Gesloten Onderwerp
Resultaten 1 tot 11 van de 11

Onderwerp: Hijacklog Nakijken

  1. #1

    Ingeschreven
    Feb 2010
    Berichten
    5
    hallo
    ik ben nieuw op dit forum.
    ik heb geen groot pobleem maar zou het fijn vinden als iemand hier eens naar kijkt.
    mijn laptop is een nc6120 XP. af en toe als ik internet ratelt ie bij het openen van een nieuwe pagina, en postvak doet het dan ook niet. dit verhelp ik door een goede google pagina te open , zomaar wat in de zoekbalk te zetten, dat aanklikken en mijn hele probleem is verholpen.......
    misschien dat u wat kan vinden in mijn log, waardoor dit niet meer gebeurt.
    groet.
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:04:28, on 6-2-2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\windows\System32\smss.exe
    C:\windows\system32\winlogon.exe
    C:\windows\system32\services.exe
    C:\windows\system32\lsass.exe
    C:\windows\system32\svchost.exe
    C:\windows\System32\svchost.exe
    C:\windows\system32\svchost.exe
    C:\windows\Explorer.EXE
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\windows\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\windows\system32\CNAB4RPK.EXE
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\windows\system32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\windows\AGRSMMSG.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe
    C:\windows\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    C:\windows\System32\svchost.exe
    C:\windows\system32\wuauclt.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Documents and Settings\Gebruiker\Bureaublad\HiJackThis.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    R3 - URLSearchHook: (no name) - *{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Docum ents and Settings\Gebruiker\jxhgyj.exe \s
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\s wg.dll
    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [HitmanPro35] "C:\Program Files\Hitman Pro 3.5\HitmanPro35[1].exe" /scan:boot
    O4 - HKLM\..\Run: [RCAutoLiveUpdate] C:\Program Files\Max Registry Cleaner\MaxLURC.exe -AUTO
    O4 - HKLM\..\Run: [RCSystemTray] C:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe"
    O4 - Global Startup: BTTray.lnk = ?
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Verzenden naar &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/58.14/uploader2.cab
    O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.nl/s/v/53.13/uploader2.cab
    O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.mypix.com/nl/nl/importer/newcon...geUploader5.cab
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photo...ol/MSNPUpld.cab
    O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://cache.hyves-static.net/statics/Auri...geUploader4.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{6EB7F184-2756-4DFB-B938-52F0AF6B3BB0}: NameServer = 192.168.2.1
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\windows\SYSTEM32\avgrsstx.dll
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Google Updateservice (gupdate1ca00cdefd9f9df) (gupdate1ca00cdefd9f9df) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    --
    End of file - 9701 bytes
    Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

  2. #2
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    14.192

    Start Hijackthis op en kies voor 'Do a system scan only'
    Selecteer alleen de items die hieronder zijn genoemd:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    R3 - URLSearchHook: (no name) - *{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Docum ents and Settings\Gebruiker\jxhgyj.exe \s

    Klik op 'Fix checked' om de items te verwijderen.


    Download Combofix

    naar je Bureaublad en gebruik het volgens deze handleiding.

    OPMERKING: indien je, tijdens of na het downloaden van Combofix of tijdens het gebruik van Combofix een melding krijgt van je Antivirus- of een andere realtime scanner, schakel dan deze scanner uit en download Combofix opnieuw.
    Sommige scanners zien bepaalde componenten die Combofix gebruikt als verdacht en gaan deze blokkeren of verwijderen!
    • Dubbelklik op Combofix.exe om het te starten.
    • Indien je Combofix al eerder hebt gebruikt, kan je een waarschuwing krijgen dat een update beschikbaar is. Sta toe dat ComboFix wordt geupdate.
    • Klik op OK in het "NirCmd" venstertje.
    • Indien de Recovery Console niet geïnstalleerd is, wordt je gevraagd om dit alsnog te doen door op JA te klikken in het "Query - Recovery Console" venster.
    • Klik op OK en Ja om automatisch de Recovery Console te laten installeren.
    • Klik na afloop terug op Ja om het scannen op malware te starten.
    • Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.
    • Wanneer de fix voltooid is en na herstart, zal de log Combofix.txt openen.
    Post dit logje in je volgende antwoord.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips


    Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

  3. #3

    Ingeschreven
    Feb 2010
    Berichten
    5
    bij deze:

    ComboFix 10-02-06.03 - Gebruiker 07-02-2010 10:24:35.1.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1043.18.2039.1420 [GMT 1:00]
    Gestart vanuit: c:\documents and settings\Gebruiker\Bureaublad\ComboFix.exe
    AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    WAARSCHUWING - DE RECOVERY CONSOLE IS NIET OP DIT SYSTEEM GEINSTALLEERD !!
    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\f3setupinstall
    c:\program files\f3setupinstall\f3initialsetup1.0.1.1.inf
    c:\program files\f3setupinstall\f3Setup1.exe
    c:\program files\FunWebProducts
    c:\program files\FunWebProducts\Installr\1.bin\F3EZsetp.dll
    c:\program files\Internet Saving Optimizer
    c:\program files\Internet Saving Optimizer\3.7.1.4630\Data\config.md
    c:\program files\Internet Saving Optimizer\3.7.1.4630\FF\chrome\content\NPAddOn.js
    c:\program files\Internet Saving Optimizer\3.7.1.4630\FF\chrome\content\NPAddOn.xul
    c:\program files\Internet Saving Optimizer\3.7.1.4630\FF\chrome\NPAddOn.jar
    c:\program files\Internet Saving Optimizer\3.7.1.4630\FF\components\NPFFAddOn.xpt
    c:\program files\Internet Saving Optimizer\3.7.1.4630\FF\components\NPFFHelperCompo nent.js
    c:\program files\Internet Saving Optimizer\3.7.1.4630\FF\install.rdf
    c:\program files\Internet Saving Optimizer\3.7.1.4630\unins000.dat
    c:\program files\Media Access Startup
    c:\program files\Media Access Startup\1.6.0.940\Data\config.md
    c:\program files\Media Access Startup\1.6.0.940\FF\chrome\content\HPAddOn.js
    c:\program files\Media Access Startup\1.6.0.940\FF\chrome\content\HPAddOn.xul
    c:\program files\Media Access Startup\1.6.0.940\FF\chrome\HPAddOn.jar
    c:\program files\Media Access Startup\1.6.0.940\FF\components\HPFFAddOn.xpt
    c:\program files\Media Access Startup\1.6.0.940\FF\components\HPFFHelperComponen t.js
    c:\program files\Media Access Startup\1.6.0.940\FF\install.rdf
    c:\program files\Media Access Startup\1.6.0.940\unins000.dat
    c:\program files\RelevantKnowledge
    c:\program files\RelevantKnowledge\rloci.bin
    c:\sysmon\flvdirect
    c:\sysmon\flvdirect\cvhc13007.exe
    c:\windows\system32\kr_done1
    c:\windows\system32\win32.exe

    .
    (((((((((((((((((((( Bestanden Gemaakt van 2010-01-07 to 2010-02-07 ))))))))))))))))))))))))))))))
    .

