Mededeling

Collapse
No announcement yet.

Ik krijg reclame als ik internet opstart

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Ik krijg reclame als ik internet opstart

    Heey, als ik het internet opstart krijg ik allemaal reclame, voornamelijk van CiD. Wat moet ik hier aan doen?
    mvg Miekdemikmak
    btw: ik snap die logjes die iedereen post niet echt... met die heel veel codes enzo..

  • #2
    k krijg steeds reclame als ik internet opstart

    Voornamelijk CiD reclame.

    Dit is het log:

    Adobe Flash Player ActiveX
    Adobe Reader 8.1.2
    Adobe Reader 8.1.2 - Nederlands
    Adobe Shockwave Player
    Adobe® Photoshop® Album Starter Edition 3.2
    AppCore
    Apple Software Update
    ASUS WiFi-AP Solo
    Attansic Giga Ethernet Utility
    Attansic L1 Gigabit Ethernet Driver
    AV
    BrowsingTool
    ccCommon
    Colin McRae Rally 3
    Corel Paint Shop Pro Photo X2
    FBrowsingAdvisor
    Finale NotePad 2008
    FotoSketcher 1.4
    GameSpy Arcade
    GearDrvs
    Google Toolbar for Internet Explorer
    Google Toolbar for Internet Explorer
    High Definition Audio Driver Package - KB888111
    HijackThis 2.0.2
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB914440)
    Hotfix for Windows XP (KB915865)
    Hotfix for Windows XP (KB926239)
    Hotfix for Windows XP (KB935448)
    LimeWire Plus 1.7
    Linksys Wireless-G PCI Adapter
    LiveUpdate 3.2 (Symantec Corporation)
    LiveUpdate Notice (Symantec Corporation)
    Media Converter for Philips
    Messenger Plus! Live & Sponsor (CiD)
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Access MUI (Dutch) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (Dutch) 2007
    Microsoft Office Groove MUI (Dutch) 2007
    Microsoft Office InfoPath MUI (Dutch) 2007
    Microsoft Office OneNote MUI (Dutch) 2007
    Microsoft Office Outlook MUI (Dutch) 2007
    Microsoft Office PowerPoint MUI (Dutch) 2007
    Microsoft Office Proof (Dutch) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (German) 2007
    Microsoft Office Proofing (Dutch) 2007
    Microsoft Office Publisher MUI (Dutch) 2007
    Microsoft Office Shared MUI (Dutch) 2007
    Microsoft Office Word MUI (Dutch) 2007
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    MSN
    MSXML 4.0 SP2 (KB936181)
    Nero 7 Essentials
    NIO
    Norton 360
    Norton 360
    Norton 360
    Norton 360 (Symantec Corporation)
    Norton 360 Help
    Norton Confidential Browser Component
    Norton Confidential Web Authentification Component
    Norton Confidential Web Protection Component
    NVIDIA Drivers
    Philips Device Manager
    PlayMP3z
    QuickTime
    Race Driver 3
    RCT3 Soaked
    Realtek High Definition Audio Driver
    RollerCoaster Tycoon 3
    Security Update for Excel 2007 (KB946974)
    Security Update for Office 2007 (KB947801)
    Security Update for Outlook 2007 (KB946983)
    Security Update for Visio 2007 (KB947590)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB937894)
    Security Update for Windows XP (KB938127)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB941202)
    Security Update for Windows XP (KB941568)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB941644)
    Security Update for Windows XP (KB941693)
    Security Update for Windows XP (KB942615)
    Security Update for Windows XP (KB943055)
    Security Update for Windows XP (KB943460)
    Security Update for Windows XP (KB943485)
    Security Update for Windows XP (KB944653)
    Security Update for Windows XP (KB945553)
    Security Update for Windows XP (KB946026)
    Security Update for Windows XP (KB948590)
    Security Update for Windows XP (KB948881)
    SPBBC 32bit
    SuppSoft
    Symantec Technical Support Controls
    SymNet
    Teach2000 8.21
    The Sims Deluxe
    Update for Office 2007 (KB946691)
    Update for Outlook 2007 Junk Email Filter (kb949037)
    Update for Windows XP (KB894391)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB904942)
    Update for Windows XP (KB908531)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB911280)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB936357)
    Update for Windows XP (KB938828)
    Update for Windows XP (KB942763)
    Windows Installer 3.1 (KB893803)
    Windows Internet Explorer 7
    Windows Live installer
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Media Format 11 runtime
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Media Player 11
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781

    --------------------------------------------------------
    No LOP job-files found
    --------------------------------------------------------
    Files in Windows Tasks folder

    AppleSoftwareUpdate.job
    --------------------------------------------------------
    Export App Data folders
    --------------------------------------------------------
    Volume in drive C has no label.
    Volume Serial Number is 385A-31EF

