Mededeling

Collapse
No announcement yet.

Computer sluit weer vanzelf af

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Computer sluit weer vanzelf af

    Twee weken terug sloot de computer steeds vanzelf af en dat is met behulp van jullie toen verholpen. Helaas is het probleem gister weer teruggekomen. Omdat ik er zelf heel weinig verstand van heb vraag ik toch weer om jullie hulp. gr. Monique

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:32:54, on 2-4-2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\savedump.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\Program Files\VIAudioi\SBADeck\ADeck.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\SPAMfighter\SFAgent.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\MSGTAG\MSGTAG.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\SPAMfighter\sfus.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
    C:\WINDOWS\system32\UAService7.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.nl/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 ME\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [MSGTAG] "C:\Program Files\MSGTAG\MSGTAG.exe" /startup
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [HyvesKwekker] "C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe"
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
    O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/NL/install.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://marceluchtballon.spaces.live.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {5D2CF9D0-113A-476B-986F-288B54571614} (DevalVR Control) - http://www.devalvr.com/instalacion/plugin/devalocx.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {6211AC26-A1B4-422A-AC52-1E70B7D24465} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/nl/filesharingctrl.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1135083412274
    O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://fotoboeken.spaces.live.com/PhotoUpload/MsnPUpld.cab
    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://camaras.costablanca.org/AxisCamControl.cab
    O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://80.73.129.185/fotoxs/ImageUploader3.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://game18.zylomgames.com/activex/zylomloader.cab
    O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://82.92.48.123/activex/AMC.cab
    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.hema.nl/site/xupload/XUpload.ocx
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Autodata Limited License Service - Unknown owner - C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: NBService - Nero AG - D:\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
    O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

    --
    End of file - 8929 bytes

  • #2
    Logje laat geen sporen van infecties zien.

    Download Combofix eens en maak daar een logje mee, post dat in je volgende bericht.

    Comment


    • #3
      Oorspronkelijk geplaatst door rrmmss
      Hallo, door omstandigheden heb ik een tijd niet gereageerd op "computer sluit steeds vanzelf af". We hebben echter nog steeds grote problemen met de computer, vooral wat internet betreft. We krijgen de ene foutmelding na de ander. Daarom wil ik vragen of jullie mijn vraag kunnen heropenen zodat er nog eens naar gekeken kan worden. Met vriendelijke groet Monique
      Topic bij deze heropend

      Comment


      • #4
        Dank je wel

        Hierbij nogmaals een log, hoop dat je ons helpen kan.

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:22:12, on 28-4-2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16640)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\VTTimer.exe
        C:\Program Files\VIAudioi\SBADeck\ADeck.exe
        C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
        C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\SPAMfighter\SFAgent.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\Program Files\MSGTAG\MSGTAG.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe
        C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
        C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
        C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\Program Files\SPAMfighter\sfus.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\UAService7.exe
        C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
        C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Outlook Express\msimn.exe
        C:\Program Files\internet explorer\iexplore.exe
        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.buienradar.nl/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: (no name) - - (no file)
        O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
        O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
        O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKCU\..\Run: [MSGTAG] "C:\Program Files\MSGTAG\MSGTAG.exe" /startup
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [HyvesKwekker] "C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe"
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
        O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Lokale service')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
        O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
        O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/NL/install.cab
        O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
        O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://marceluchtballon.spaces.live.com//PhotoUpload/MsnPUpld.cab
        O16 - DPF: {5D2CF9D0-113A-476B-986F-288B54571614} (DevalVR Control) - http://www.devalvr.com/instalacion/plugin/devalocx.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
        O16 - DPF: {6211AC26-A1B4-422A-AC52-1E70B7D24465} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/nl/filesharingctrl.cab
        O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1135083412274
        O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://fotoboeken.spaces.live.com/PhotoUpload/MsnPUpld.cab
        O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://camaras.costablanca.org/AxisCamControl.cab
        O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://80.73.129.185/fotoxs/ImageUploader3.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
        O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://game18.zylomgames.com/activex/zylomloader.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://82.92.48.123/activex/AMC.cab
        O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.hema.nl/site/xupload/XUpload.ocx
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: Autodata Limited License Service - Unknown owner - C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: NBService - Nero AG - D:\Nero 7\Nero BackItUp\NBService.exe
        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
        O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

        --
        End of file - 9826 bytes

        Comment


        • #5
          Dit staat nog open
          Oorspronkelijk geplaatst door smeenk Bekijk Berichten
          Logje laat geen sporen van infecties zien.

          Download Combofix eens en maak daar een logje mee, post dat in je volgende bericht.

          Comment


          • #6
            ComboFix 08-04-26.3 - Monique 2008-04-28 19:09:59.4 - FAT32x86
            Microsoft Windows XP Professional 5.1.2600.2.1252.1.1043.18.84 [GMT 2:00]
            Gestart vanuit: C:\Documents and Settings\Monique\Bureaublad\ComboFix.exe

            WAARSCHUWING - DE RECOVERY CONSOLE IS NIET OP DIT SYSTEEM GEINSTALLEERD !!
            .

