+ Plaats een Reactie
Resultaten 1 tot 14 van de 14

Onderwerp: Internet Explorer/Firefox crasht steeds

  1. #1

    Ingeschreven
    Nov 2005
    Locatie
    Holland
    Leeftijd
    21
    Berichten
    1.065

    Exclamation Internet Explorer/Firefox crasht steeds

    Korte (duidelijke!) omschrijving van het probleem: Tijdens het internetten crasht mijn internet steeds, dit is zowel bij Firefox als bij Internet Explorer. Dit is bij alle site's. (Dus niet alleen youtube)
    Ook gebruikt hij heel veel geheugen (Taakbeheer) bij elk programma minimaal 30.000.
    Terwijl die sinds gister (na een Ad Aware scan) helemaal geen geheugen erbij vermeld.
    Ook veel last van toolbars etc.

    Malwarebytes' Anti-Malware log:
    Malwarebytes Anti-Malware (-evaluatieversie-) 1.60.0.1800
    www.malwarebytes.org

    Databaseversie: v2012.01.03.04
    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 8.0.6001.18702
    Eigenaar :: EIGENAAR-317372 [administrator]

    Realtime bescherming: Ingeschakeld
    3-1-2012 21:31:21
    mbam-log-2012-01-03 (21-31-21).txt

    Scantype: Snelle scan
    Ingeschakelde scanopties: Geheugen | Opstarten | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
    Uitgeschakelde scanopties: P2P
    Objecten gescand: 164625
    Verstreken tijd: 9 minuut/minuten, 3 seconde(n)

    Geheugenprocessen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 1
    C:\Documents and Settings\Eigenaar\Mijn documenten\Downloads\SoftonicDownloader_voor_nexus-radio.exe (PUP.BundleOffer.Downloader.S) -> Succesvol in quarantaine geplaatst en verwijderd.

    (einde)




    HijackThis log:

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 21:46:27, on 3-1-2012
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Microsoft\BingBar\SeaPort.EXE
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Ask.com\Updater\Updater.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\iTunes\iTunes.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
    C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
    C:\Program Files\VideoLAN\VLC\vlc.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\WINDOWS\notepad.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Microsoft\BingBar\BingBar.exe
    C:\Program Files\Microsoft\BingBar\BingApp.exe
    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.searchcompletion.com/?si=10205&home=1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.nl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.searchcompletion.com/?si=10205&home=1
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    R3 - URLSearchHook: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\4.7\youtubedownloaderToolbarIE.dll
    O2 - BHO: AC-Pro - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Documents and Settings\Eigenaar\Application Data\Complitly\AutocompletePro.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - (no file)
    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Complitly - {D27FC31C-6E3D-4305-8D53-ACDAEFA5F862} - C:\Documents and Settings\Eigenaar\Application Data\Complitly\Complitly.dll
    O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\4.7\youtubedownloaderToolbarIE.dll
    O3 - Toolbar: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YouTube Downloader Toolbar\IE\4.7\youtubedownloaderToolbarIE.dll
    O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
    O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    O4 - HKLM\..\Run: [PlusService] C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Eigenaar\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
    O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1309523576375
    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
    O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

    --
    End of file - 10279 bytes


    Bij voorbaat dank,

    Groeten

    Sierra^

    Laatst gewijzigd door Sierra^; 03-01-12 om 21:50.
    Wie zonder zonde is werpe de eerste steen.

  2. #2
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    1) Zet TeaTimer van Spybot even uit tijdens de fix want hij kan veranderingen in de weg staan.
    - Start Spybot S&D
    - Ga naar het Mode menu en selecteer "Advanced Mode"
    - Aan de linkerkant, kies "Tools"kies "Tools" (of gereedschap ) en klik op > Resident
    - Uitvinken "Resident TeaTimer" en en sluit Spybot S&D.
    - Herstart de computer.

    2)
    Start Hijackthis op en kies voor 'Do a system scan only'
    Selecteer alleen de items die hieronder zijn genoemd:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.searchcompletion.com/?si=10205&home=1
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.searchcompletion.com/?si=10205&home=1
    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O2 - BHO: AC-Pro - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Documents and Settings\Eigenaar\Application Data\Complitly\AutocompletePro.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - (no file)
    O2 - BHO: Complitly - {D27FC31C-6E3D-4305-8D53-ACDAEFA5F862} - C:\Documents and Settings\Eigenaar\Application Data\Complitly\Complitly.dll
    O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
    O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    Sluit alle vensters behalve Hijackthis
    Klik op 'Fix checked' om de items te verwijderen.

    Download ComboFix van één van deze locaties:

    Link 1
    Link 2

    * BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op.

    >>Hier<< kunt u lezen hoe u Combofix dient te gebruiken.


    1. Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix.

    * (hier of hier staat een handleiding over hoe je deze kan uitschakelen

    2. Het kan voorkomen dat de computer meerdere malen opnieuw gestart moet worden, dit is normaal.
    3. Dubbelklik op "Combofix.exe" om de tool te starten.
    4. Klik niet in het scherm van Combofix als deze actief is, hierdoor kan de 'tool' vastlopen.

    * Noot !!! Als er een error wordt getoond met de melding "Illegal operation attempted on a registery key that has been marked for deletion." herstart dan de computer.