    Directory of C:\Documents and Settings\Elsemiek\Application Data

    04/05/2008 08:04 PM <DIR> .
    04/05/2008 08:04 PM <DIR> ..
    01/21/2008 07:03 PM <DIR> Adobe
    04/05/2008 08:04 PM <DIR> APPLEC~1 Apple Computer
    01/17/2008 04:58 PM <DIR> Atari
    04/03/2008 05:54 PM <DIR> Basement
    01/23/2008 05:58 PM <DIR> Corel
    02/12/2008 03:34 PM <DIR> Google
    01/17/2008 03:30 PM <DIR> IDENTI~1 Identities
    01/17/2008 04:46 PM <DIR> INSTAL~1 InstallShield
    03/09/2008 08:38 PM <DIR> LEADER~1 Leadertech
    04/16/2008 02:50 PM <DIR> LIMEWI~1 LimeWirePlus
    02/02/2008 07:35 PM <DIR> MACROM~1 Macromedia
    04/15/2008 07:19 PM <DIR> MICROS~1 Microsoft
    04/01/2008 06:56 PM <DIR> PLAYMOVE
    02/10/2008 06:15 PM <DIR> Sun
    01/22/2008 05:14 PM <DIR> Symantec
    0 File(s) 0 bytes
    17 Dir(s) 291,812,913,152 bytes free
    Volume in drive C has no label.
    Volume Serial Number is 385A-31EF

    Directory of C:\Documents and Settings\All Users\Application Data

    04/19/2008 10:21 AM <DIR> .
    04/19/2008 10:21 AM <DIR> ..
    01/21/2008 06:25 PM <DIR> Adobe
    03/11/2008 06:58 PM <DIR> Apple
    01/23/2008 05:57 PM <DIR> Corel
    02/02/2008 03:33 PM <DIR> Google
    01/22/2008 04:42 PM <DIR> MESSEN~1 Messenger Plus!
    01/23/2008 05:37 PM <DIR> MICROS~1 Microsoft
    04/09/2008 01:04 PM <DIR> MICROS~2 Microsoft Help
    01/16/2008 01:23 PM <DIR> Nero
    04/19/2008 10:55 AM <DIR> Symantec
    0 File(s) 0 bytes
    11 Dir(s) 291,812,913,152 bytes free
    --------------------------------------------------------
    All User Accounts
    --------------------------------------------------------
    Administrator
    All Users
    Carlijn
    Elsemiek
    Frank
    Maddie
    --------------------------------------------------------

    Comment


    • #3
      Download: RVAXO.exe
      • Sla het bestand op je bureaublad op, dubbelklik het en kies voor "Unzip" om het uit te pakken.
      • Start de computer in veilige modus.
      • Open nu de map RVAXO op je bureaublad en dubbeklik RunMe.cmd
        Er zal een cmd-schermpje openen, daarin zullen snel enkele regels over niet gevonden bestanden voorbijkomen, dit is normaal.
      • Mogelijk start er ook een uninstaller van een rogue scanner op, sluit deze niet af maar volg eventuele aanwijzingen en laat deze gewoon zijn werk doen.
      • Daarna zal je PC herstarten, laat hem nu weer in normale modus starten. Na de herstart opent het cmd-venster van RVAXO opnieuw.
        Laat deze lopen en wacht tot er een logfile opent: C:\RVAXO-results.log
      • Herstart je computer niet vanzelf, of start de tool niet na de reboot, doe dit dan handmatig.
      • Post de inhoud van de logfile in je volgende bericht.


      Download Deckard's System Scanner naar je Bureaublad.
      • Sluit alle toepassingen en vensters.
      • Dubbelklik op dss.exe om het te activeren, en volg de aanwijzingen.
      • Wanneer de scan volledig is, zal een tekstbestand - main.txt - openen.
      • Kopieer (Ctrl+A gevolgd door Ctrl+C) en plak (Ctrl+V) de inhoud van main.txt in je volgende antwoord evenals extra.txt.

      Opmerking: Sommige firewalls kunnen waarschuwen dat sigcheck.exe probeert verbinding te maken met het internet
      - zorg dat sigcheck.exe toestemming krijgt om dit te doen !
      Tevens kan het gebeuren dat je Antivirus DSS als verdacht aangeeft, of zelfs probeert te verwijderen.
      Laat je Antivirus dit niet verwijderen ! (In dit geval is het misschien beter om tijdens de scan van DSS je Antivirus even uit te schakelen)

      Comment


      • #4
        Dit stond er in het bestand toen ik het in de normale modus opende:
        ---RVAXO.exe Updated: 2008-04-20---first run---
        Uninstallers:

        Files found:
        C:\WINDOWS\system32\_000013_.tmp.dll
        C:\regxpcom.exe

        Folders Found:
        C:\Program Files\PlayMP3z
        C:\Program Files\FBrowsingAdvisor
        C:\Program Files\BrowsingTool
        C:\Program Files\FBrowserAdvisor

        Hosts-file was reset, If you use a custom hosts file please replace it...

