coolwwwsearch

  • sonja

    Logfile of HijackThis v1.99.1

    Scan saved at 22:09:36, on 26-10-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Fujitsu Siemens Computers\Odyssey Client for Fujitsu Siemens Computers\odClientService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe

    C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE

    C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe

    C:\WINDOWS\System32\igfxtray.exe

    C:\WINDOWS\System32\hkcmd.exe

    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe

    C:\Program Files\Fujitsu Siemens Computers\Odyssey Client for Fujitsu Siemens Computers\OdTray.exe

    C:\Program Files\Launch Manager\LaunchAp.exe

    C:\Program Files\Launch Manager\HotkeyApp.exe

    C:\Program Files\Launch Manager\CtrlVol.exe

    C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe

    C:\Program Files\Launch Manager\Wbutton.exe

    C:\Program Files\MessengerPlus! 3\MsgPlus.exe

    C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Documents and Settings\Sonja\Mijn documenten\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startkabel.nl/

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startkabel.nl

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

    O2 - BHO: (no name) - {4ED59D0D-9C5B-315A-B286-C2A2D25822C6} - (no file)

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll

    O4 - HKLM\..\Run: C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe

    O4 - HKLM\..\Run: C:\WINDOWS\System32\igfxtray.exe

    O4 - HKLM\..\Run: C:\WINDOWS\System32\hkcmd.exe

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”

    O4 - HKLM\..\Run: C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup

    O4 - HKLM\..\Run: “C:\Program Files\Fujitsu Siemens Computers\Odyssey Client for Fujitsu Siemens Computers\OdTray.exe”

    O4 - HKLM\..\Run: C:\Program Files\Launch Manager\LaunchAp.exe

    O4 - HKLM\..\Run: C:\Program Files\Launch Manager\HotkeyApp.exe

    O4 - HKLM\..\Run: C:\Program Files\Launch Manager\CtrlVol.exe

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\Wbutton.exe”

    O4 - HKLM\..\Run: C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

    O4 - HKLM\..\Run: “C:\Program Files\MessengerPlus! 3\MsgPlus.exe”

    O4 - HKLM\..\Run: C:\Documents and Settings\All Users.WINDOWS\Application Data\4ElseDupeLies\For Logo.exe

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll

    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL

    O9 - Extra ‘Tools’ menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll

    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

    O15 - Trusted Zone: http://www.loonaangifte2006.nl

    O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab

    O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab

    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab

    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab

    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab

    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab

    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab

    O17 - HKLM\System\CCS\Services\Tcpip\..\{3CAB5CC3-F156-43C5-9339-1B13535B7EC5}: NameServer = 192.160.0.1

    O17 - HKLM\System\CS1\Services\Tcpip\..\{3CAB5CC3-F156-43C5-9339-1B13535B7EC5}: NameServer = 192.160.0.1

    O20 - AppInit_DLLs: MsgPlusLoader.dll

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe

    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

    O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE

    O23 - Service: Odyssey Client (odClientService) - Funk Software, Inc. - C:\Program Files\Fujitsu Siemens Computers\Odyssey Client for Fujitsu Siemens Computers\odClientService.exe

    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE

    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

  • Avondsmurf

    Wat zijn de klachten, welke problemen loop je tegenaan?…………..Smurfie :)

  • Jahewi

    Hoi Sonja,

    Blijkbaar kwam gisteren niemand meer toe aan de behandeling van je probleem :?;)

    Zou je, voordat we je computer gaan opruimen, even het volgende willen doen?

    Open kladblok.

    Kopieer de twee onderstaande, vetgedrukte regels en plak dit in het kladblokvenster.

    Sla het nieuwe kladblok-bestand op, op je bureaublad, als FindTasks.bat, als type bestand Alle bestanden:

    dir %Windir%\tasks /a:h > FindTasks.txt

    notepad FindTasks.txt

    Sluit kladblok daarna weer.

    Dubbelklik op het bestand FindTasks.bat, dat op je bureaublad staat. Hierdoor wordt kladblok geopend met daarin wat tekst.

    Kopieer deze hele tekst naar dit onderwerp.

    suk6, Jan :)

  • wollie

    Zie andere topic Jan :)

    Wollie

  • jahewi

    Mogge, Wolksen :D

    Viel me pas op, toen ik de mijne al had geplaatst ….

    Ik denk trouwens niet dat alleen Msg+ deinstalleren is voldoende :? :+

    Jan :)

  • wollie

    jahewi schreef:

    >

    > Mogge, Wolksen :D

    >

    > Viel me pas op, toen ik de mijne al had geplaatst ….

    > Ik denk trouwens niet dat alleen Msg+ deinstalleren is

    > voldoende :? :+

    >

    Nee ik denk het ook niet. Ik denk dat tenminste nodig is dat Sonja weer reageert :D:D:+

  • pavlov

    wollie schreef:

    >

    > Zie andere topic Jan :)

    Had ik een linkje over geplaats maar dat is ook weggehaald. :(:(:(

    Als het hier nu beredruk zou zijn, zou ik het nog wel begrijpen dat je reacties binnen 24 uur zijn weggehaald, maar dit haalt bij mij de lol dus wel aardig weg…