32.exe
                        C:\WINDOWS\system32\nvsvc32.exe
                        C:\Program Files\Windows Media Player\WMPNetwk.exe
                        C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
                        C:\WINDOWS\DvzCommon\DvzMsgr.exe
                        C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\WINDOWS\system32\locator.exe
                        .
                        **************************************************************************
                        .
                        Voltooingstijd: 2008-03-27 16:47:25 - machine was rebooted
                        ComboFix-quarantined-files.txt 2008-03-27 15:47:20
                        Pre-Run: 89,560,977,408 bytes beschikbaar
                        Post-Run: 89,532,600,320 bytes beschikbaar
                        .
                        2008-03-20 04:57:39 --- E O F ---

                        2. Hijacksthis.log:

                        Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                        Scan saved at 16:48:54, on 27/03/2008
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Sygate\SPF\smc.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\system32\agrsmsvc.exe
                        C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                        C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
                        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                        C:\WINDOWS\system32\RunDll32.exe
                        C:\WINDOWS\AGRSMMSG.exe
                        C:\WINDOWS\Dit.exe
                        C:\WINDOWS\mHotkey.exe
                        C:\WINDOWS\CNYHKey.exe
                        C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
                        C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                        C:\WINDOWS\system32\nvsvc32.exe
                        C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                        C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
                        C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
                        C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                        C:\Program Files\QuickTime\QTTask.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\Windows Live\Family Safety\fssui.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Windows Media Player\WMPNSCFG.exe
                        C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                        C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
                        C:\WINDOWS\DvzCommon\DvzMsgr.exe
                        C:\Program Files\Palm\HOTSYNC.EXE
                        C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\WINDOWS\explorer.exe
                        C:\WINDOWS\system32\notepad.exe
                        C:\pcinstallatie\computer beveiliging\HiJackThis_v2.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://pac.telenet.be:8080
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
                        R3 - URLSearchHook: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul1.dll
                        O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O2 - BHO: ContextAdvisor - {87E68009-29A8-D669-F7C2-B31D08635C50} - C:\Program Files\ContextAdvisor\ContextAdvisor-2.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
                        O2 - BHO: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul1.dll
                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul1.dll
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                        O4 - HKLM\..\Run: [Snelkoppeling naar eigenschappenvenster voor High Definition Audio] HDAudPropShortcut.exe
                        O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                        O4 - HKLM\..\Run: [Dit] Dit.exe
                        O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
                        O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                        O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
                        O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                        O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELENE~1\SMARTB~1\MotiveSB.exe
                        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
                        O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
                        O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                        O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
                        O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\SCHIJF~1\ucookw.exe" -start
                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                        O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
                        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                        O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
                        O4 - Startup: PowerReg SchedulerV2.exe
                        O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
                        O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
                        O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                        O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                        O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                        O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                        O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                        O8 - Extra context menu item: Openen in een nieuwe achtergrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-be\msntabres.dll.mui/229?4e67066dea734ab5b3d2de0cb1df822c
                        O8 - Extra context menu item: Openen in een nieuwe voorgrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-be\msntabres.dll.mui/230?4e67066dea734ab5b3d2de0cb1df822c
                        O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                        O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                        O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
                        O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com
                        O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
                        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                        O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
                        O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
                        O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://62.100.53.122/activex/AxisCamControl.cab
                        O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/74914091/activex/IPSUploader4.cab
                        O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.5/installer.exe
                        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                        O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                        O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                        O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
                        O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                        O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
                        O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                        O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
                        O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
                        O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
                        O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                        O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                        O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
                        O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

                        --
                        End of file - 13848 bytes


                        Het beste ermee
                        Alvast tot hier toe bdedankt voor jullie hulp

                        Comment


                        • #13
                          Open Kladblok, kopiëer en plak het volgende (vetgedrukte tekst) in een leeg venster:

                          Folder::
                          C:\Documents and Settings\OEM\Application Data\schijfbewaker
                          C:\Documents and Settings\All Users\Application Data\schijfbewaker
                          C:\Documents and Settings\All Users\Application Data\SalesMon
                          C:\Program Files\Common Files\SchijfBewaker
                          C:\Program Files\ContextAdvisor
                          C:\Program Files\Common Files\BOONTY Shared

                          File::
                          C:\Documents and Settings\OEM\Application Data\setup_nl[1].exe

                          Registry::
                          [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87E68009-29A8-D669-F7C2-B31D08635C50}]
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "ucookw"=-

                          Driver::
                          Boonty Games

                          Sla dit op op je Bureaublad als CFScript.txt

                          Sleep CFScript.txt in ComboFix.exe zoals getoond in onderstaand voorbeeld :



                          Dit zal ComboFix doen herstarten.
                          Start opnieuw op als daarom gevraagd wordt,
                          en post de inhoud van de Combofix.txt in je volgende antwoord

                          Nog problemen?
                          Groet,
                          Pimmerd

                          Comment


                          • #14
                            Hier volgt de nieuwe combifix.txt. Na uitvoeren van het bovenstaande kladblok:

                            ComboFix 08-03-26.1 - OEM 2008-03-27 19:10:49.2 - NTFSx86
                            Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.184 [GMT 1:00]
                            Gestart vanuit: C:\Documents and Settings\OEM\Bureaublad\ComboFix.exe
                            Command switches used :: C:\Documents and Settings\OEM\Bureaublad\CFScript.txt
                            * Nieuw herstelpunt werd aangemaakt

                            FILE ::
                            C:\Documents and Settings\OEM\Application Data\setup_nl[1].exe
                            .

                            (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
                            .

                            C:\Documents and Settings\All Users\Application Data\SalesMon
                            C:\Documents and Settings\All Users\Application Data\schijfbewaker
                            C:\Documents and Settings\All Users\Application Data\schijfbewaker\Data\ac
                            C:\Documents and Settings\All Users\Application Data\schijfbewaker\Data\em
                            C:\Documents and Settings\All Users\Application Data\schijfbewaker\Data\oid
                            C:\Documents and Settings\All Users\Application Data\schijfbewaker\Data\user
                            C:\Documents and Settings\OEM\Application Data\schijfbewaker
                            C:\Documents and Settings\OEM\Application Data\schijfbewaker\Logs\update.log
                            C:\Documents and Settings\OEM\Application Data\setup_nl[1].exe
                            C:\Program Files\Common Files\BOONTY Shared
                            C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
                            C:\Program Files\Common Files\SchijfBewaker
                            C:\Program Files\Common Files\SchijfBewaker\is-PFP9F.VIR
                            C:\Program Files\ContextAdvisor
                            C:\Program Files\ContextAdvisor\ContextAdvisor-2.dll
                            C:\Program Files\ContextAdvisor\ContextAdvisor.dat
                            C:\Program Files\ContextAdvisor\pcre3.dll
                            C:\Program Files\ContextAdvisor\uninstall.exe

                            .
                            ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                            .

                            -------\Legacy_BOONTY_GAMES
                            -------\Service_Boonty Games


                            (((((((((((((((((((( Bestanden Gemaakt van 2008-02-27 to 2008-03-27 ))))))))))))))))))))))))))))))
                            .