    5. Wanneer ComboFix klaar is, zal het het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



  3. #3

    Ingeschreven
    Nov 2005
    Locatie
    Holland
    Leeftijd
    21
    Berichten
    1.065
    Ten eerste bedankt voor het snelle bericht

    Het Combofix logje:

    ComboFix 12-01-04.02 - Eigenaar 04-01-2012 21:08:04.1.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.1022.417 [GMT 1:00]
    Gestart vanuit: c:\documents and settings\Eigenaar\Bureaublad\ComboFix.exe
    AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
    .
    ADS - system32: deleted 12 bytes in 1 streams.
    .
    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\install.exe
    c:\windows\alcrmv.exe
    c:\windows\system32\drivers\npf.sys
    c:\windows\system32\Packet.dll
    c:\windows\system32\WanPacket.dll
    c:\windows\system32\wpcap.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Legacy_NPF
    -------\Service_NPF
    .
    .
    (((((((((((((((((((( Bestanden Gemaakt van 2011-12-04 to 2012-01-04 ))))))))))))))))))))))))))))))
    .
    .
    2012-01-03 20:28 . 2012-01-03 20:28 -------- d-----w- c:\documents and settings\Eigenaar\Application Data\Malwarebytes
    2012-01-03 20:28 . 2012-01-03 20:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2012-01-03 20:28 . 2012-01-03 20:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2012-01-03 20:28 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-01-02 17:37 . 2012-01-04 19:41 -------- d--h--r- c:\documents and settings\Eigenaar\Onlangs geopend
    2011-12-23 14:21 . 2011-12-23 14:21 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
    2011-12-14 21:00 . 2011-12-14 21:04 -------- d-----w- c:\program files\Google
    2011-12-10 11:35 . 2011-12-10 11:36 -------- d-----w- c:\program files\Realtek AC97
    2011-12-09 21:43 . 2006-08-01 14:02 49152 ----a-w- c:\windows\system32\ChCfg.exe
    2011-12-09 21:43 . 2008-04-13 22:46 141056 ----a-w- c:\windows\system32\drivers\ks.sys
    2011-12-09 21:43 . 2006-12-29 13:48 4026112 ----a-r- c:\windows\system32\drivers\alcxwdm.sys
    2011-12-09 21:43 . 2008-04-14 20:33 23552 ----a-w- c:\windows\system32\wdmaud.drv
    2011-12-09 21:43 . 2008-04-13 22:49 146048 ----a-w- c:\windows\system32\drivers\portcls.sys
    2011-12-09 21:43 . 2008-04-14 20:32 4096 ----a-w- c:\windows\system32\ksuser.dll
    2011-12-09 21:43 . 2008-04-13 22:15 60160 ----a-w- c:\windows\system32\drivers\drmk.sys
    2011-12-09 21:43 . 2008-04-14 20:33 129536 ----a-w- c:\windows\system32\ksproxy.ax
    2011-12-09 21:43 . 2008-04-13 22:15 49408 ----a-w- c:\windows\system32\drivers\stream.sys
    2011-12-09 21:37 . 2006-12-08 14:20 10528768 ----a-w- c:\windows\system32\RTLCPL.exe
    2011-12-09 21:36 . 2006-11-17 04:42 577536 ----a-w- c:\windows\soundman.exe
    2011-12-09 21:36 . 2006-11-17 04:40 18804736 ----a-w- c:\windows\system32\alsndmgr.cpl
    2011-12-09 21:36 . 2006-10-18 01:53 147456 ----a-w- c:\windows\system32\RtlCPAPI.dll
    2011-12-09 21:36 . 2006-07-31 10:19 315392 ----a-w- c:\windows\alcupd.exe
    2011-12-09 21:36 . 2011-12-09 21:36 -------- d--h--w- c:\program files\InstallShield Installation Information
    2011-12-09 21:36 . 2011-12-09 21:36 -------- d-----w- c:\program files\Common Files\InstallShield
    2011-12-09 21:32 . 2011-12-09 21:32 -------- d-----w- c:\program files\Lavalys
    2011-12-09 12:28 . 2011-12-09 12:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
    2011-12-09 12:28 . 2011-12-09 12:28 -------- d-----w- c:\program files\Yuna Software
    .
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-12-06 13:32 . 2011-07-25 08:31 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-11-28 18:46 . 2011-11-28 18:46 388096 ----a-r- c:\documents and settings\Eigenaar\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2011-11-23 14:40 . 2008-04-14 20:05 1859712 ----a-w- c:\windows\system32\win32k.sys
    2011-11-08 11:58 . 2008-04-14 20:33 26112 ----a-w- c:\windows\system32\userinit.exe
    2011-11-05 19:55 . 2011-11-05 19:55 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2011-11-05 19:55 . 2011-11-05 21:12 16432 ----a-w- c:\windows\system32\lsdelete.exe
    2011-11-04 19:13 . 2008-04-14 20:32 916992 ----a-w- c:\windows\system32\wininet.dll
    2011-11-04 19:13 . 2008-04-14 20:33 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-11-04 19:13 . 2008-04-14 20:32 43520 ------w- c:\windows\system32\licmgr10.dll
    2011-11-04 11:25 . 2008-04-14 20:05 385024 ------w- c:\windows\system32\html.iec
    2011-11-03 11:06 . 2011-11-05 19:46 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2011-11-01 16:07 . 2008-04-14 20:32 1288192 ----a-w- c:\windows\system32\ole32.dll
    2011-10-28 05:32 . 2008-04-14 20:32 33280 ----a-w- c:\windows\system32\csrsrv.dll
    2011-10-26 10:50 . 2008-04-14 22:11 2031616 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2011-10-26 10:50 . 2008-04-14 20:11 2153472 ----a-w- c:\windows\system32\ntoskrnl.exe
    2011-10-18 11:13 . 2008-04-14 20:32 186880 ----a-w- c:\windows\system32\encdec.dll
    2011-10-10 14:22 . 2011-07-01 12:17 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-12-21 08:02 . 2012-01-03 12:02 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"="c:\program files\Steam\Steam.exe" [2011-03-16 1242448]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