            (((((((((((((((((((( Bestanden Gemaakt van 2008-03-28 to 2008-04-28 ))))))))))))))))))))))))))))))
            .

            2008-04-27 18:39 . 2007-11-13 17:41 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
            2008-04-27 17:32 . 2008-04-27 17:32 <DIR> d-------- C:\Program Files\Lavasoft
            2008-04-27 17:32 . 2008-04-27 17:32 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
            2008-04-20 10:42 . 2008-03-01 15:05 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
            2008-04-20 10:42 . 2007-07-01 05:31 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
            2008-04-20 10:42 . 2007-07-01 05:36 1,032,192 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
            2008-04-20 10:42 . 2008-03-01 15:05 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
            2008-04-20 10:42 . 2008-03-01 15:05 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
            2008-04-20 10:42 . 2008-03-01 15:05 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
            2008-04-20 10:42 . 2008-03-01 15:05 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
            2008-04-20 10:42 . 2008-03-01 15:05 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
            2008-04-20 10:42 . 2008-02-22 12:00 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
            2008-04-20 10:41 . 2008-04-20 10:41 <DIR> d-------- C:\WINDOWS\system32\nl-nl
            2008-04-19 11:43 . 2008-04-24 19:26 54,156 --ah----- C:\WINDOWS\QTFont.qfn
            2008-04-19 11:43 . 2008-04-19 11:43 1,409 --a------ C:\WINDOWS\QTFont.for
            2008-04-02 15:25 . 2008-04-02 15:25 <DIR> d-------- C:\Program Files\SpeedFan
            2008-04-02 15:25 . 2008-04-02 15:25 45 --a------ C:\WINDOWS\system32\initdebug.nfo
            2008-04-01 11:20 . 2008-04-01 11:20 <DIR> d-------- C:\Program Files\Hyves Kwekker

            .
            ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2008-03-24 09:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hema Album Software Advanced
            2008-03-23 21:36 --------- d-----w C:\Program Files\ALDI
            2008-03-23 07:48 --------- d-----w C:\Program Files\Common Files\Download Manager
            2008-03-23 07:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
            2008-03-21 20:56 --------- d-----w C:\Program Files\Trend Micro
            2008-03-20 08:10 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
            2008-03-20 08:10 1,845,376 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
            2008-03-11 17:29 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller
            2008-03-11 17:28 --------- d-----w C:\Program Files\Windows Live
            2008-03-11 17:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
            2008-03-11 13:53 --------- d-----w C:\Program Files\Common Files\Symantec Shared
            2008-03-11 13:08 --------- d-----w C:\Program Files\SlySoft
            2008-03-10 14:55 --------- d-----w C:\Program Files\Common Files\Ahead
            2008-03-10 14:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
            2008-03-01 16:35 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
            2008-02-29 08:58 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
            2008-02-29 08:58 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
            2008-02-20 06:52 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
            2008-02-20 06:52 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
            2008-02-20 05:39 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
            2008-02-20 05:39 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
            2008-02-20 05:39 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
            2008-02-16 09:05 474,624 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
            2008-02-16 09:05 151,552 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
            2008-02-16 09:05 1,494,528 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
            2008-02-16 09:05 1,057,280 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
            2008-02-16 09:05 1,023,488 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
            2008-02-15 05:44 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
            2004-12-27 07:05 8,058 ----a-w C:\Program Files\CurrentCfg.tpr
            2003-09-16 11:14 936 ----a-w C:\Program Files\Readme.big5.txt
            2003-09-16 11:14 933 ----a-w C:\Program Files\Readme.gb.txt
            2003-09-16 11:14 147,543 ----a-w C:\Program Files\P4Package.dll
            2003-09-16 11:14 135,255 ----a-w C:\Program Files\P3Package.dll
            2003-09-16 11:14 1,363 ----a-w C:\Program Files\License.big5.txt
            2003-09-16 11:14 1,341 ----a-w C:\Program Files\Readme.fr.txt
            2003-09-16 11:14 1,238 ----a-w C:\Program Files\Readme.ja.txt
            2003-09-16 11:14 1,203 ----a-w C:\Program Files\Readme.en.txt
            1997-12-03 11:01 71,680 ----a-w C:\Program Files\SMACKW32.DLL
            1995-03-20 10:56 127,997 ----a-w C:\Program Files\WING.Z
            .