        --------------RVAXO.exe last run---------------
        Not deleted items:

        --------------RVAXO.exe finished----------------

        Comment


        • #5
          Oorspronkelijk geplaatst door smeenk Bekijk Berichten
          Download Deckard's System Scanner naar je Bureaublad.
          • Sluit alle toepassingen en vensters.
          • Dubbelklik op dss.exe om het te activeren, en volg de aanwijzingen.
          • Wanneer de scan volledig is, zal een tekstbestand - main.txt - openen.
          • Kopieer (Ctrl+A gevolgd door Ctrl+C) en plak (Ctrl+V) de inhoud van main.txt in je volgende antwoord evenals extra.txt.

          Opmerking: Sommige firewalls kunnen waarschuwen dat sigcheck.exe probeert verbinding te maken met het internet
          - zorg dat sigcheck.exe toestemming krijgt om dit te doen !
          Tevens kan het gebeuren dat je Antivirus DSS als verdacht aangeeft, of zelfs probeert te verwijderen.
          Laat je Antivirus dit niet verwijderen ! (In dit geval is het misschien beter om tijdens de scan van DSS je Antivirus even uit te schakelen)

          Comment


          • #6
            Ok.. dit is wat ik heb van die dss:

            Deckard's System Scanner v20071014.68
            Run by Elsemiek on 2008-04-20 19:28:46
            Computer is in Normal Mode.
            --------------------------------------------------------------------------------

            -- System Restore --------------------------------------------------------------

            Successfully created a Deckard's System Scanner Restore Point.


            -- Last 5 Restore Point(s) --
            83: 2008-04-20 17:28:52 UTC - RP166 - Deckard's System Scanner Restore Point
            82: 2008-04-19 08:31:40 UTC - RP165 - Removed Java(TM) 6 Update 5
            81: 2008-04-19 08:27:20 UTC - RP164 - Removed Java(TM) 6 Update 3
            80: 2008-04-19 08:26:49 UTC - RP163 - Removed J2SE Runtime Environment 5.0 Update 3
            79: 2008-04-18 18:59:48 UTC - RP162 - System Checkpoint


            -- First Restore Point --
            1: 2008-01-20 18:09:54 UTC - RP84 - Unsigned driver install


            Backed up registry hives.
            Performed disk cleanup.



            -- HijackThis (run as Elsemiek.exe) --------------------------------------------

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 7:29:28 PM, on 4/20/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16640)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\PSIService.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\UAService7.exe
            C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
            C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
            C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
            C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
            C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
            C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\ASUS WiFi-AP Solo\AWWFSPU.exe
            C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
            C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
            C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
            C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            C:\Documents and Settings\Elsemiek\Desktop\dss.exe
            C:\PROGRA~1\TRENDM~1\HIJACK~1\Elsemiek.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
            O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
            O3 - Toolbar: Visa Norton-verktygsfältet - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
            O4 - HKLM\..\Run: [PhilipsDM] C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe OS_STARTUP
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [AWWFSPU] "C:\Program Files\ASUS WiFi-AP Solo\AWWFSPU.exe" -nogui
            O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
            O4 - HKUS\S-1-5-21-484763869-1659004503-725345543-1005\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User 'Frank')
            O4 - HKUS\S-1-5-21-484763869-1659004503-725345543-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Frank')
            O4 - HKUS\S-1-5-21-484763869-1659004503-725345543-1005\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User 'Frank')
            O4 - HKUS\S-1-5-21-484763869-1659004503-725345543-1006\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User 'Maddie')
            O4 - HKUS\S-1-5-21-484763869-1659004503-725345543-500\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User 'Administrator')
            O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
            O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
            O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
            O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/NL-NL/a-UNO1/GAME_UNO1.cab
            O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://partyflock.nl/components/ImageUploader4.cab
            O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} (Navigram Control) - http://www.navigram.com/engine/v911/Navigram.cab
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
            O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
            O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
            O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

            --
            End of file - 11028 bytes

            -- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

            backup-20080419-105228-519 O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
            backup-20080419-105228-539 O4 - HKCU\..\Run: [download find] C:\DOCUME~1\Elsemiek\APPLIC~1\PLAYMOVE\Debug Flaw.exe
            backup-20080419-105228-725 O4 - HKLM\..\Run: [dog about manager team] C:\Documents and Settings\All Users\Application Data\Drv Audio Dog About\bold kind.exe
            backup-20080419-105228-740 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            backup-20080419-105228-823 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/

            -- File Associations -----------------------------------------------------------

            All associations okay.