    2010-02-06 09:47 . 2010-02-07 09:11 -------- d--h--r- c:\documents and settings\Gebruiker\Onlangs geopend
    2010-02-05 16:13 . 2010-02-05 16:13 -------- d-----w- c:\program files\Ask Search Assistant
    2010-02-02 11:43 . 2010-02-02 11:58 -------- d-----w- c:\program files\Nero
    2010-02-02 11:43 . 2010-02-02 11:59 -------- d-----w- c:\program files\Common Files\Nero
    2010-02-02 11:33 . 2010-02-04 23:36 123 ----a-w- c:\windows\system\SysRegC.dll
    2010-02-02 11:33 . 2010-02-02 20:48 -------- d-----w- c:\program files\Max Registry Cleaner
    2010-02-02 11:33 . 2010-02-02 12:54 -------- d-----w- c:\windows\MaxSecureBackup
    2010-02-02 11:33 . 2009-12-19 11:05 151472 ----a-w- c:\windows\system32\GetHardDiskNo.dll
    2010-02-02 09:52 . 2010-01-11 08:52 2066200 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
    2010-02-01 12:22 . 2010-02-01 12:22 12872 ----a-w- c:\windows\system32\bootdelete.exe
    2010-01-31 00:44 . 2010-01-31 00:44 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\Canneverbe Limited
    2010-01-30 15:04 . 2010-01-30 15:04 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\Canneverbe_Limited
    2010-01-30 15:04 . 2010-01-30 15:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
    2010-01-30 09:05 . 2010-02-07 09:30 -------- d-----w- C:\sysmon
    2010-01-29 22:28 . 2003-03-25 14:08 286720 ----a-w- c:\windows\system32\NCTWMAFile2.dll
    2010-01-29 22:28 . 2002-12-03 02:11 143872 ----a-w- c:\windows\system32\NCTWMAFile.dll
    2010-01-29 22:28 . 2002-12-03 02:07 168448 ----a-w- c:\windows\system32\NCTAudioPlayer.dll
    2010-01-29 22:28 . 2003-03-26 05:59 573440 ----a-w- c:\windows\system32\NCTAudioInformation2.dll
    2010-01-29 22:28 . 2002-12-03 02:02 491520 ----a-w- c:\windows\system32\NCTAudioFile.dll
    2010-01-29 22:23 . 2000-10-01 19:00 119568 ----a-w- c:\windows\system32\VB6FR.DLL
    2010-01-29 22:23 . 1999-03-25 19:00 101888 ----a-w- c:\windows\system32\VB6STKIT.DLL
    2010-01-29 22:23 . 1998-07-12 23:00 21504 ----a-w- c:\windows\system32\TABCTFR.DLL
    2010-01-29 22:23 . 1998-07-12 23:00 59904 ----a-w- c:\windows\system32\Mscc2fr.dll
    2010-01-29 22:23 . 1998-07-12 23:00 141312 ----a-w- c:\windows\system32\MSCMCFR.DLL
    2010-01-29 22:23 . 1998-07-12 19:00 32768 ----a-w- c:\windows\system32\CMDLGFR.DLL
    2010-01-29 22:23 . 2010-01-29 22:34 -------- d-----w- c:\program files\Free Audio Pack
    2010-01-29 15:49 . 2010-01-29 15:49 1236992 ----a-w- c:\windows\system32\a1H-R4R_9Vi__.dll
    2010-01-27 22:32 . 2010-01-27 22:32 15880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
    2010-01-27 22:32 . 2010-01-27 22:32 163728 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
    2010-01-27 22:32 . 2010-01-27 22:32 327000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
    2010-01-27 22:32 . 2010-01-27 22:32 87496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
    2010-01-24 13:22 . 2010-01-24 13:22 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
    2010-01-24 13:22 . 2010-01-24 13:22 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\NCH Swift Sound
    2010-01-24 12:54 . 2010-01-24 12:54 -------- d-----w- c:\windows\system32\windows media
    2010-01-24 12:54 . 2010-01-24 12:54 -------- d--h--w- c:\windows\msdownld.tmp
    2010-01-24 12:54 . 2010-01-24 12:54 -------- d-----w- c:\program files\Windows Media Components
    2010-01-23 00:29 . 2010-01-23 00:29 -------- d-----w- c:\program files\IrfanView
    2010-01-20 16:32 . 2010-02-04 22:32 3803208 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
    2010-01-14 18:04 . 2010-01-14 18:04 -------- d-----w- c:\documents and settings\Gebruiker\Local Settings\Application Data\VSO
    2010-01-14 00:12 . 2010-01-16 11:27 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\VSO
    2010-01-13 09:20 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
    2010-01-10 08:27 . 2010-01-10 08:27 -------- d-----w- c:\program files\Belastingdienst
    2010-01-09 12:10 . 2010-01-27 22:32 15880 ----a-w- c:\windows\system32\lsdelete.exe
    2010-01-09 10:32 . 2009-12-02 13:19 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-01-09 10:32 . 2010-01-27 22:32 862040 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
    2010-01-09 10:32 . 2010-01-27 22:32 206944 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
    2010-01-09 10:32 . 2010-01-27 22:32 390288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
    2010-01-09 10:30 . 2010-01-09 10:30 -------- d-----w- c:\program files\Lavasoft