    "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
    "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
    "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
    "AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
    "PlusService"="c:\program files\Yuna Software\Messenger Plus!\PlusService.exe" [2011-10-24 801792]
    "SoundMan"="SOUNDMAN.EXE" [2006-11-17 577536]
    "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Raptr\\raptr.exe"=
    "c:\\Program Files\\Raptr\\raptr_im.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
    "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Steam\\Steam.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5985:TCP"= 5985:TCP:*isabled:Windows Remote Management
    .
    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5-11-2011 20:46 64512]
    R2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [21-10-2011 15:23 196176]
    R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [13-10-2011 17:21 249648]
    R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [3-1-2012 21:28 652872]
    R2 thdudf;TOSHIBA UDF2.5 Reader File System Driver;c:\windows\system32\drivers\thdudf.sys [5-8-2011 11:10 66944]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [3-1-2012 21:28 20464]
    S2 gupdate;Google Update-service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [14-12-2011 22:00 136176]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3-11-2011 12:06 2152152]
    S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [14-12-2011 22:00 136176]
    S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [3-11-2011 12:06 15232]
    S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19-2-2010 13:37 517096]
    S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14-4-2008 21:33 14336]
    .
    --- Andere Services/Drivers In Geheugen ---
    .
    *NewlyCreated* - WS2IFSL
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    WINRM REG_MULTI_SZ WINRM
    .
    Inhoud van de 'Gedeelde Taken' map
    .
    2012-01-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-11-03 11:06]
    .
    2011-12-10 c:\windows\Tasks\AdobeAAMUpdater-1.0-EIGENAAR-317372-Eigenaar.job
    - c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-11-19 16:42]
    .
    2012-01-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-12-14 21:00]
    .
    2012-01-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-12-14 21:00]
    .
    2012-01-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-1343024091-842925246-1003Core.job
    - c:\documents and settings\Eigenaar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-05 15:13]
    .
    2012-01-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-1343024091-842925246-1003UA.job
    - c:\documents and settings\Eigenaar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-05 15:13]
    .
    2012-01-04 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
    - c:\program files\Ask.com\UpdateTask.exe [2011-12-14 14:51]
    .
    2012-01-04 c:\windows\Tasks\User_Feed_Synchronization-{5CF0C4B7-08F8-4A8D-BCD7-43061D0B4870}.job
    - c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
    .
    .
    ------- Bijkomende Scan -------
    .
    uStart Page = hxxp://google.nl/
    uInternet Settings,ProxyOverride = *.local
    IE: Free YouTube to MP3 Converter - c:\documents and settings\Eigenaar\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
    TCP: DhcpNameServer = 192.168.0.1
    FF - ProfilePath - c:\documents and settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\5d4anoja.default\
    FF - prefs.js: browser.search.selectedEngine - Ask.com
    FF - prefs.js: browser.startup.homepage - google.nl
    FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ORJ&o=100000027&locale=nl_NL&apn_uid=9BB74CA9-76DC-4288-8B79-CE82877AB528&apn_ptnrs=U3&apn_sauid=28E8B6BF-CF02-4400-AB06-7C1395278C9B&apn_dtid=OSJ000YYNL&&q=
    .
    - - - - ORPHANS VERWIJDERD - - - -
    .
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-01-04 21:16
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scannen van verborgen processen ...
    .
    scannen van verborgen autostart items ...
    .
    scannen van verborgen bestanden ...
    .
    Scan succesvol afgerond
    verborgen bestanden: 0
    .
    **************************************************************************
    .
    --------------------- DLLs Geladen Onder Lopende Processen ---------------------
    .
    - - - - - - - > 'explorer.exe'(1152)
    c:\progra~1\WINDOW~2\wmpband.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Andere Aktieve Processen ------------------------
    .
    c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\SOUNDMAN.EXE
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Voltooingstijd: 2012-01-04 21:20:30 - machine werd herstart
    ComboFix-quarantined-files.txt 2012-01-04 20:20
    .
    Pre-Run: 33.938.804.736 bytes beschikbaar
    Post-Run: 33.900.425.216 bytes beschikbaar
    .
    WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    UnsupportedDebug="do not select this" /debug
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
    C:\wubildr.mbr = "Ubuntu"
    .
    - - End Of File - - 50C8F2F76F780FB98795300944165013