            -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

            R3 AtcL001 (NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller) - c:\windows\system32\drivers\atl01_xp.sys <Not Verified; Attansic Technology corporation.; Attansic L1 Gigabit Ethernet Controller>
            R3 MTsensor (ATK0110 ACPI UTILITY) - c:\windows\system32\drivers\asacpi.sys <Not Verified; ; ATK0110 ACPI Utility>
            R3 WinDriver6 - c:\windows\system32\drivers\windrvr6.sys <Not Verified; Jungo; WinDriver Device Driver>

            S3 AR2425 (AzureWave AR5006 Wireless Network Adapter Service) - c:\windows\system32\drivers\aw5006.sys <Not Verified; AzureWave Technologies, Inc.; Atheros AR5001 Wireless Network Adapter>
            S3 RT61 (Linksys Wireless-G PCI Adapter Driver(RT61)) - c:\windows\system32\drivers\rt61.sys <Not Verified; Ralink Technology Inc.; Ralink 802.11 Wireless Adapters>


            -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

            R2 UserAccess7 (SecuROM User Access Service (V7)) - c:\windows\system32\uaservice7.exe
            R3 NMIndexingService - "c:\program files\common files\ahead\lib\nmindexingservice.exe" <Not Verified; Nero AG; Nero Home>


            -- Device Manager: Disabled ----------------------------------------------------

            Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
            Description: AR5006 Wireless Network Adapter
            Device ID: PCI\VEN_168C&DEV_001C&SUBSYS_10341A3B&REV_01\4&4C5E15F&0&00E2
            Manufacturer: AzureWave
            Name: AR5006 Wireless Network Adapter
            PNP Device ID: PCI\VEN_168C&DEV_001C&SUBSYS_10341A3B&REV_01\4&4C5E15F&0&00E2
            Service: AR2425

            Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
            Description: Linksys Wireless-G PCI Adapter
            Device ID: PCI\VEN_1814&DEV_0301&SUBSYS_00551737&REV_00\4&CF81C54&0&08F0
            Manufacturer: Linksys, A Division of Cisco Systems, Inc.
            Name: Linksys Wireless-G PCI Adapter
            PNP Device ID: PCI\VEN_1814&DEV_0301&SUBSYS_00551737&REV_00\4&CF81C54&0&08F0
            Service: RT61


            -- Scheduled Tasks -------------------------------------------------------------

            2008-04-19 11:11:00 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


            -- Files created between 2008-03-20 and 2008-04-20 -----------------------------

            2008-04-20 14:01:12 0 d-------- C:\RVAXO
            2008-04-20 13:59:02 797489 --a------ C:\WINDOWS\system32\RVAXO.bat
            2008-04-20 13:59:02 69632 --a------ C:\WINDOWS\system32\remove.exe
            2008-04-20 13:42:07 0 d-------- C:\WINDOWS\pss
            2008-04-19 13:35:23 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
            2008-04-19 10:46:51 0 d-------- C:\Program Files\Trend Micro
            2008-04-19 10:26:41 0 d-------- C:\Documents and Settings\All Users\Templates
            2008-04-09 17:49:31 0 d-------- C:\VISION
            2008-04-09 17:49:31 0 d-------- C:\Documents and Settings\Carlijn\WINDOWS
            2008-04-07 19:01:43 0 d-------- C:\Program Files\FotoSketcher 1.4
            2008-04-05 20:04:03 0 d-------- C:\Documents and Settings\Elsemiek\Application Data\Apple Computer
            2008-04-03 17:54:41 0 d-------- C:\Documents and Settings\Elsemiek\Application Data\Basement
            2008-04-02 08:58:43 0 d-------- C:\Documents and Settings\Maddie\Application Data\PLAYMOVE
            2008-04-01 17:55:29 0 d-------- C:\Program Files\PLAYMOVE
            2008-04-01 14:38:33 0 d-------- C:\Documents and Settings\Carlijn\Application Data\Apple Computer


            -- Find3M Report ---------------------------------------------------------------

            2008-04-20 19:29:21 0 d-------- C:\Program Files\Common Files\Symantec Shared
            2008-04-20 17:07:50 848 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
            2008-04-19 10:31:53 0 d-------- C:\Program Files\Java
            2008-04-16 14:50:00 0 d-------- C:\Documents and Settings\Elsemiek\Application Data\LimeWirePlus
            2008-04-01 17:55:18 0 d-------- C:\Program Files\Messenger Plus! Live
            2008-03-31 18:00:09 77528 --a------ C:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
            2008-03-16 11:22:55 0 d-------- C:\Program Files\QuickTime
            2008-03-16 11:21:07 0 d-------- C:\Program Files\IJsfontein
            2008-03-11 19:43:04 0 d-------- C:\Program Files\Common Files\Adobe
            2008-03-11 18:58:01 0 d-------- C:\Program Files\Apple Software Update
            2008-03-09 20:38:04 0 d-------- C:\Documents and Settings\Elsemiek\Application Data\Leadertech
            2008-03-09 15:54:31 126976 --a------ C:\WINDOWS\system32\UAService7.exe
            2008-03-09 15:54:17 0 d-------- C:\Program Files\NIO
            2008-02-29 12:53:40 0 d-------- C:\Program Files\Navigram
            2008-01-20 09:58:26 1015 --a------ C:\WINDOWS\eReg.dat


