opschonen laptop

cowboyhenk
16 Nov, 2012 19:41

Goedenavond,

ben mijn laptop aan het opschonen.

Hij is in de loop der tijd wat langzaam geworden.

Heb inmiddels alle opschoonstappen doorlopen en wil jullie vragen eens kritisch naar mijn rapporten te kijken.

Bij voorbaat dank.

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 19:30:21, on 16-11-2012

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v9.00 (9.00.8112.16455)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Windows\Explorer.EXE

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe

C:\Program Files\WinZip\WZQKPICK32.EXE

C:\Windows\ehome\ehmsas.exe

C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Windows\system32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.glarysoft.com/?src=iehome

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.glarysoft.com/?src=newtab

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.glarysoft.com/?src=iehome

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.glarysoft.com/?src=iehome

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: (no name) - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - (no file)

O1 - Hosts: ::1 localhost

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O2 - BHO: TBSB05810 - {A7AF277D-1466-4A7B-93AF-B043984A5671} - C:\Program Files\Glarysoft Toolbar\tbcore3.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll

O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O3 - Toolbar: Glarysoft Toolbar - {32D47EA5-9473-4CAD-805D-9999F15D5AE2} - C:\Program Files\Glarysoft Toolbar\tbcore3.dll

O4 - HKLM\..\Run: “C:\Program Files\AVAST Software\Avast\avastUI.exe” /nogui

O4 - HKLM\..\Run: %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: RtHDVCpl.exe

O4 - HKLM\..\Run: NDSTray.exe

O4 - HKLM\..\Run: “C:\Program Files\QuickTime\QTTask.exe” -atboottime

O4 - HKLM\..\Run: “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

O4 - HKLM\..\RunOnce: “C:\Windows\is-EJNOD.exe” /REG /REGSVRMODE

O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: C:\Windows\ehome\ehTray.exe

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?NL (file missing)

O11 - Options group: Accelerated graphics

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe

O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

End of file - 8247 bytes

Malwarebytes Anti-Malware 1.65.1.1000

www.malwarebytes.org

Databaseversie: v2012.11.16.08

Windows Vista Service Pack 2 x86 NTFS

Internet Explorer 9.0.8112.16421

Reny :: LAPTOPVANRENY

16-11-2012 19:13:38

mbam-log-2012-11-16 (19-13-38).txt

Scantype: Snelle scan

Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

Uitgeschakelde scanopties: P2P

Objecten gescand: 199761

Verstreken tijd: 8 minuut/minuten, 28 seconde(n)

Geheugenprocessen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registersleutels gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registerwaarden gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registerdata gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Mappen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Bestanden gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

(einde)

Bewerkt 29 Nov, 2012 15:34
fazantje
16 Nov, 2012 20:46

Hoi Erik,

Ik zie dat je Glarysoft op je laptop hebt staan en daar zijn de meningen nogal over verdeeld.

Dat programma wordt aangegeven als “open to debate”.

Ik zeg dan, als je het niet speciaal nodig hebt, verwijder deze dan.

Start HijackThis, klik op scan en vink de volgende regel aan:

R3 - URLSearchHook: (no name) - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - (no file)

Sluit alle openstaande vensters, behalve HijackThis en klik op Fix Checked.

Download hier AdwCleaner by Xplode naar je Bureaublad.

Sluit alle openstaande vensters.

Vista en Windows 7 gebruikers: Rechtsklik op AdwCleaner en selecteer als Administrator uitvoeren…

Voor XP: Gewoon dubbelklikken op AdwCleaner.

Klik vervolgens op Verwijderen.

Klik bij AdwCleaner – Informatie op OK

Klik bij AdwCleaner – Herstarten Noodzakelijk op OK

Dat tijdens de aktie de snelkoppelingen verdwijnen, is normaal.

Nadat de PC opnieuw is opgestart, opent een logfile.

Post dit logje samen met een nieuw HijackThis logje in je volgende bericht.

Succes,

Huib;)

cowboyhenk
16 Nov, 2012 21:16

Huib,

bedankt voor je hulp en suggesties.