    --------------------------------------------------------------------------------------------

    Gelijk even het Hijack logje erbij (voor de zekerheid )

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 21:23:34, on 4-1-2012
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Microsoft\BingBar\BBSvc.EXE
    C:\Program Files\Microsoft\BingBar\SeaPort.EXE
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.nl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
    O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    O4 - HKLM\..\Run: [PlusService] C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Eigenaar\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
    O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1309523576375
    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
    O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

    --
    End of file - 6871 bytes

    Groeten

    Sierra^
    Wie zonder zonde is werpe de eerste steen.

  4. #4
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    Open Kladblok, kopieer en plak het volgende (vetgedrukte, blauwe tekst) in een leeg venster:



    Firefox::
    FF - ProfilePath - c:\documents and settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\5d4anoja.default\
    FF - prefs.js: browser.search.selectedEngine -
    FF - prefs.js: keyword.URL -





    Sla dit op op je Bureaublad als CFScript.txt.


    Sleep CFScript.txt in ComboFix.exe zoals getoond in onderstaand voorbeeld :



    Dit zal ComboFix doen herstarten.


    Na het herstarten van je computer, (indien het vraagt om te herstarten), kopieer en plak de inhoud van Combofix.txt in je volgende antwoord.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



  5. #5

    Ingeschreven
    Nov 2005
    Locatie
    Holland
    Leeftijd
    21
    Berichten
    1.065
    ComboFix 12-01-05.01 - Eigenaar 05-01-2012 21:54:04.2.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.1022.607 [GMT 1:00]
    Gestart vanuit: c:\documents and settings\Eigenaar\Bureaublad\ComboFix.exe
    gebruikte Opdracht switches :: c:\documents and settings\Eigenaar\Bureaublad\CFScript.txt
    AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
    .
    .
    (((((((((((((((((((( Bestanden Gemaakt van 2011-12-05 to 2012-01-05 ))))))))))))))))))))))))))))))
    .
    .
    2012-01-03 20:28 . 2012-01-03 20:28 -------- d-----w- c:\documents and settings\Eigenaar\Application Data\Malwarebytes
    2012-01-03 20:28 . 2012-01-03 20:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2012-01-03 20:28 . 2012-01-03 20:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2012-01-03 20:28 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-01-02 17:37 . 2012-01-05 20:43 -------- d--h--r- c:\documents and settings\Eigenaar\Onlangs geopend
    2011-12-23 14:21 . 2011-12-23 14:21 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
    2011-12-14 21:00 . 2011-12-14 21:04 -------- d-----w- c:\program files\Google
    2011-12-10 11:35 . 2011-12-10 11:36 -------- d-----w- c:\program files\Realtek AC97
    2011-12-09 21:43 . 2006-08-01 14:02 49152 ----a-w- c:\windows\system32\ChCfg.exe
    2011-12-09 21:43 . 2008-04-13 22:46 141056 ----a-w- c:\windows\system32\drivers\ks.sys
    2011-12-09 21:43 . 2006-12-29 13:48 4026112 ----a-r- c:\windows\system32\drivers\alcxwdm.sys
    2011-12-09 21:43 . 2008-04-14 20:33 23552 ----a-w- c:\windows\system32\wdmaud.drv
    2011-12-09 21:43 . 2008-04-13 22:49 146048 ----a-w- c:\windows\system32\drivers\portcls.sys
    2011-12-09 21:43 . 2008-04-14 20:32 4096 ----a-w- c:\windows\system32\ksuser.dll
    2011-12-09 21:43 . 2008-04-13 22:15 60160 ----a-w- c:\windows\system32\drivers\drmk.sys
    2011-12-09 21:43 . 2008-04-14 20:33 129536 ----a-w- c:\windows\system32\ksproxy.ax
    2011-12-09 21:43 . 2008-04-13 22:15 49408 ----a-w- c:\windows\system32\drivers\stream.sys
    2011-12-09 21:37 . 2006-12-08 14:20 10528768 ----a-w- c:\windows\system32\RTLCPL.exe
    2011-12-09 21:36 . 2006-11-17 04:42 577536 ----a-w- c:\windows\soundman.exe
    2011-12-09 21:36 . 2006-11-17 04:40 18804736 ----a-w- c:\windows\system32\alsndmgr.cpl
    2011-12-09 21:36 . 2006-10-18 01:53 147456 ----a-w- c:\windows\system32\RtlCPAPI.dll
    2011-12-09 21:36 . 2006-07-31 10:19 315392 ----a-w- c:\windows\alcupd.exe
    2011-12-09 21:36 . 2011-12-09 21:36 -------- d--h--w- c:\program files\InstallShield Installation Information
    2011-12-09 21:36 . 2011-12-09 21:36 -------- d-----w- c:\program files\Common Files\InstallShield
    2011-12-09 21:32 . 2011-12-09 21:32 -------- d-----w- c:\program files\Lavalys
    2011-12-09 12:28 . 2011-12-09 12:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
    2011-12-09 12:28 . 2011-12-09 12:28 -------- d-----w- c:\program files\Yuna Software
    .
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-12-06 13:32 . 2011-07-25 08:31 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-11-28 18:46 . 2011-11-28 18:46 388096 ----a-r- c:\documents and settings\Eigenaar\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2011-11-23 14:40 . 2008-04-14 20:05 1859712 ----a-w- c:\windows\system32\win32k.sys
    2011-11-08 11:58 . 2008-04-14 20:33 26112 ----a-w- c:\windows\system32\userinit.exe
    2011-11-05 19:55 . 2011-11-05 19:55 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2011-11-05 19:55 . 2011-11-05 21:12 16432 ----a-w- c:\windows\system32\lsdelete.exe
    2011-11-04 19:13 . 2008-04-14 20:32 916992 ----a-w- c:\windows\system32\wininet.dll
    2011-11-04 19:13 . 2008-04-14 20:33 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-11-04 19:13 . 2008-04-14 20:32 43520 ------w- c:\windows\system32\licmgr10.dll