                            2008-03-20 18:58 . 2008-03-20 18:58 <DIR> d-------- C:\Program Files\Type Expert Junior
                            2008-03-19 17:04 . 2008-03-19 17:41 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
                            2008-03-19 17:04 . 2008-03-19 17:04 <DIR> d-------- C:\Documents and Settings\OEM\Application Data\SUPERAntiSpyware.com
                            2008-03-19 17:04 . 2008-03-19 17:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
                            2008-03-18 19:17 . 2008-03-18 19:17 <DIR> d-------- C:\Program Files\svcdplaza
                            2008-03-16 18:37 . 2008-03-27 16:32 <DIR> d-------- C:\Program Files\Spyware Doctor
                            2008-03-16 18:37 . 2008-03-16 18:37 <DIR> d-------- C:\Documents and Settings\OEM\Application Data\PC Tools
                            2008-03-16 18:37 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
                            2008-03-16 18:37 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
                            2008-03-16 18:37 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
                            2008-03-16 18:37 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
                            2008-03-15 13:59 . 2007-10-17 13:53 43,816 --a------ C:\WINDOWS\system32\drivers\fssfltr.sys
                            2008-03-15 13:55 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
                            2008-03-15 13:53 . 2008-03-15 13:53 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
                            2008-03-15 13:22 . 2008-03-17 19:39 <DIR> d-------- C:\Program Files\Windows Live
                            2008-03-15 13:22 . 2008-03-15 13:38 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
                            2008-03-15 13:22 . 2008-03-15 13:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
                            2008-03-15 12:24 . 2008-03-15 12:24 <DIR> d-------- C:\Program Files\InfinitySW
                            2008-03-15 12:19 . 2008-03-15 12:22 <DIR> d-------- C:\Program Files\Handmark
                            2008-03-13 18:03 . 2008-03-14 10:48 <DIR> d-------- C:\Program Files\Registry Defender
                            2008-03-01 13:17 . 2008-03-01 13:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\My Games
                            2008-03-01 06:46 . 2008-03-04 21:16 <DIR> d-------- C:\Program Files\VirtualDJ
                            2008-02-29 14:57 . 2008-02-29 14:57 <DIR> d-------- C:\Documents and Settings\OEM\.GalleryRemote
                            2008-02-27 18:12 . 2008-02-27 18:19 <DIR> d-------- C:\Documents and Settings\OEM\Application Data\PowerChallenge

                            .
                            ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
                            .
                            2008-03-27 18:16 17,408 ----a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS
                            2008-03-27 15:33 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
                            2008-03-25 18:42 --------- d-----w C:\Documents and Settings\OEM\Application Data\Ahead
                            2008-03-25 03:44 --------- d-----w C:\Program Files\eMule
                            2008-03-19 15:59 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
                            2008-03-19 15:59 --------- d-----w C:\Program Files\Common Files\Real
                            2008-03-17 18:35 --------- d-----w C:\Program Files\Realspace3_at
                            2008-03-17 18:24 --------- d-----w C:\Program Files\LimewirePlus
                            2008-03-17 18:22 --------- d-----w C:\Program Files\Zylom Games
                            2008-03-16 09:14 --------- d-----w C:\Program Files\Palm
                            2008-03-16 07:22 --------- d-----w C:\Documents and Settings\OEM\Application Data\LimeWirePlus
                            2008-03-15 13:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
                            2008-03-15 11:25 --------- d-----w C:\Program Files\Kinoma
                            2008-03-15 11:16 --------- d-----w C:\Program Files\Documents To Go
                            2008-03-07 16:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
                            2008-03-02 09:54 --------- d-----w C:\Documents and Settings\OEM\Application Data\Zylom
                            2008-02-27 19:44 --------- d-----w C:\Program Files\Common Files\Adobe
                            2008-02-23 06:28 --------- d-----w C:\Program Files\iTunes
                            2008-02-23 06:27 --------- d-----w C:\Program Files\iPod
                            2008-02-23 06:22 --------- d-----w C:\Program Files\QuickTime
                            2008-02-22 19:41 --------- d-----w C:\Documents and Settings\OEM\Application Data\U3
                            2008-02-17 15:25 47,962 -c--a-w C:\Documents and Settings\OEM\Application Data\wklnhst.dat
                            2008-01-30 18:31 --------- d-----w C:\Program Files\Microsoft Silverlight
                            2008-01-30 17:54 --------- d-----w C:\Documents and Settings\OEM\Application Data\BSplayer
                            2007-03-27 10:37 79,432 -c--a-w C:\Documents and Settings\OEM\Application Data\GDIPFONTCACHEV1.DAT
                            2001-03-28 10:02 122,880 ----a-w C:\WINDOWS\inf\AGFA\message.exe
                            2003-01-13 09:12 278,528 ------w C:\Program Files\internet explorer\plugins\PanoViewer.dll
                            1999-04-30 14:00 98,304 ------w C:\Program Files\internet explorer\plugins\UPjpeg.dll
                            2004-10-08 08:54 8 -csh--r C:\WINDOWS\system32\E1D3DFE4A3.sys
                            2004-10-08 08:54 5,224 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
                            .