Hier het logje

# AdwCleaner v2.007 - Verslag gemaakt op 16/11/2012 om 21:10:23

# Geactualiseerd op 06/11/2012 door Xplode

# Besturingssysteem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)

# Gebruiker : Reny - LAPTOPVANRENY

# Opstarten Modus : Normale modus

# Gelanceerd vanaf : C:\Users\Reny\Desktop\adwcleaner.exe

# Optie

***** *****

***** *****

File Verwijdert : C:\Windows\system32\conduitEngine.tmp

Map Verwijdert : C:\Users\Reny\AppData\Local\Conduit

Map Verwijdert : C:\Users\Reny\AppData\LocalLow\Conduit

***** *****

Sleutel Verwijdert : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}

Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}

Sleutel Verwijdert : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}

Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}

Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}

Sleutel Verwijdert : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}

Sleutel Verwijdert : HKLM\Software\Conduit

Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}

Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}

***** *****

-\\ Internet Explorer v9.0.8112.16421

Vervangen : = hxxp://isearch.glarysoft.com/?src=iehome –> hxxp://www.google.com

Vervangen : = hxxp://isearch.glarysoft.com/?src=iehome –> hxxp://www.google.com

Vervangen : = hxxp://isearch.glarysoft.com/?src=iehome –> hxxp://www.google.com

Vervangen : = hxxp://isearch.glarysoft.com/?src=iehome –> hxxp://www.google.com

-\\ Google Chrome v

File : C:\Users\Reny\AppData\Local\Google\Chrome\User Data\Default\Preferences

De file bevat geen enkele ongeoorloofde invoer.

*************************

AdwCleaner.txt - -

########## EOF - C:\AdwCleaner.txt - ##########

fazantje
16 Nov, 2012 21:18

Hoi Erik,

Nu nog graag even een nieuw HijackThis logje, waar ik ook om vroeg.

En geef ook even antwoord op Glarysoft.

Groetjes Huib;)

cowboyhenk
16 Nov, 2012 21:35

Excuseer!

Ik heb Glarysoft meteen via het configuratiescherm van mijn laptop verwijderd.

Hier is het logje van Hijackthis

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 21:34:28, on 16-11-2012

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v9.00 (9.00.8112.16455)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Windows\system32\NOTEPAD.EXE

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe

C:\Windows\system32\Macromed\Flash\FlashUtil32_11_5_502_110_ActiveX.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE

C:\Windows\system32\prevhost.exe

C:\Windows\system32\prevhost.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HiJackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll

O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: “C:\Program Files\AVAST Software\Avast\avastUI.exe” /nogui

O4 - HKLM\..\Run: %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: RtHDVCpl.exe

O4 - HKLM\..\Run: NDSTray.exe

O4 - HKLM\..\Run: “C:\Program Files\QuickTime\QTTask.exe” -atboottime

O4 - HKLM\..\Run: “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: C:\Windows\ehome\ehTray.exe

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?NL (file missing)

O11 - Options group: Accelerated graphics

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe

O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe

O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

End of file - 7081 bytes

fazantje
16 Nov, 2012 21:42

Hoi Erik,

Download Combofix hier en plaats het op jou bureaublad.

Schakel nu eerst jou virusscanner uit. Deze gaat weer aan nadat computer opnieuw is opgestart.

Indien je Combofix al eerder hebt gebruikt, gelieve die versie te verwijderen en Combofix opnieuw te downloaden via bovenstaande link,

want Combofix wordt dagelijks geupdate.

OPMERKING: indien je, tijdens of na het downloaden van Combofix of tijdens het gebruik van Combofix een melding krijgt

van je Antivirus- of een andere realtime scanner, schakel dan deze scanner uit en download Combofix opnieuw.

Sommige scanners zien bepaalde componenten die Combofix gebruikt als verdacht en gaan deze blokkeren of verwijderen!

Dubbelklik op Combofix.exe

Volg de instructies, aanvaard de disclaimer.

Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.

De scan kan, afhankelijk van de besmetting 40 tot wel 100 minuten duren, dus denk niet van hij zit vast.

Wanneer de fix voltooid is en na herstart, zal de log combofix.txt openen.

Plaats deze log in je volgende post samen met een nieuw HijackThis log.

Groetjes Huib;)

cowboyhenk
16 Nov, 2012 22:44

ComboFix 12-11-16.02 - Reny 16-11-2012 22:20:47.1.2 - x86

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.2037.874

Gestart vanuit: c:\users\Reny\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RVJ5JDJP\ComboFix.exe

AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-10-16 to 2012-11-16 ))))))))))))))))))))))))))))))

.

.