    2011-11-04 11:25 . 2008-04-14 20:05 385024 ------w- c:\windows\system32\html.iec
    2011-11-03 11:06 . 2011-11-05 19:46 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2011-11-01 16:07 . 2008-04-14 20:32 1288192 ----a-w- c:\windows\system32\ole32.dll
    2011-10-28 05:32 . 2008-04-14 20:32 33280 ----a-w- c:\windows\system32\csrsrv.dll
    2011-10-26 10:50 . 2008-04-14 22:11 2031616 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2011-10-26 10:50 . 2008-04-14 20:11 2153472 ----a-w- c:\windows\system32\ntoskrnl.exe
    2011-10-18 11:13 . 2008-04-14 20:32 186880 ----a-w- c:\windows\system32\encdec.dll
    2011-10-10 14:22 . 2011-07-01 12:17 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-12-21 08:02 . 2012-01-03 12:02 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2012-01-04_20.16.32 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2012-01-05 06:25 . 2012-01-05 06:25 16384 c:\windows\Temp\Perflib_Perfdata_73c.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"="c:\program files\Steam\Steam.exe" [2011-03-16 1242448]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
    "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
    "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
    "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
    "AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
    "PlusService"="c:\program files\Yuna Software\Messenger Plus!\PlusService.exe" [2011-10-24 801792]
    "SoundMan"="SOUNDMAN.EXE" [2006-11-17 577536]
    "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Raptr\\raptr.exe"=
    "c:\\Program Files\\Raptr\\raptr_im.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
    "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Steam\\Steam.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5985:TCP"= 5985:TCP:*isabled:Windows Remote Management
    .
    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5-11-2011 20:46 64512]
    R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [13-10-2011 17:21 249648]
    R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [3-1-2012 21:28 652872]
    R2 thdudf;TOSHIBA UDF2.5 Reader File System Driver;c:\windows\system32\drivers\thdudf.sys [5-8-2011 11:10 66944]
    R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [3-11-2011 12:06 15232]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [3-1-2012 21:28 20464]
    S2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [21-10-2011 15:23 196176]
    S2 gupdate;Google Update-service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [14-12-2011 22:00 136176]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3-11-2011 12:06 2152152]
    S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [14-12-2011 22:00 136176]
    S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19-2-2010 13:37 517096]
    S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14-4-2008 21:33 14336]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    WINRM REG_MULTI_SZ WINRM
    .
    Inhoud van de 'Gedeelde Taken' map
    .
    2012-01-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-11-03 11:06]
    .
    2011-12-10 c:\windows\Tasks\AdobeAAMUpdater-1.0-EIGENAAR-317372-Eigenaar.job
    - c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-11-19 16:42]
    .
    2012-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-12-14 21:00]
    .
    2012-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-12-14 21:00]
    .
    2012-01-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-1343024091-842925246-1003Core.job
    - c:\documents and settings\Eigenaar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-05 15:13]
    .
    2012-01-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-1343024091-842925246-1003UA.job
    - c:\documents and settings\Eigenaar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-05 15:13]
    .
    2012-01-05 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
    - c:\program files\Ask.com\UpdateTask.exe [2011-12-14 14:51]
    .
    2012-01-05 c:\windows\Tasks\User_Feed_Synchronization-{5CF0C4B7-08F8-4A8D-BCD7-43061D0B4870}.job
    - c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
    .
    .
    ------- Bijkomende Scan -------
    .
    uStart Page = hxxp://google.nl/
    uInternet Settings,ProxyOverride = *.local
    IE: Free YouTube to MP3 Converter - c:\documents and settings\Eigenaar\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
    TCP: DhcpNameServer = 192.168.0.1
    FF - ProfilePath - c:\documents and settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\5d4anoja.default\
    FF - prefs.js: browser.startup.homepage - google.nl
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-01-05 22:00
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scannen van verborgen processen ...
    .
    scannen van verborgen autostart items ...
    .
    scannen van verborgen bestanden ...
    .
    Scan succesvol afgerond
    verborgen bestanden: 0
    .
    **************************************************************************
    .
    --------------------- DLLs Geladen Onder Lopende Processen ---------------------
    .
    - - - - - - - > 'winlogon.exe'(780)
    c:\windows\system32\igfxsrvc.dll
    c:\windows\system32\hccutils.DLL
    .
    - - - - - - - > 'explorer.exe'(436)
    c:\progra~1\WINDOW~2\wmpband.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Voltooingstijd: 2012-01-05 22:02:37
    ComboFix-quarantined-files.txt 2012-01-05 21:02
    ComboFix2.txt 2012-01-04 20:20
    .
    Pre-Run: 33.832.722.432 bytes beschikbaar
    Post-Run: 33.855.582.208 bytes beschikbaar
    .
    - - End Of File - - 2EFEE17E11F2788E3F3766E98A4854B3