                            ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
                            .
                            .
                            REGEDIT4
                            *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

                            [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
                            2007-12-17 11:12 56360 --a------ C:\Program Files\Windows Live\Family Safety\fssbho.dll

                            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
                            "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
                            "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2006-06-06 10:07 40960]
                            "BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
                            "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 21:53 204288]
                            "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-11-06 20:00 8523776]
                            "nwiz"="nwiz.exe" [2007-11-06 20:00 1626112 C:\WINDOWS\system32\nwiz.exe]
                            "Snelkoppeling naar eigenschappenvenster voor High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 15:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
                            "Cmaudio"="cmicnfg.cpl"
                            "AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 15:00 88363 C:\WINDOWS\AGRSMMSG.exe]
                            "Dit"="Dit.exe" [2004-07-20 17:18 90112 C:\WINDOWS\Dit.exe]
                            "CHotkey"="mHotkey.exe" [2004-02-24 13:05 508416 C:\WINDOWS\mHotkey.exe]
                            "ledpointer"="CNYHKey.exe" [2004-02-03 16:15 5794816 C:\WINDOWS\CNYHKey.exe]
                            "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
                            "PCMService"="C:\Program Files\Home Cinema\PowerCinema\PCMService.exe" [2004-10-29 20:34 81920]
                            "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 22:42 176128]
                            "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
                            "SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2006-06-06 10:07 40960]
                            "avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-10 16:01 249896]
                            "Motive SmartBridge"="C:\PROGRA~1\TELENE~1\SMARTB~1\MotiveSB.exe" [ ]
                            "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-07-14 15:09 57344]
                            "Ulead AutoDetector"="C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-11-19 12:03 45056]
                            "mmtask"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2006-01-17 12:03 53248]
                            "SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
                            "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
                            "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
                            "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
                            "fssui"="C:\Program Files\Windows Live\Family Safety\fssui.exe" [2007-12-17 11:12 243240]

                            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                            "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]

                            C:\Documents and Settings\OEM\Menu Start\Programma's\Opstarten\
                            HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2003-10-14 10:54:12 299008]
                            PowerReg SchedulerV2.exe [2006-07-02 08:34:14 233472]

                            [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
                            "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
                            C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

                            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                            "%windir%\\system32\\sessmgr.exe"=
                            "%WinDir%\\system32\\fxsclnt.exe"=
                            "%ProgramFiles%\\CA\\eTrust Antivirus\\InocIT.exe"=
                            "%ProgramFiles%\\CA\\eTrust Antivirus\\Realmon.exe"=
                            "%ProgramFiles%\\CA\\eTrust Antivirus\\InoRpc.exe"=
                            "%ProgramFiles%\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
                            "C:\\Program Files\\Messenger\\msmsgs.exe"=
                            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                            "C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
                            "C:\\Program Files\\LimeWire Plus\\LimeWire.exe"=
                            "C:\\Program Files\\eMule\\emule.exe"=
                            "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                            "C:\\Program Files\\iTunes\\iTunes.exe"=
                            "C:\\Program Files\\Palm\\HOTSYNC.EXE"=
                            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                            "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