    .
    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))) ))
    .
    2010-02-06 19:04 . 2009-08-15 09:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
    2010-02-06 16:14 . 2009-07-09 18:58 -------- d-----w- c:\program files\Google
    2010-02-06 11:27 . 2009-08-09 14:14 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\Belastingdienst
    2010-02-06 09:06 . 2010-01-02 23:47 15944 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
    2010-02-05 16:12 . 2009-08-11 18:39 -------- d-----w- c:\program files\Messenger Plus! Live
    2010-02-04 22:32 . 2010-01-09 10:32 389784 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
    2010-02-04 22:32 . 2010-01-09 10:31 823928 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
    2010-02-04 22:32 . 2010-01-09 10:31 1181328 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
    2010-02-02 18:24 . 2009-10-21 19:56 -------- d-----w- c:\program files\Audacity
    2010-02-02 18:24 . 2009-12-02 18:44 -------- d-----w- c:\program files\Ask.com
    2010-02-02 11:45 . 2009-10-23 00:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
    2010-02-01 12:22 . 2010-01-02 23:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
    2010-01-31 11:53 . 2009-07-09 21:11 -------- d-----w- c:\program files\Lexmark X1100 Series
    2010-01-31 09:34 . 2009-06-10 07:24 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
    2010-01-30 09:24 . 2009-07-09 19:38 -------- d-----w- c:\program files\LimeWire
    2010-01-29 22:45 . 2009-07-29 12:28 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
    2010-01-27 22:32 . 2010-01-09 10:32 537576 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
    2010-01-27 22:32 . 2010-01-09 10:32 8 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
    2010-01-27 22:32 . 2010-01-09 10:31 6296864 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
    2010-01-27 22:32 . 2010-01-09 10:31 933120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
    2010-01-27 22:32 . 2010-01-09 10:31 816784 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
    2010-01-27 22:32 . 2010-01-09 10:31 1643272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
    2010-01-27 22:32 . 2010-01-09 10:31 788880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
    2010-01-26 21:08 . 2009-10-21 23:55 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
    2010-01-25 10:11 . 2009-11-07 22:01 1 ----a-w- c:\documents and settings\Gebruiker\Application Data\OpenOffice.org\3\user\uno_packages\cache\stam p.sys
    2010-01-12 12:09 . 2009-09-19 22:26 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
    2010-01-09 10:32 . 2010-01-09 10:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-01-09 10:30 . 2010-01-09 10:30 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
    2010-01-04 09:20 . 2004-08-04 12:00 89380 ----a-w- c:\windows\system32\perfc013.dat
    2010-01-04 09:20 . 2004-08-04 12:00 505044 ----a-w- c:\windows\system32\perfh013.dat
    2010-01-02 23:47 . 2010-01-02 23:47 -------- d-----w- c:\program files\Hitman Pro 3.5
    2009-12-26 16:24 . 2009-12-26 16:24 -------- d-----w- c:\program files\DivX
    2009-12-26 16:24 . 2009-12-26 16:24 -------- d-----w- c:\program files\Common Files\DivX Shared
    2009-12-21 21:43 . 2009-12-21 21:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Zylom
    2009-12-21 19:10 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-12-16 13:04 . 2009-12-02 18:46 -------- d-----w- c:\program files\GPLGS
    2009-12-16 13:03 . 2009-12-10 16:10 -------- d-----w- c:\program files\Microsoft Silverlight
    2009-12-07 14:10 . 2010-01-09 10:30 2953352 -c--a-w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe
    2009-11-24 01:03 . 2009-11-26 00:36 196608 ----a-w- c:\windows\system32\HMIPCore.dll
    2009-11-21 16:03 . 2004-08-04 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))) )
    .
    .
    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