    Groeten

    Sierra^
    Wie zonder zonde is werpe de eerste steen.

  6. #6
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    Nog klachten ?
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



  7. #7

    Ingeschreven
    Nov 2005
    Locatie
    Holland
    Leeftijd
    21
    Berichten
    1.065
    Nooo! Hartelijk bedankt voor de gedane moeite, zou het zelf nooit voor mekaar gekregen hebben.
    Dit scheelt wel vergeleken met je PC formatteren en backups maken.

    Dankuwel en een prettig weekend toegewenst.

    Groeten

    Sierra^
    Wie zonder zonde is werpe de eerste steen.

  8. #8
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    Verwijder ComboFix, kopiëer het onderstaande commando met (Ctrl + C):
    Combofix /Uninstall (let op!!! de spatie voor /Uninstall)

    Klik Start -> Uitvoeren, en plak (Ctrl + V) het commando, toets vervolgens Ctrl + Shift + Enter.
    Dit verwijdert zowel ComboFix, als je oude systeemherstelpunten (met eventuele restanten van malware), en maakt een nieuw systeemherstelpunt aan.


    Ccleaner
    Download CCleaner Slim
    Installeer CCleaner en start CCleaner op.

    • Klik in de linkse kolom op Cleaner.
    • Klik achtereenvolgens op Analyseren en Opschonen.
    • Klik vervolgens in de linkse kolom op Register en klik op Scan naar problemen.
    • Als er fouten gevonden worden klik je op Herstel geselecteerde problemen en OK.
    • Dan krijg je de vraag om een back-up te maken, klik op JA. en kies dan Herstel alle geselecteerde fouten.
    • Sluit hierna CCleaner af.


    Om herbesmetting te vermijden, kan je deze tips eens nalezen:
    Hoe voorkom ik een nieuwe infectie?
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



  9. #9

    Ingeschreven
    Nov 2005
    Locatie
    Holland
    Leeftijd
    21
    Berichten
    1.065
    Hallo Juisterrr,

    Ik moet helaas bekennen dat internet en het besturingssysteem zelf, vaak blijven hangen.
    het hijack-logje:

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 8:49:14, on 9-1-2012
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Microsoft\BingBar\SeaPort.EXE
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.nl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
    O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    O4 - HKLM\..\Run: [PlusService] C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Eigenaar\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
    O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1309523576375
    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
    O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

    --
    End of file - 6784 bytes

    Groeten

    Sierra^
    Wie zonder zonde is werpe de eerste steen.

  10. #10
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    Download LopSD naar je Bureaublad
    • Kies Optie N en Enter
    • Klik OK bij het informatie venter
    • Kies Optie 2 (Fix + Hosts), en Enter
    • Aan het eind verschijnt een log ( LopR.txt ) plaats de inhoud ervan in je volgende antwoord
    Vista gebruikers:rechtsklik op LopSD en kies voor "Als Administrator uitvoeren”
    Note:LopSD wordt door sommige virusscanners als virus gezien,deactiveer daarom je scanner
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



  11. #11

    Ingeschreven
    Nov 2005
    Locatie
    Holland
    Leeftijd
    21
    Berichten
    1.065
    Ik hoop dat ik het goede logje plaats want hij kwam niet in beeld nadat hij klaar was.
    Ik heb hem bij de C;// gevonden.

    Groeten

    Sierra^


    --------------------\\ Lop S&D 4.2.5-0 XP/Vista

    Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.06GHz )
    BIOS : Phoenix ROM BIOS PLUS Version 1.10 A05
    USER : Eigenaar ( Administrator )
    BOOT : Normal boot
    Antivirus : Lavasoft Ad-Watch Live! Anti-Virus (Not Activated)
    C:\ (Local Disk) - NTFS - Total:74 Go (Free:34 Go)
    D:\ (CD or DVD)
    E:\ (Local Disk) - FAT32 - Total:149 Go (Free:92 Go)

    "C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
    Option : [2] ( ma 09-01-2012|18:48 )


    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


    --------------------\\ Beschrijving van mappen in APPLIC~1

    [05-11-2011|19:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [19-11-2011|22:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [05-11-2011|19:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
    [05-11-2011|19:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
    [30-07-2011|17:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ask
    [13-08-2011|17:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallMate
    [05-11-2011|20:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
    [03-01-2012|21:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
    [14-10-2011|13:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
    [09-12-2011|13:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
    [05-11-2011|15:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [04-08-2011|13:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
    [20-11-2011|21:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\regid.1986-12.com.adobe
    [04-01-2012|20:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    [30-07-2011|17:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sun
    [01-07-2011|13:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [17-09-2011|09:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
    [04-08-2011|13:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
    [0|bestand(en)] C:\DOCUME~1\ALLUSE~1\APPLIC~1\bytes
    [20|map(pen)] C:\DOCUME~1\ALLUSE~1\APPLIC~1\bytes beschikbaar

    [19-11-2011|21:17] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
    [04-08-2011|13:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
    [0|bestand(en)] C:\DOCUME~1\DEFAUL~1\APPLIC~1\bytes
    [4|map(pen)] C:\DOCUME~1\DEFAUL~1\APPLIC~1\bytes beschikbaar