            -- Registry Dump ---------------------------------------------------------------

            *Note* empty entries & legit default entries are not shown


            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [01/29/2008 06:38 PM]
            "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [02/01/2008 12:13 AM]
            "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
            "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 01:47 AM]
            "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [03/22/2007 04:09 PM]
            "PhilipsDM"="C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe" [04/30/2007 05:50 PM]
            "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/09/2007 11:59 PM]
            "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [01/12/2006 04:40 PM]
            "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [12/05/2007 02:41 AM]
            "nwiz"="nwiz.exe" [12/05/2007 02:41 AM C:\WINDOWS\system32\nwiz.exe]
            "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [12/05/2007 02:41 AM]
            "SkyTel"="SkyTel.EXE" [04/04/2007 11:22 AM C:\WINDOWS\SkyTel.exe]
            "RTHDCPL"="RTHDCPL.EXE" [04/10/2007 09:28 AM C:\WINDOWS\RTHDCPL.exe]
            "AWWFSPU"="C:\Program Files\ASUS WiFi-AP Solo\AWWFSPU.exe" [12/18/2006 01:19 PM]
            "Corel Photo Downloader"="C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" [08/16/2007 01:00 PM]

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [04/16/2008 06:03 PM]
            "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [10/18/2007 12:34 PM]
            "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 02:00 PM]
            "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [12/23/2006 07:05 PM]

            C:\Documents and Settings\Elsemiek\Start Menu\Programs\Startup\
            OneNote 2007 Schermopname en Snel starten.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [10/26/2006 9:24:54 PM]

            *Newly Created Service* - COMHOST



            -- End of Deckard's System Scanner: finished at 2008-04-20 19:29:47 ------------


            En dit is van het extra.txt:

            Deckard's System Scanner v20071014.68
            Extra logfile - please post this as an attachment with your post.
            --------------------------------------------------------------------------------

            -- System Information ----------------------------------------------------------

            Microsoft Windows XP Professional (build 2600) SP 2.0
            Architecture: X86; Language: English

            CPU 0: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
            CPU 1: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
            CPU 2: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
            CPU 3: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
            Percentage of Memory in Use: 27%
            Physical Memory (total/avail): 2047.17 MiB / 1481.14 MiB
            Pagefile Memory (total/avail): 3940.12 MiB / 3508.08 MiB
            Virtual Memory (total/avail): 2047.88 MiB / 1935.17 MiB

            C: is Fixed (NTFS) - 298.08 GiB total, 271.93 GiB free.
            D: is CDROM (No Media)

            \\.\PHYSICALDRIVE0 - WDC WD3200AAKS-00YGA0 - 298.09 GiB - 1 partition
            \PARTITION0 (bootable) - Installable File System - 298.08 GiB - C:



            -- Security Center -------------------------------------------------------------

            AUOptions is scheduled to auto-install.
            Windows Internal Firewall is disabled.

            FirstRunDisabled is set.

            FW: Norton 360 v2007 (SYMANTEC Corporation)
            AV: Norton 360 v2007 (SYMANTEC Corperation)

            [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Authoriz edApplications\List]
            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabledxpsp2res.dll,-22019"
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabledxpsp3res.dll,-20000"
            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
            "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

            [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Author izedApplications\List]
            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabledxpsp2res.dll,-22019"
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabledxpsp3res.dll,-20000"
            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
            "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
            "C:\\Program Files\\LimeWire Plus\\LimeWire.exe"="C:\\Program Files\\LimeWire Plus\\LimeWire.exe:*:Enabled:LimeWire"
            "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
            "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
            "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"


            -- Environment Variables -------------------------------------------------------

            ALLUSERSPROFILE=C:\Documents and Settings\All Users
            APPDATA=C:\Documents and Settings\Elsemiek\Application Data
            CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
            CommonProgramFiles=C:\Program Files\Common Files
            COMPUTERNAME=F-1C13F02528A14
            ComSpec=C:\WINDOWS\system32\cmd.exe
            FP_NO_HOST_CHECK=NO
            HOMEDRIVE=C:
            HOMEPATH=\Documents and Settings\Elsemiek
            LOGONSERVER=\\F-1C13F02528A14
            NUMBER_OF_PROCESSORS=4
            OS=Windows_NT
            Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
            PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            PROCESSOR_ARCHITECTURE=x86
            PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 11, GenuineIntel
            PROCESSOR_LEVEL=6
            PROCESSOR_REVISION=0f0b
            ProgramFiles=C:\Program Files
            PROMPT=$P$G
            QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
            SESSIONNAME=Console
            SystemDrive=C:
            SystemRoot=C:\WINDOWS
            TEMP=C:\DOCUME~1\Elsemiek\LOCALS~1\Temp
            TMP=C:\DOCUME~1\Elsemiek\LOCALS~1\Temp
            USERDOMAIN=F-1C13F02528A14
            USERNAME=Elsemiek
            USERPROFILE=C:\Documents and Settings\Elsemiek
            windir=C:\WINDOWS