            ((((((((((((((((((((((((((((( [email protected]_16.57.49.69 )))))))))))))))))))))))))))))))))))))))))
            .
            - 2008-04-27 14:55:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
            + 2008-04-28 16:53:56 2,048 --s-a-w C:\WINDOWS\bootstat.dat
            - 2007-11-04 08:02:44 1,038,336 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe
            + 2008-04-27 15:33:10 1,038,336 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe
            - 2007-11-04 08:02:44 178,688 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe
            + 2008-04-27 15:33:10 178,688 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe
            - 2007-11-04 08:02:44 171,008 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe
            + 2008-04-27 15:33:10 171,008 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe
            - 2007-11-04 08:02:44 8,704 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe
            + 2008-04-27 15:33:10 8,704 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe
            - 2008-03-10 12:25:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
            + 2007-12-14 10:32:52 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
            .
            ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            REGEDIT4
            *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "MSGTAG"="C:\Program Files\MSGTAG\MSGTAG.exe" [2003-06-06 12:48 1311744]
            "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
            "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
            "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:03 15360]
            "HyvesKwekker"="C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe" [2007-04-06 11:12 1588736]
            "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 19:03 152872]
            "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "VTTimer"="VTTimer.exe" [2004-03-26 07:07 49152 C:\WINDOWS\system32\VTTimer.exe]
            "AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2004-05-24 08:18 7912448]
            "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
            "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-18 08:07 579584]
            "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
            "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-04-25 14:27 155648]
            "SPAMfighter Agent"="C:\Program Files\SPAMfighter\SFAgent.exe" [2007-10-25 15:29 308880]
            "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
            "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
            "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:03 15360]
            "AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-23 08:08 219136]

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
            SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Device Detection]

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"=
            "C:\\Program Files\\Messenger\\MSMSGS.EXE"=
            "C:\\Program Files\\MSGTAG\\MSGTAG.exe"=
            "C:\\Program Files\\MP3Downloading\\bindata.exe"=
            "D:\\DVD\\emule\\emule.exe"=
            "C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
            "C:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
            "C:\\WINDOWS\\System32\\java.exe"=
            "C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
            "C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
            "C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
            "C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
            "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

            R2 SPAMfighter Update Service;SPAMfighter Update Service;"C:\Program Files\SPAMfighter\sfus.exe" [2007-10-25 15:29]
            S3 Camdrv30;Philips ToUcam XS;C:\WINDOWS\system32\Drivers\camdrv30.sys [2001-08-17 22:04]
            S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-24 09:40]

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
            \Shell\AutoRun\command - E:\SETUP.EXE -autorun

            *Newly Created Service* - CATCHME
            .
            **************************************************************************

            catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2008-04-28 19:11:33
            Windows 5.1.2600 Service Pack 2 FAT NTAPI

            scannen van verborgen processen ...

            scannen van verborgen autostart items ...

            scannen van verborgen bestanden ...

            Scan succesvol afgerond
            verborgen bestanden: 0

            **************************************************************************
            .
            Voltooingstijd: 2008-04-28 19:12:09
            ComboFix-quarantined-files.txt 2008-04-28 17:12:06
            ComboFix2.txt 2008-04-27 14:58:16

            Pre-Run: 5,991,383,040 bytes beschikbaar
            Post-Run: 6,054,232,064 bytes beschikbaar

            152 --- E O F --- 2008-04-27 20:52:44

            Comment


            • #7
              Ik zie helaas geen verkeerde dingen.

              Download Dial-a-fix-2006 en pak beide bestanden in hun eigen map uit naar je Bureaublad.
              • In de map Dial-a-fix-v0.60.0.24, dubbelklik op Dial-a-fix.exe
                In het venster dat opengaat, klik onderaan op het icoontje met het dubbele groene vinkje (check all).
                Klik daarna op "GO" en laat de tool alle instellingen terugzetten.
                Sluit dit venster na afloop door onderaan op "Exit" te klikken.
              Vertel of dat verbetering geeft

              Comment


              • #8
                Heb ik gedaan en een tijdje op internet rondgekeken.
                Heb een paar keer foutmelding gehad: in Internet Explorer is een fout opgetreden en moet worden afgesloten/in Generic Host Process for Win32 services is een fout opgetreden en meot worden afgesloten/In msimn.exe is een fout opgetreden en moet worden afgesloten. Als ik in de mail een link aanklik (mailtje van jullie) slaat ook alles af.

                Comment


                • #9
                  Draai Dial-a-fix eens in veilige modus.

                  Probeer ook deze tool eens.

                  Comment


                  • #10
                    hallo, heb beide gedaan, helpt ook niet. Kan het zijn dat onze computer aan zijn eind is? groetjes Monique

                    Comment


                    • #11
                      Zou kunnen, logjes kunnen niet alles vertellen.

                      Check je HD op fouten.
                      • Open Windows explorer
                      • Rechtsklik de C-schijf (of andere disk die je wilt scannen)
                      • Kies > eigenschappen > tabblad extra
                      • Kies het volume op fouten controleren
                      • Vink aan “Fouten in bestandssysteem automatisch corrigeren” en “Beschadigde sectoren zoeken en repareren”
                        Het systeem zal om een herstart vragen
                      • Sluit alle programma’s en herstart de computer
                      • Onderbreek de schijfcontrole na herstart niet.
                      Defragmenteer daarna je harde schijf eens.

                      Meldt of dat verbetering geeft

                      Comment

                      Sorry, you are not authorized to view this page
                      Working...
                      X