    [05-08-2011|17:31] C:\DOCUME~1\Eigenaar\APPLIC~1\.dvdcss
    [21-11-2011|13:14] C:\DOCUME~1\Eigenaar\APPLIC~1\Adobe
    [05-11-2011|21:43] C:\DOCUME~1\Eigenaar\APPLIC~1\Apowersoft
    [05-11-2011|20:40] C:\DOCUME~1\Eigenaar\APPLIC~1\Apple Computer
    [05-11-2011|16:21] C:\DOCUME~1\Eigenaar\APPLIC~1\Azureus
    [13-08-2011|22:36] C:\DOCUME~1\Eigenaar\APPLIC~1\BitTorrent
    [19-11-2011|21:18] C:\DOCUME~1\Eigenaar\APPLIC~1\com.adobe.downloadassistant.AdobeDownloadAssistant
    [04-01-2012|20:57] C:\DOCUME~1\Eigenaar\APPLIC~1\Complitly
    [17-10-2011|00:58] C:\DOCUME~1\Eigenaar\APPLIC~1\dvdcss
    [10-12-2011|12:08] C:\DOCUME~1\Eigenaar\APPLIC~1\DVDVideoSoft
    [06-11-2011|12:34] C:\DOCUME~1\Eigenaar\APPLIC~1\DVDVideoSoftIEHelpers
    [28-11-2011|19:53] C:\DOCUME~1\Eigenaar\APPLIC~1\ESET
    [04-08-2011|13:42] C:\DOCUME~1\Eigenaar\APPLIC~1\GetRightToGo
    [14-12-2011|22:05] C:\DOCUME~1\Eigenaar\APPLIC~1\Google
    [01-07-2011|13:23] C:\DOCUME~1\Eigenaar\APPLIC~1\Identities
    [25-07-2011|09:29] C:\DOCUME~1\Eigenaar\APPLIC~1\Macromedia
    [03-01-2012|21:28] C:\DOCUME~1\Eigenaar\APPLIC~1\Malwarebytes
    [28-11-2011|19:46] C:\DOCUME~1\Eigenaar\APPLIC~1\Microsoft
    [15-11-2011|21:00] C:\DOCUME~1\Eigenaar\APPLIC~1\Mozilla
    [04-08-2011|13:50] C:\DOCUME~1\Eigenaar\APPLIC~1\MSN6
    [05-08-2011|11:10] C:\DOCUME~1\Eigenaar\APPLIC~1\Pavtube
    [13-08-2011|21:36] C:\DOCUME~1\Eigenaar\APPLIC~1\Raptr
    [02-10-2011|09:19] C:\DOCUME~1\Eigenaar\APPLIC~1\Search Settings
    [30-07-2011|17:03] C:\DOCUME~1\Eigenaar\APPLIC~1\Sun
    [08-11-2011|17:58] C:\DOCUME~1\Eigenaar\APPLIC~1\U3
    [17-10-2011|21:31] C:\DOCUME~1\Eigenaar\APPLIC~1\vlc
    [31-07-2011|07:06] C:\DOCUME~1\Eigenaar\APPLIC~1\WinRAR
    [03-10-2011|07:48] C:\DOCUME~1\Eigenaar\APPLIC~1\YouTube Downloader
    [0|bestand(en)] C:\DOCUME~1\Eigenaar\APPLIC~1\bytes
    [30|map(pen)] C:\DOCUME~1\Eigenaar\APPLIC~1\bytes beschikbaar

    [05-11-2011|19:55] C:\DOCUME~1\LOCALS~1\APPLIC~1\Apple Computer
    [19-10-2011|18:09] C:\DOCUME~1\LOCALS~1\APPLIC~1\McAfee
    [30-07-2011|17:55] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
    [0|bestand(en)] C:\DOCUME~1\LOCALS~1\APPLIC~1\bytes
    [5|map(pen)] C:\DOCUME~1\LOCALS~1\APPLIC~1\bytes beschikbaar

    [01-07-2011|13:19] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
    [0|bestand(en)] C:\DOCUME~1\NETWOR~1\APPLIC~1\bytes
    [3|map(pen)] C:\DOCUME~1\NETWOR~1\APPLIC~1\bytes beschikbaar

    --------------------\\ Geplande Taken gelocaliseerd in C:\WINDOWS\Tasks

    [09-01-2012 18:05][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    [09-01-2012 08:37][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    [10-12-2011 02:00][--a------] C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-EIGENAAR-317372-Eigenaar.job
    [09-01-2012 07:42][--a------] C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
    [09-01-2012 18:46][--a------] C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
    [09-01-2012 18:29][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-1343024091-842925246-1003UA.job
    [08-01-2012 22:29][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-1343024091-842925246-1003Core.job
    [09-01-2012 18:40][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{5CF0C4B7-08F8-4A8D-BCD7-43061D0B4870}.job
    [09-01-2012 07:42][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [04-08-2004 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    --------------------\\ Beschrijving van mappen in C:\Program Files

    [19-11-2011|22:58] C:\Program Files\Adobe
    [19-11-2011|21:17] C:\Program Files\Adobe Download Assistant
    [05-11-2011|19:55] C:\Program Files\Apple Software Update
    [05-11-2011|22:12] C:\Program Files\Application Updater
    [04-01-2012|20:57] C:\Program Files\Ask.com
    [05-11-2011|19:54] C:\Program Files\Bonjour
    [05-11-2011|16:19] C:\Program Files\CCleaner
    [15-11-2011|20:46] C:\Program Files\CleanUp!
    [05-01-2012|21:58] C:\Program Files\Common Files
    [14-08-2011|08:51] C:\Program Files\CommViewWiFi
    [28-08-2011|13:10] C:\Program Files\Complitly
    [01-07-2011|13:17] C:\Program Files\ComPlus Applications
    [05-11-2011|15:07] C:\Program Files\DIFX
    [31-07-2011|07:06] C:\Program Files\FreeTime
    [14-12-2011|22:04] C:\Program Files\Google
    [09-12-2011|22:36] C:\Program Files\InstallShield Installation Information
    [15-12-2011|00:30] C:\Program Files\Internet Explorer
    [05-11-2011|19:56] C:\Program Files\iPod
    [05-11-2011|19:57] C:\Program Files\iTunes
    [26-10-2011|13:20] C:\Program Files\Java
    [09-12-2011|22:32] C:\Program Files\Lavalys
    [05-11-2011|20:46] C:\Program Files\Lavasoft
    [02-10-2011|20:41] C:\Program Files\Makayama Interactive
    [03-01-2012|21:28] C:\Program Files\Malwarebytes' Anti-Malware
    [01-07-2011|13:44] C:\Program Files\Messenger
    [23-12-2011|15:20] C:\Program Files\Microsoft
    [01-07-2011|13:20] C:\Program Files\microsoft frontpage
    [14-10-2011|13:01] C:\Program Files\Microsoft Silverlight
    [17-09-2011|09:23] C:\Program Files\Microsoft SQL Server Compact Edition
    [17-09-2011|09:24] C:\Program Files\Microsoft Sync Framework
    [01-07-2011|14:25] C:\Program Files\Movie Maker
    [03-01-2012|13:02] C:\Program Files\Mozilla Firefox
    [01-07-2011|14:46] C:\Program Files\MSBuild
    [01-07-2011|13:16] C:\Program Files\MSN Gaming Zone
    [01-07-2011|13:18] C:\Program Files\NetMeeting
    [01-07-2011|13:18] C:\Program Files\Online Services
    [01-07-2011|14:26] C:\Program Files\Outlook Express
    [23-10-2011|23:42] C:\Program Files\PokerStars
    [13-08-2011|18:09] C:\Program Files\Raptr
    [10-12-2011|12:36] C:\Program Files\Realtek AC97
    [01-07-2011|14:46] C:\Program Files\Reference Assemblies
    [24-08-2011|06:49] C:\Program Files\RocketDock
    [06-11-2011|11:42] C:\Program Files\Spybot - Search & Destroy
    [05-01-2012|07:27] C:\Program Files\Steam
    [28-11-2011|19:46] C:\Program Files\Trend Micro
    [01-07-2011|13:23] C:\Program Files\Uninstall Information
    [30-07-2011|17:16] C:\Program Files\VideoLAN
    [26-12-2011|22:49] C:\Program Files\Windows Live
    [17-09-2011|09:21] C:\Program Files\Windows Live SkyDrive
    [01-07-2011|14:43] C:\Program Files\Windows Media Connect 2
    [01-07-2011|14:43] C:\Program Files\Windows Media Player
    [01-07-2011|13:16] C:\Program Files\Windows NT
    [01-07-2011|13:18] C:\Program Files\WindowsUpdate
    [31-07-2011|07:05] C:\Program Files\WinRAR
    [01-07-2011|13:20] C:\Program Files\xerox
    [02-10-2011|09:18] C:\Program Files\YouTube Downloader Toolbar
    [09-12-2011|13:28] C:\Program Files\Yuna Software
    [0|bestand(en)] C:\Program Files\bytes
    [59|map(pen)] C:\Program Files\bytes beschikbaar