            -- User Profiles ---------------------------------------------------------------

            Elsemiek (admin)
            Carlijn (admin)
            Frank (admin)
            Maddie (admin)
            Administrator (admin)


            -- Add/Remove Programs ---------------------------------------------------------

            --> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
            --> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
            --> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
            --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
            --> C:\WINDOWS\UNRecode.exe /UNINSTALL
            --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
            Adobe Reader 8.1.2 - Nederlands --> MsiExec.exe /I{AC76BA86-7AD7-1043-7B44-A81200000003}
            Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
            Adobe® Photoshop® Album Starter Edition 3.2 --> MsiExec.exe /I{A654A805-41D9-40C7-AA46-4AF04F044D61}
            AppCore --> MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
            Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
            ASUS WiFi-AP Solo --> C:\Program Files\InstallShield Installation Information\{295941F1-484E-4C23-B43C-7EFDC3E6DF43}\Setup.exe -runfromtemp -l0x0009 -removeonly
            Attansic Giga Ethernet Utility --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F698102-5739-441E-96F0-74F4EA540F06}\setup.exe" -l0x9
            Attansic L1 Gigabit Ethernet Driver --> rundll32.exe C:\WINDOWS\system32\Attansic\L1\atcInst.dll,AtcUninst C:\WINDOWS\system32\Attansic\L1 x86 1969 1048 L1
            AV --> MsiExec.exe /I{F4DB525F-A986-4249-B98B-42A8066251CA}
            ccCommon --> MsiExec.exe /I{3CCAD2EF-CFF2-4637-82AA-AABF370282D3}
            Colin McRae Rally 3 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D26D1A53-D8A2-4004-BC98-0642B4EEAAB2}\setup.exe" -l0x9
            Corel Paint Shop Pro Photo X2 --> MsiExec.exe /X{64E72FB1-2343-4977-B4A8-262CD53D0BD3}
            Finale NotePad 2008 --> C:\Program Files\Finale NotePad 2008\uninstallNP.exe
            FotoSketcher 1.4 --> "C:\Program Files\FotoSketcher 1.4\unins000.exe"
            GameSpy Arcade --> C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG
            GearDrvs --> MsiExec.exe /I{228F6876-A313-40A3-91C0-C3CBE6997D09}
            Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
            Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
            High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
            HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
            Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
            LimeWire Plus 1.7 --> C:\Program Files\LimeWire Plus\uninstall.exe
            Linksys Wireless-G PCI Adapter --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4DDC3BED-CC68-44AA-B435-D727B620CA5B}\setup.exe" -l0x9
            LiveUpdate 3.2 (Symantec Corporation) --> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
            LiveUpdate Notice (Symantec Corporation) --> MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}
            Media Converter for Philips --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7CDA2B02-E0A4-4EB5-8533-050D535BA43A}\setup.exe" -l0x13
            Messenger Plus! Live & Sponsor (CiD) --> "C:\Program Files\Messenger Plus! Live\Uninstall.exe"
            Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
            Microsoft Office Access MUI (Dutch) 2007 --> MsiExec.exe /X{90120000-0015-0413-0000-0000000FF1CE}
            Microsoft Office Enterprise 2007 --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISER /dll OSETUP.DLL
            Microsoft Office Enterprise 2007 --> MsiExec.exe /X{91120000-0030-0000-0000-0000000FF1CE}
            Microsoft Office Excel MUI (Dutch) 2007 --> MsiExec.exe /X{90120000-0016-0413-0000-0000000FF1CE}
            Microsoft Office Groove MUI (Dutch) 2007 --> MsiExec.exe /X{90120000-00BA-0413-0000-0000000FF1CE}
            Microsoft Office InfoPath MUI (Dutch) 2007 --> MsiExec.exe /X{90120000-0044-0413-0000-0000000FF1CE}
            Microsoft Office OneNote MUI (Dutch) 2007 --> MsiExec.exe /X{90120000-00A1-0413-0000-0000000FF1CE}
            Microsoft Office Outlook MUI (Dutch) 2007 --> MsiExec.exe /X{90120000-001A-0413-0000-0000000FF1CE}
            Microsoft Office PowerPoint MUI (Dutch) 2007 --> MsiExec.exe /X{90120000-0018-0413-0000-0000000FF1CE}
            Microsoft Office Proof (Dutch) 2007 --> MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
            Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
            Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
            Microsoft Office Proof (German) 2007 --> MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
            Microsoft Office Proofing (Dutch) 2007 --> MsiExec.exe /X{90120000-002C-0413-0000-0000000FF1CE}
