Mijn logje eindelijk!

  • Jumi

    Logfile of HijackThis v1.99.1

    Scan saved at 23:14:15, on 27-10-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\brsvc01a.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\brss01a.exe

    C:\WINDOWS\Explorer.exe

    C:\WINDOWS\services.exe

    C:\WINDOWS\SYSTEM32\Brmfrmps.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe

    C:\WINDOWS\System32\svchost.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe

    C:\windows\system\hpsysdrv.exe

    C:\HP\KBD\KBD.EXE

    C:\Program Files\Winamp\winampa.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Messenger Plus! 3\MsgPlus.exe

    C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe

    C:\Program Files\Brother\ControlCenter2\brctrcen.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\WINDOWS\system32\LVCOMSX.EXE

    C:\Program Files\Logitech\Video\LogiTray.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Skype\Phone\Skype.exe

    C:\Program Files\MSN Messenger\msnmsgr.exe

    c:\progra~1\intern~1\iexplore.exe

    C:\Program Files\Logitech\Video\FxSvr2.exe

    C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe

    C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe

    C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://klant.casema.nl/

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.cyhntxjtfq.us/EdX_0t1rlZUo3JdIc2VpeCP28ha4vZdPHWEjJzt7fUUj15eOA8korc2BC78NVcGj.jsp

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yfwjdnyyjihmhfqgxrzwme.us/EdX_0t1rlZVO9R_MEVYKlHUpLLX_WKjLlZdsCSHu4KM.html

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ne3.hpwis.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-ne3.hpwis.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-ne3.hpwis.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-ne3.hpwis.com/

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ne3.hpwis.com/

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\fservice.exe

    O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - C:\WINDOWS\mslagent\4b_1,0,1,2_mslagent.dll (file missing)

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

    O2 - BHO: (no name) - {3AF1C74D-B793-566F-F0A7-0724B63CEBCB} - C:\PROGRA~1\DALECA~1\Sect pure.exe (file missing)

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: (no name) - {613232EB-2A4D-5237-A69E-1CC272E97307} - C:\DOCUME~1\Eigenaar\APPLIC~1\DALECA~1\Sect pure.exe (file missing)

    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O4 - HKLM\..\Run: c:\windows\system\hpsysdrv.exe

    O4 - HKLM\..\Run: C:\HP\KBD\KBD.EXE

    O4 - HKLM\..\Run: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: C:\WINDOWS\System32\igfxtray.exe

    O4 - HKLM\..\Run: C:\WINDOWS\System32\hkcmd.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\ps2.exe

    O4 - HKLM\..\Run: C:\Program Files\Winamp\winampa.exe

    O4 - HKLM\..\Run: nwiz.exe /install

    O4 - HKLM\..\Run: “C:\Program Files\Messenger Plus! 3\MsgPlus.exe”

    O4 - HKLM\..\Run: C:\Documents and Settings\All Users\Application Data\for clock way ante\webmail.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe” -Embedding -boot

    O4 - HKLM\..\Run: C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe

    O4 - HKLM\..\Run: C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe

    O4 - HKLM\..\Run: C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\LVCOMSX.EXE

    O4 - HKLM\..\Run: C:\Program Files\Logitech\Video\ISStart.exe

    O4 - HKLM\..\Run: C:\Program Files\Logitech\Video\LogiTray.exe

    O4 - HKLM\..\Run: wkssvc32.exe

    O4 - HKLM\..\Run: C:\Documents and Settings\All Users\Application Data\insidecamp1active\dupe atom.exe

    O4 - HKLM\..\Run: “C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe”

    O4 - HKLM\..\RunServices: wupfyny.exe

    O4 - HKLM\..\RunServices: wkssvc32.exe

    O4 - HKCU\..\Run: wupfyny.exe

    O4 - HKCU\..\Run: RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: C:\DOCUME~1\Eigenaar\APPLIC~1\LOADSH~1\Time Stop.exe

    O4 - HKCU\..\Run: “C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized

    O4 - HKCU\..\Run: “C:\Program Files\Logitech\Video\ManifestEngine.exe” boot

    O4 - HKCU\..\Run: wkssvc32.exe

    O4 - HKCU\..\Run: “C:\Program Files\MSN Messenger\msnmsgr.exe” /background

    O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe

    O4 - Global Startup: Image Transfer.lnk = ?

    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

    O4 - Global Startup: Microsoft Office OneNote 2003 Snel Starten.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE

    O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab

    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409

    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab

    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-30.cab

    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab

    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/148119a2571ca3/housecall.antivirus.com/housecall/xscan53.cab

    O16 - DPF: {8731163E-77B9-4F91-9122-F112521C28AF} (MMSPlayerX Class) - http://212.41.157.233:8080/mmawap/jsp/composer/player/mmsPlayer.cab

    O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

    O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab

    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab

    O16 - DPF: {C2326BDF-43B0-431F-940A-52D042621188} (Dial.getdial) - http://www.mediaswitch.nl/eromedia/mediaswitch.cab

    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab

    O16 - DPF: {FE8400F2-C848-4379-989F-DF2ED39040BE} (Eyeball Instant Messaging Control) - http://www.onehello.nl/chat/RSVPChat.cab

    O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\SYSTEM32\Brmfrmps.exe" -service (file missing)

    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe

    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe

    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    ok wat moet ik nu doen?