    --------------------\\ Beschrijving van mappen in C:\Program Files\Common Files

    [19-11-2011|22:58] C:\Program Files\Common Files\Adobe
    [19-11-2011|21:17] C:\Program Files\Common Files\Adobe AIR
    [05-11-2011|19:56] C:\Program Files\Common Files\Apple
    [10-12-2011|12:20] C:\Program Files\Common Files\DVDVideoSoft
    [09-12-2011|22:36] C:\Program Files\Common Files\InstallShield
    [26-10-2011|13:21] C:\Program Files\Common Files\Java
    [18-09-2011|19:29] C:\Program Files\Common Files\Microsoft Shared
    [01-07-2011|13:18] C:\Program Files\Common Files\MSSoap
    [01-07-2011|15:11] C:\Program Files\Common Files\ODBC
    [01-07-2011|13:18] C:\Program Files\Common Files\Services
    [01-07-2011|15:11] C:\Program Files\Common Files\SpeechEngines
    [02-10-2011|09:18] C:\Program Files\Common Files\Spigot
    [17-11-2011|23:36] C:\Program Files\Common Files\Steam
    [01-07-2011|13:17] C:\Program Files\Common Files\System
    [17-09-2011|09:10] C:\Program Files\Common Files\Windows Live
    [0|bestand(en)] C:\Program Files\Common Files\bytes
    [17|map(pen)] C:\Program Files\Common Files\bytes beschikbaar

    --------------------\\ Process

    ( 36 Processes )

    ... OK !

    --------------------\\ Zoeken met S_Lop

    Geen Lop mappen gevonden !

    --------------------\\ Zoeken naar Lop Bestanden - Mappen

    Geen Lop mappen gevonden !

    --------------------\\ Zoeken doorheen het Register

    ..... OK !

    --------------------\\ Nazicht van het Hosts bestand

    Hosts bestand IN ORDE


    --------------------\\ Zoeken naar verborgen bestanden met Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-01-09 18:54:18
    Windows 5.1.2600 Service Pack 3 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 0

    --------------------\\ Zoeken naar andere infecties


    Geen andere infecties gevonden !

    [F:11][D:7]-> C:\DOCUME~1\Eigenaar\LOCALS~1\Temp
    [F:35][D:0]-> C:\DOCUME~1\Eigenaar\Cookies
    [F:114][D:4]-> C:\DOCUME~1\Eigenaar\LOCALS~1\TEMPOR~1\content.IE5

    1 - "C:\Lop SD\LopR_1.txt" - ma 09-01-2012|18:56 - Option : [2]

    --------------------\\ Scan voltooid om 18:56:27
    Wie zonder zonde is werpe de eerste steen.

  12. #12
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    Hoe gaat het nu ?
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



  13. #13

    Ingeschreven
    Nov 2005
    Locatie
    Holland
    Leeftijd
    21
    Berichten
    1.065
    Goed als de computer weer vaag gaat doen laat ik het weten..
    Bedankt voor de moeite kerel, meen ik echt, scheelt nogal wat vergeleken met formatteren..!!!!!!!!!

    Groeten

    Sierra^
    Wie zonder zonde is werpe de eerste steen.

  14. #14
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    Graag gedaan hoor.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



+ Plaats een Reactie

Forum Rechten

  • Je mag geen nieuwe onderwerpen plaatsen
  • Je mag geen reacties plaatsen
  • Je mag geen bijlagen toevoegen
  • Je mag jouw berichten niet wijzigen

SEO by vBSEO 3.5.1