    [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
    2009-11-25 12:02 1230080 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

    [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

    [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2009-07-09 39408]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
    "SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT \TINTSETP.EXE" [2004-08-04 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TIN TSETP.EXE" [2004-08-04 455168]
    "Lexmark X1100 Series"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 57344]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.E XE" [2004-08-04 208952]
    "igfxtray"="c:\windows\system32\igfxtray.exe" [2007-06-19 101144]
    "igfxpers"="c:\windows\system32\igfxpers.exe" [2007-06-19 125720]
    "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2007-06-19 84760]
    "AGRSMMSG"="AGRSMMSG.exe" [2005-11-16 88209]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-16 2043160]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
    "RCAutoLiveUpdate"="c:\program files\Max Registry Cleaner\MaxLURC.exe" [2009-12-21 954288]
    "RCSystemTray"="c:\program files\Max Registry Cleaner\MaxRCSystemTray.exe" [2009-12-19 987056]

    c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\
    BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-2-27 581693]
    WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-11-18 495432]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-09-19 22:26 11952 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "avg8emc"=2 (0x2)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\WINDOWS\\system32\\CNAB4RPK.EXE"=
    "c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=

    R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\ avgrkx86.sys [19-9-2009 11:18 PM 12552]
    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [9-1-2010 11:32 AM 64288]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [19-9-2009 11:18 PM 335240]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [19-9-2009 11:18 PM 108552]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [19-9-2009 11:26 PM 297752]
    R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssflt r_tdi.sys [20-9-2009 12:36 PM 54752]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2-12-2009 2:19 PM 1181328]
    R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtip ci21.sys [9-6-2009 2:56 PM 87936]
    S2 gupdate1ca00cdefd9f9df;Google Updateservice (gupdate1ca00cdefd9f9df);c:\program files\Google\Update\GoogleUpdate.exe [9-7-2009 8:46 PM 133104]
    S3 fsssvc;De service Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [5-8-2009 9:48 PM 704864]
    S3 PbsAuDrv;PolderbitS Audio Driver;c:\windows\system32\drivers\pbsaudrv.sys --> c:\windows\system32\drivers\pbsaudrv.sys [?]
    .
    Inhoud van de 'Gedeelde Taken' map

    2010-02-07 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 22:32]

    2010-02-07 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 22:32]

    2010-02-07 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 22:32]

    2010-02-07 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 22:32]

    2010-02-07 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 22:32]

    2010-02-07 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-09 19:44]

    2010-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-09 19:46]

    2010-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-09 19:46]
    .
    .
    ------- Bijkomende Scan -------
    .
    uStart Page = hxxp://www.google.nl/
    uDefault_Search_URL = hxxp://www.google.com/ie
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Save YouTube Video
    IE: Save YouTube Video as MP3
    IE: Verzenden naar &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    TCP: {6EB7F184-2756-4DFB-B938-52F0AF6B3BB0} = 192.168.2.1
    DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.com/s/v/58.14/uploader2.cab
    DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab
    .
    - - - - ORPHANS VERWIJDERD - - - -

    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    WebBrowser-{59382727-9048-6123-1523-597264847187} - (no file)
    AddRemove-HijackThis - c:\documents and settings\Gebruiker\Local Settings\Temporary Internet Files\Content.IE5\UK82RMA0\HijackThis.exe



    ************************************************** ************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-02-07 10:32
    Windows 5.1.2600 Service Pack 3 NTFS

    scannen van verborgen processen ...

    scannen van verborgen autostart items ...

    scannen van verborgen bestanden ...