2012-11-16 21:32 . 2012-11-16 21:33 ——– d—–w- c:\users\Reny\AppData\Local\temp

2012-11-16 21:32 . 2012-11-16 21:32 ——– d—–w- c:\users\Default\AppData\Local\temp

2012-11-16 19:00 . 2012-10-30 22:51 106560 —-a-w- c:\windows\system32\drivers\aswFW.sys

2012-11-16 18:58 . 2012-10-30 22:51 199320 —-a-w- c:\windows\system32\drivers\aswNdis2.sys

2012-11-16 18:58 . 2012-10-30 22:51 20624 —-a-w- c:\windows\system32\drivers\aswKbd.sys

2012-11-16 18:57 . 2012-09-21 09:26 12112 —-a-w- c:\windows\system32\drivers\aswNdis.sys

2012-11-16 07:20 . 2012-10-17 00:32 6918632 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2A02A0C3-511C-414E-BED3-60649B4B88BB}\mpengine.dll

2012-11-14 21:52 . 2012-10-08 07:47 1427968 —-a-w- c:\windows\system32\inetcpl.cpl

2012-11-14 16:33 . 2012-09-25 16:19 75776 —-a-w- c:\windows\system32\synceng.dll

2012-11-14 16:33 . 2012-10-12 14:29 2047488 —-a-w- c:\windows\system32\win32k.sys

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-11-16 07:06 . 2012-04-19 05:35 697272 —-a-w- c:\windows\system32\FlashPlayerApp.exe

2012-11-16 07:06 . 2011-05-18 16:19 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-10-30 22:51 . 2011-12-18 10:32 361032 —-a-w- c:\windows\system32\drivers\aswSP.sys

2012-10-30 22:51 . 2011-12-18 10:32 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys

2012-10-30 22:51 . 2011-12-18 10:32 35928 —-a-w- c:\windows\system32\drivers\aswRdr.sys

2012-10-30 22:51 . 2011-12-18 10:32 738504 —-a-w- c:\windows\system32\drivers\aswSnx.sys

2012-10-30 22:51 . 2011-12-18 10:32 58680 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys

2012-10-30 22:51 . 2011-12-18 10:32 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys

2012-10-30 22:51 . 2011-12-18 10:31 41224 —-a-w- c:\windows\avastSS.scr

2012-10-30 22:50 . 2011-12-18 10:31 227648 —-a-w- c:\windows\system32\aswBoot.exe

2012-09-13 13:28 . 2012-10-10 15:17 2048 —-a-w- c:\windows\system32\tzres.dll

2012-08-29 11:27 . 2012-10-10 15:18 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe

2012-08-29 11:27 . 2012-10-10 15:18 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe

2012-08-24 15:53 . 2012-10-10 15:17 172544 —-a-w- c:\windows\system32\wintrust.dll

2012-08-21 11:01 . 2012-10-05 08:05 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys

2012-08-21 11:01 . 2010-12-05 11:17 106928 —-a-w- c:\windows\system32\GEARAspi.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

@=“{472083B0-C522-11CF-8763-00608CC02F24}”

2012-10-30 22:50 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll

.

“WMPNSCFG”=“c:\program files\Windows Media Player\WMPNSCFG.exe”

“Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe”

“ehTray.exe”=“c:\windows\ehome\ehTray.exe”

.

“avast”=“c:\program files\AVAST Software\Avast\avastUI.exe”

“RtHDVCpl”=“RtHDVCpl.exe”

“NDSTray.exe”=“NDSTray.exe”

“QuickTime Task”=“c:\program files\QuickTime\QTTask.exe”

“Adobe ARM”=“c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

.

“EnableUIADesktopToggle”= 0 (0x0)

“EnableLinkedConnections”= 1 (0x1)

.

@=“Service”

.

backup=c:\windows\pss\Gigaset WLAN Adapter Monitor.lnk.CommonStartup

backupExtension=.CommonStartup

.

backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup

backupExtension=.CommonStartup

.

backup=c:\windows\pss\Dropbox.lnk.Startup

backupExtension=.Startup

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_TRAY

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ROC_roc_ssl_v12

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg

.

2007-01-17 12:46 534648 —-a-w- c:\program files\TOSHIBA\FlashCards\TCrdMain.exe

.

2012-07-27 20:51 919008 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

.

2007-09-10 23:43 67488 —-a-w- c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe

.

2006-09-11 14:21 180224 —-a-w- c:\program files\Apoint2K\Apoint.exe

.

2012-09-10 14:58 59280 —-a-w- c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe

.

2011-10-05 23:52 59240 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

.

2012-08-27 19:32 59280 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe

.

2007-01-19 12:25 1507328 —-a-w- c:\program files\IDM\Desktop SMS\DesktopSMS.exe

.

2009-02-26 16:36 30040 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

.

2008-02-11 19:13 166424 —-a-w- c:\windows\System32\hkcmd.exe

.

2006-12-07 15:49 55416 —-a-w- c:\program files\TOSHIBA\TBS\HSON.exe

.

2006-11-01 07:06 413696 —-a-w- c:\program files\TOSHIBA\Utilities\HWSetup.exe

.