            Microsoft Office Publisher MUI (Dutch) 2007 --> MsiExec.exe /X{90120000-0019-0413-0000-0000000FF1CE}
            Microsoft Office Shared MUI (Dutch) 2007 --> MsiExec.exe /X{90120000-006E-0413-0000-0000000FF1CE}
            Microsoft Office Word MUI (Dutch) 2007 --> MsiExec.exe /X{90120000-001B-0413-0000-0000000FF1CE}
            Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
            Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            MSN --> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
            Nero 7 Essentials --> MsiExec.exe /X{B28B351F-1232-46EA-85EF-B8EA91641033}
            NIO --> MsiExec.exe /X{77A2CC67-A928-4D55-8F25-535D5392F2C1}
            Norton 360 --> MsiExec.exe /I{21829177-4DED-4209-AD08-490B3AC9C01A}
            Norton 360 --> MsiExec.exe /I{2D617065-1C52-4240-B5BC-C0AE12157777}
            Norton 360 --> MsiExec.exe /I{63A6E9A9-A190-46D4-9430-2DB28654AFD8}
            Norton 360 (Symantec Corporation) --> "C:\Program Files\Common Files\Symantec Shared\SymSetup\{2D617065-1C52-4240-B5BC-C0AE12157777}_1_0_0_184\{2D617065-1C52-4240-B5BC-C0AE12157777}.exe" /X
            Norton 360 Help --> MsiExec.exe /I{1CA941F1-5006-487E-9FD4-09F812A7D6B8}
            Norton Confidential Browser Component --> MsiExec.exe /I{4843B611-8FCB-4428-8C23-31D0A5EAE164}
            Norton Confidential Web Authentification Component --> MsiExec.exe /I{3074EB89-1BCA-4AEF-AFF4-EFB4634C1923}
            Norton Confidential Web Protection Component --> MsiExec.exe /I{D353CC51-430D-4C6F-9B7E-52003DA1E05A}
            NVIDIA Drivers --> C:\WINDOWS\system32\nvuninst.exe UninstallGUI
            Philips Device Manager --> C:\Program Files\InstallShield Installation Information\{36A9D3F8-3FCF-4FBA-A8AD-3C1CE56C8AF4}\setup.exe -runfromtemp -l0x0013 -removeonly
            QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
            Race Driver 3 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A137D52E-FA96-4815-85F5-E7B8F66837DB}\Setup.exe" -l0x9 -removeonly
            RCT3 Soaked --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA926717-CE5A-4CB4-AB21-9E6E9565A458}\Setup.exe" -l0x13
            Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x9 -removeonly
            RollerCoaster Tycoon 3 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\Setup.exe" -l0x13
            Security Update for Excel 2007 (KB946974) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}
            Security Update for Office 2007 (KB947801) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}
            Security Update for Outlook 2007 (KB946983) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {66B9496E-C0C3-4065-9868-85CCA92126C3}
            Security Update for Visio 2007 (KB947590) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
            SPBBC 32bit --> MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
            SuppSoft --> MsiExec.exe /I{022DA2C3-81C7-4003-A6BC-1BB147B20097}
            Symantec Technical Support Controls --> MsiExec.exe /I{92B1B3CC-EC78-45B8-96D0-8B3F11495864}
            SymNet --> MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
            Teach2000 8.21 --> "C:\Program Files\Teach2000\Uninstall\unins000.exe"
            The Sims Deluxe --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{10798AE3-DCBB-43C3-9C93-C23512427E25}\setup.exe" -l0013
            Update for Office 2007 (KB946691) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
            Update for Outlook 2007 Junk Email Filter (kb949037) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {B4F188C6-6DBF-42A5-A8A3-3086D1A384F2}
            Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
            Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
            Windows Live Sign-in Assistant --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
            Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"


            -- Application Event Log -------------------------------------------------------

            Event Record #/Type7183 / Success
            Event Submitted/Written: 04/20/2008 05:23:48 PM
            Event ID/Source: 12001 / usnjsvc
            Event Description:
            The Messenger Sharing USN Journal Reader service started successfully.

            Event Record #/Type7142 / Success
            Event Submitted/Written: 04/20/2008 01:36:08 PM
            Event ID/Source: 12001 / usnjsvc
            Event Description:
            The Messenger Sharing USN Journal Reader service started successfully.

            Event Record #/Type7124 / Error
            Event Submitted/Written: 04/20/2008 01:25:52 PM
            Event ID/Source: 1000 / Application Error
            Event Description:
            Faulting application pictureviewer.exe, version 7.4.1.14, faulting module quicktime.qts, version 7.4.1.14, fault address 0x00aac6bb.
            Processing media-specific event for [pictureviewer.exe!ws!]