    Scan succesvol afgerond
    verborgen bestanden: 0

    ************************************************** ************************
    .
    --------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Curr entVersion\Installer\UserData\LocalSystem\Componen ts\€–}|ÿÿÿÿÀ•}|ù•9~*]
    "3140110900063D11C8EF10054038389C"="C?\\WINDOWS\\s ystem32\\FM20ENU.DLL"
    .
    Voltooingstijd: 2010-02-07 10:34:54
    ComboFix-quarantined-files.txt 2010-02-07 09:34

    Pre-Run: 11.819.278.336 bytes beschikbaar
    Post-Run: 11.960.311.808 bytes beschikbaar

    - - End Of File - - 05B1A8079C92715EC64B49A7137BDFFB
    Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

  4. #4
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    14.192
    Dit >
    WAARSCHUWING - DE RECOVERY CONSOLE IS NIET OP DIT SYSTEEM GEINSTALLEERD !!
    is niet slim hoor.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips


    Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

  5. #5
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    14.192
    Nieuw HijackThis logje ook nog even aub.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips


    Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

  6. #6

    Ingeschreven
    Feb 2010
    Berichten
    5
    bij deze:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:09:58, on 8-2-2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\windows\System32\smss.exe
    C:\windows\system32\winlogon.exe
    C:\windows\system32\services.exe
    C:\windows\system32\lsass.exe
    C:\windows\system32\svchost.exe
    C:\windows\System32\svchost.exe
    C:\windows\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\windows\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
    C:\windows\system32\CNAB4RPK.EXE
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\windows\system32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\windows\AGRSMMSG.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\windows\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    C:\windows\System32\svchost.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\windows\explorer.exe
    C:\Program Files\AVG\AVG8\avgtray.exe
    C:\Program Files\Nero\Nero 9\Nero StartSmart\NeroStartSmart.exe
    C:\Program Files\Nero\Nero 9\Nero StartSmart\NMDllHost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Gebruiker\Bureaublad\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\s wg.dll
    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [RCAutoLiveUpdate] C:\Program Files\Max Registry Cleaner\MaxLURC.exe -AUTO
    O4 - HKLM\..\Run: [RCSystemTray] C:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe"
    O4 - Global Startup: BTTray.lnk = ?
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Verzenden naar &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/58.14/uploader2.cab
    O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.nl/s/v/53.13/uploader2.cab
    O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.mypix.com/nl/nl/importer/newcon...geUploader5.cab
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photo...ol/MSNPUpld.cab
    O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://cache.hyves-static.net/statics/Auri...geUploader4.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{6EB7F184-2756-4DFB-B938-52F0AF6B3BB0}: NameServer = 192.168.2.1
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\windows\SYSTEM32\avgrsstx.dll
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Google Updateservice (gupdate1ca00cdefd9f9df) (gupdate1ca00cdefd9f9df) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    --
    End of file - 9278 bytes
    Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

  7. #7
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    14.192
    Nog ergens last van nu ?
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips


    Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

  8. #8

    Ingeschreven
    Feb 2010
    Berichten
    5
    vanmiddag deed ie het nog een keer maar daarna heb ik er geen last meer van gehad, dus ik denk dat het nu over is.
    heel erg bedankt!
    groetjes
    yvonne
    Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

  9. #9
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    14.192
    Ga naar Start - Uitvoeren
    en Geef hier het volgende in: Combofix /Uninstall
    Druk daarna op OK.
    Als het goed is krijg je dan een melding dat Combofix verwijderd werd.

    Voorbeeld:



    Uitvoeren kan ook gestart worden door de toetsencombinatie
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips


    Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

  10. #10

    Ingeschreven
    Feb 2010
    Berichten
    5
    gedaan.
    geen last meer gehad tot nu toe.
    dank je wel.
    Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

  11. #11
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    14.192
    Graag gedaan hoor.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips


    Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!

Forum Rechten

  • Je mag geen nieuwe onderwerpen plaatsen
  • Je mag geen reacties plaatsen
  • Je mag geen bijlagen toevoegen
  • Je mag jouw berichten niet wijzigen

SEO by vBSEO 3.5.1