2012-08-29 12:00 59280 —-a-w- c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe

.

2008-02-11 19:13 141848 —-a-w- c:\windows\System32\igfxtray.exe

.

2012-09-09 21:30 421776 —-a-w- c:\program files\iTunes\iTunesHelper.exe

.

2006-11-06 16:14 34352 —-a-w- c:\program files\TOSHIBA\Utilities\KeNotify.exe

.

2007-01-13 08:40 7766016 —-a-w- c:\windows\System32\nvcpl.dll

.

2007-01-13 08:40 81920 —-a-w- c:\windows\System32\nvmctray.dll

.

2007-01-13 08:40 90191 —-a-w- c:\windows\System32\nvsvc.dll

.

2008-02-11 19:13 133656 —-a-w- c:\windows\System32\igfxpers.exe

.

2012-04-18 18:56 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

.

2007-02-06 13:21 509496 —-a-w- c:\program files\TOSHIBA\SmoothView\SmoothView.exe

.

2012-01-17 10:07 252296 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

.

2006-03-22 20:42 438272 —-a-w- c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe

.

2009-03-20 06:36 1451304 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

.

2012-08-28 05:41 247768 —-a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe

.

2007-03-02 13:10 577536 —-a-w- c:\program files\TOSHIBA\Toshiba Online Product Information\TOPI.exe

.

2007-02-19 14:00 571024 —-a-w- c:\program files\TOSHIBA\Registration\ToshibaRegistration.exe

.

2006-12-19 22:16 411768 —-a-w- c:\program files\TOSHIBA\Power Saver\TPwrMain.exe

.

“DisableMonitoring”=dword:00000001

.

“DisableMonitoring”=dword:00000001

.

“DisableMonitoring”=dword:00000001

.

LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

.

Inhoud van de ‘Gedeelde Taken’ map

.

2012-11-16 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

.

2012-11-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe

.

2012-11-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe

.

.

——- Bijkomende Scan ——-

.

uStart Page = hxxp://www.google.com

mStart Page = hxxp://www.google.com

uInternet Settings,ProxyOverride = *.local

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 212.54.40.25 212.54.35.25

.

- - - - ORPHANS VERWIJDERD - - - -

.

SafeBoot-WudfPf

SafeBoot-WudfRd

MSConfigStartUp-Google Update - c:\users\Reny\AppData\Local\Google\Update\GoogleUpdate.exe

MSConfigStartUp-MobileDocuments - c:\program files\Common Files\Apple\Internet Services\ubd.exe

MSConfigStartUp-TOSCDSPD - TOSCDSPD.EXE

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2012-11-16 22:33

Windows 6.0.6002 Service Pack 2 NTFS

.

scannen van verborgen processen …

.

scannen van verborgen autostart items …

.

scannen van verborgen bestanden …

.

Scan succesvol afgerond

verborgen bestanden: 0

.

**************************************************************************

.

——————— VERGRENDELDE REGISTER SLEUTELS ———————

.

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

“BlindDial”=dword:00000000

“MSCurrentCountry”=dword:0000007b

.

Voltooingstijd: 2012-11-16 22:36:57

ComboFix-quarantined-files.txt 2012-11-16 21:36

.

Pre-Run: 93.870.043.136 bytes beschikbaar

Post-Run: 93.370.396.672 bytes beschikbaar

.

- - End Of File - - E6A0C7BAB941199643B45234FF90E9EE

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 22:40:12, on 16-11-2012

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v9.00 (9.00.8112.16455)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Windows\system32\NOTEPAD.EXE

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe

C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE

C:\Windows\system32\conime.exe

C:\Windows\explorer.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HiJackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll

O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: “C:\Program Files\AVAST Software\Avast\avastUI.exe” /nogui

O4 - HKLM\..\Run: RtHDVCpl.exe

O4 - HKLM\..\Run: NDSTray.exe

O4 - HKLM\..\Run: “C:\Program Files\QuickTime\QTTask.exe” -atboottime

O4 - HKLM\..\Run: “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: C:\Windows\ehome\ehTray.exe

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?NL (file missing)

O11 - Options group: Accelerated graphics

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe

O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe

O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

End of file - 6770 bytes

fazantje
29 Nov, 2012 15:34

Omdat er geen reactie meer volgt wordt dit topic gesloten.

Wilt U Uw topic als nog weer openen, stuur dan een prive bericht naar Ben of Huib (fazantje).

Zij zullen dan het “slotje” er van af halen en het topic is weer geopend.

Het AV team.

 

Dit topic is gesloten, er kunnen geen reacties meer worden geplaatst.