                            R2 fssfltr;FssFltr;C:\WINDOWS\system32\DRIVERS\fssfltr.sys [2007-10-17 13:53]
                            R2 fsssvc;Windows Live OneCare Family Safety;"C:\Program Files\Windows Live\Family Safety\fsssvc.exe" [2007-12-17 11:13]
                            R2 LogWatch;Event Log Watch;"C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe" [2002-09-19 19:29]
                            R3 Cap7134;MEDION (7134) WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2003-06-05 09:04]
                            R3 cmudax;C-Media High Definition Audio Interface;C:\WINDOWS\system32\drivers\cmudax.sys [2005-05-12 13:39]
                            R3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2003-06-12 09:47]
                            R3 wbscr;Winbond Smartcard Reader for I/O;C:\WINDOWS\system32\drivers\wbscr.sys [2002-04-24 11:07]
                            S3 CA_LIC_CLNT;CA License Client;"C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe" [2002-09-19 19:27]
                            S3 CA_LIC_SRVR;CA License Server;"C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe" [2002-09-19 19:41]
                            S3 CardReaderFilter;Card Reader Filter;C:\WINDOWS\system32\Drivers\USBCRFT.SYS [2008-03-27 19:16]
                            S3 UKBFLT;UKBFLT;C:\WINDOWS\system32\DRIVERS\UKBFLT.sys [2003-12-19 16:13]

                            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
                            \Shell\AutoRun\command - H:\LaunchU3.exe -a

                            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2b6701e5-9534-11dc-a99a-00110957644c}]
                            \Shell\AutoRun\command - J:\LaunchU3.exe -a

                            .
                            Inhoud van de 'Gedeelde Taken' map
                            "2007-12-31 08:06:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
                            - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
                            "2008-03-27 18:12:04 C:\WINDOWS\Tasks\Controleren op updates voor Windows Live Toolbar.job"
                            - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
                            .
                            **************************************************************************

                            catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                            Rootkit scan 2008-03-27 19:15:53
                            Windows 5.1.2600 Service Pack 2 NTFS

                            scannen van verborgen processen ...

                            scannen van verborgen autostart items ...

                            scannen van verborgen bestanden ...

                            Scan succesvol afgerond
                            verborgen bestanden: 0

                            **************************************************************************

                            [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
                            "ImagePath"=""
                            .
                            ------------------------ Other Running Processes ------------------------
                            .
                            C:\Program Files\Sygate\SPF\smc.exe
                            C:\WINDOWS\System32\SCardSvr.exe
                            C:\WINDOWS\system32\agrsmsvc.exe
                            C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                            C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
                            C:\Program Files\Bonjour\mDNSResponder.exe
                            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                            C:\WINDOWS\system32\nvsvc32.exe
                            C:\Program Files\Windows Media Player\WMPNetwk.exe
                            C:\WINDOWS\system32\RunDll32.exe
                            C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            .
                            **************************************************************************
                            .
                            Voltooingstijd: 2008-03-27 19:20:17 - machine was rebooted
                            ComboFix-quarantined-files.txt 2008-03-27 18:20:12
                            ComboFix2.txt 2008-03-27 15:47:26
                            Pre-Run: 94,744,838,144 bytes beschikbaar
                            Post-Run: 94,728,339,456 bytes beschikbaar
                            .
                            2008-03-20 04:57:39 --- E O F ---


                            Gaat al wel beter.

                            Comment


                            • #15
                              Ziet er weer goed uit.

                              * Clean de Cache and Cookies in IE:

                              * Sluit Internet Explorer.
                              * Ga naar Configuratiescherm > Internet Opties > tab Algemeen
                              * Klik de Cookies verwijderen knop
                              * Klik op de Bestanden verwijderen knop ernaast
                              * Vink aan: Ook alle off line items verwijderen, klik OK

                              * Clean de Cache and Cookies in Firefox (In geval Firefox geïnstalleerd is):

                              * Go to Extra > Opties.
                              * Klik Privacy in het menu.
                              * Klik op de knop wissen (Geschiedenis, Cookies, Cache).
                              * Klik OK om het venster opnieuw te sluiten.

                              * Clean andere Temporary files + Prullenbak

                              * Ga naar Start > Uitvoeren en typ: cleanmgr en klik ok.
                              * Laat het je systeem scannen op bestanden die moeten verwijderd worden
                              * Zorg er wel voor dat je daar enkel maar 'tijdelijke bestanden', 'tijdelijke internetbestanden' en 'prullenbak' staan aangevinkt.
                              * Klik daarna op OK.


                              Nog problemen?
                              Groet,
                              Pimmerd

                              Comment

                              Sorry, you are not authorized to view this page
                              Working...
                              X