            Event Record #/Type7123 / Error
            Event Submitted/Written: 04/20/2008 01:25:24 PM
            Event ID/Source: 1000 / Application Error
            Event Description:
            Faulting application pictureviewer.exe, version 7.4.1.14, faulting module quicktime.qts, version 7.4.1.14, fault address 0x00aac6bb.
            Processing media-specific event for [pictureviewer.exe!ws!]

            Event Record #/Type7115 / Success
            Event Submitted/Written: 04/20/2008 00:26:29 PM
            Event ID/Source: 12001 / usnjsvc
            Event Description:
            The Messenger Sharing USN Journal Reader service started successfully.



            -- Security Event Log ----------------------------------------------------------

            No Errors/Warnings found.


            -- System Event Log ------------------------------------------------------------

            Event Record #/Type10132 / Error
            Event Submitted/Written: 04/20/2008 01:59:24 PM
            Event ID/Source: 7026 / Service Control Manager
            Event Description:
            The following boot-start or system-start driver(s) failed to load:
            AFD
            eeCtrl
            Fips
            intelppm
            IPSec
            MRxSmb
            NetBIOS
            NetBT
            RasAcd
            Rdbss
            SPBBCDrv
            SRTSPX
            SYMTDI
            Tcpip

            Event Record #/Type10131 / Error
            Event Submitted/Written: 04/20/2008 01:59:24 PM
            Event ID/Source: 7001 / Service Control Manager
            Event Description:
            The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
            %%31

            Event Record #/Type10130 / Error
            Event Submitted/Written: 04/20/2008 01:59:24 PM
            Event ID/Source: 7001 / Service Control Manager
            Event Description:
            The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:
            %%31

            Event Record #/Type10129 / Error
            Event Submitted/Written: 04/20/2008 01:59:24 PM
            Event ID/Source: 7001 / Service Control Manager
            Event Description:
            The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:
            %%31

            Event Record #/Type10128 / Error
            Event Submitted/Written: 04/20/2008 01:59:24 PM
            Event ID/Source: 7001 / Service Control Manager
            Event Description:
            The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:
            %%31



            -- End of Deckard's System Scanner: finished at 2008-04-20 19:29:47 ------------

            En dit is van dat raxvo ofzoiets:

            ---RVAXO.exe Updated: 2008-04-20---first run---
            Uninstallers:

            Files found:
            C:\WINDOWS\system32\_000013_.tmp.dll
            C:\regxpcom.exe

            Folders Found:
            C:\Program Files\PlayMP3z
            C:\Program Files\FBrowsingAdvisor
            C:\Program Files\BrowsingTool
            C:\Program Files\FBrowserAdvisor

            Hosts-file was reset, If you use a custom hosts file please replace it...

            --------------RVAXO.exe last run---------------
            Not deleted items:

            --------------RVAXO.exe finished----------------
            Last edited by Miekdemikmak; 20-04-08, 19:36.

            Comment


            • #7
              Logje lijkt me OK

              Doe dit nog:

              Download ATF cleaner (mirror)(gemaakt door Atribune)

              Belangrijk: Sluit al je browservensters(IE en/of Firefox en/of Opera) om de tool goed te kunnen laten werken.

              Dubbelklik op ATF cleaner om het programma te starten.
              Op het tabblad "Main", plaats je een vinkje bij Select All.
              Klik op de knop Empty Selected.

              Het volgende doen als je ook FireFox als browser hebt:
              Klik op tabblad "Firefox", plaats een vinkje bij Select All.
              Wil je de door Firefox opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
              (dit haalt het vinkje weer weg bij "Firefox saved passwords")
              Klik op de knop Empty Selected.

              Het volgende doen als je ook Opera als browser hebt:
              Klik op tabblad "Opera", plaats een vinkje bij Select All.
              Wil je de door Opera opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
              Klik op de knop Empty Selected.
              Ga naar het tabblad "Main" en klik op de knop Exit om het programma af te sluiten.

              Schakel Systeemherstel uit. Herstart de computer. Schakel Systeemherstel weer in.
              Kijk hier hoe je je systeemherstel moet uitschakelen.
              Hiermee verwijder je eventuele restanten van de infecties uit je systeemherstel.

              Verder mag je alle gebruikte programma's verwijderen.

              Vertel of je nog problemen ondervindt

              Comment


              • #8
                Bedankt!

                Heel erg bedankt! Ik heb nu helemaal geen reclames meer. De uitleg was superduidelijk en je antwoordde heel snel! Super!

                Comment


                • #9
                  Graag gedaan hoor

                  Comment

                  Sorry, you are not authorized to view this page
                  Working...
                  X