    Ik heb inmiddels de cd van xp maar daarmee kan ik ook geen systeem herstel doen :-(

  • Oetie

    Was handig als je dit even had vermeld…

    http://www.prikpagina.nl/read.php?f=571&i=372518&t=372518#reply_372518

    Via de buren dus ;-)

  • Piet

    ter info http://www.prikpagina.nl/read.php?f=571&i=372518&t=372518

    http://www.prikpagina.nl/read.php?f=571&i=372476&t=372476

  • Piet

    :+:+

  • Oetie

    1 minuutje piet ;-)

  • Jumi

    sorry pff ben echt nieuw hier geloof ik hihihi

  • JaapT

    Sja, met al die verwijzingen schiet het niet echt op.

  • Erik

    Download the hoster http://www.funkytoad.com/download/hoster.zip

    Unzip het programma, run het, klik op Restore Original Hosts, klik op OK en sluit het programma af.

    Download gencturkfix http://users.telenet.be/marcvn/tools/gencturkfix.exe

    Unzip het.

    Sluit alle open programma's.

    Open de map gencturkfix en dubbelklik op gencturkfix.bat.

    De computer zal herstarten. Wanneer de computer opnieuw gestart is, zie je nog even een dosschermpje verschijnen. Als dit scherm verdwijnt is het tooltje klaar en zou de rootkit moeten verdwenen zijn.

    Plaats nog even een nieuw HJT logje svp :-)

  • Jumi

    ok ga ik dat morgen even proberen!

    dit was vandaag mijn hjt log:

    Logfile of HijackThis v1.99.1

    Scan saved at 23:14:15, on 27-10-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\brsvc01a.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\brss01a.exe

    C:\WINDOWS\Explorer.exe

    C:\WINDOWS\services.exe

    C:\WINDOWS\SYSTEM32\Brmfrmps.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe

    C:\WINDOWS\System32\svchost.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe

    C:\windows\system\hpsysdrv.exe

    C:\HP\KBD\KBD.EXE

    C:\Program Files\Winamp\winampa.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Messenger Plus! 3\MsgPlus.exe

    C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe

    C:\Program Files\Brother\ControlCenter2\brctrcen.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\WINDOWS\system32\LVCOMSX.EXE

    C:\Program Files\Logitech\Video\LogiTray.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Skype\Phone\Skype.exe

    C:\Program Files\MSN Messenger\msnmsgr.exe

    c:\progra~1\intern~1\iexplore.exe

    C:\Program Files\Logitech\Video\FxSvr2.exe

    C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe

    C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe

    C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://klant.casema.nl/

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.cyhntxjtfq.us/EdX_0t1rlZUo3JdIc2VpeCP28ha4vZdPHWEjJzt7fUUj15eOA8korc2BC78NVcGj.jsp

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yfwjdnyyjihmhfqgxrzwme.us/EdX_0t1rlZVO9R_MEVYKlHUpLLX_WKjLlZdsCSHu4KM.html

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ne3.hpwis.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-ne3.hpwis.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-ne3.hpwis.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-ne3.hpwis.com/

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ne3.hpwis.com/

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\fservice.exe

    O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - C:\WINDOWS\mslagent\4b_1,0,1,2_mslagent.dll (file missing)

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

    O2 - BHO: (no name) - {3AF1C74D-B793-566F-F0A7-0724B63CEBCB} - C:\PROGRA~1\DALECA~1\Sect pure.exe (file missing)

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: (no name) - {613232EB-2A4D-5237-A69E-1CC272E97307} - C:\DOCUME~1\Eigenaar\APPLIC~1\DALECA~1\Sect pure.exe (file missing)

    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O4 - HKLM\..\Run: c:\windows\system\hpsysdrv.exe

    O4 - HKLM\..\Run: C:\HP\KBD\KBD.EXE

    O4 - HKLM\..\Run: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: C:\WINDOWS\System32\igfxtray.exe

    O4 - HKLM\..\Run: C:\WINDOWS\System32\hkcmd.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\ps2.exe

    O4 - HKLM\..\Run: C:\Program Files\Winamp\winampa.exe

    O4 - HKLM\..\Run: nwiz.exe /install

    O4 - HKLM\..\Run: “C:\Program Files\Messenger Plus! 3\MsgPlus.exe”

    O4 - HKLM\..\Run: C:\Documents and Settings\All Users\Application Data\for clock way ante\webmail.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe” -Embedding -boot

    O4 - HKLM\..\Run: C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe

    O4 - HKLM\..\Run: C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe

    O4 - HKLM\..\Run: C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\LVCOMSX.EXE

    O4 - HKLM\..\Run: C:\Program Files\Logitech\Video\ISStart.exe

    O4 - HKLM\..\Run: C:\Program Files\Logitech\Video\LogiTray.exe

    O4 - HKLM\..\Run: wkssvc32.exe

    O4 - HKLM\..\Run: C:\Documents and Settings\All Users\Application Data\insidecamp1active\dupe atom.exe

    O4 - HKLM\..\Run: “C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe”

    O4 - HKLM\..\RunServices: wupfyny.exe

    O4 - HKLM\..\RunServices: wkssvc32.exe

    O4 - HKCU\..\Run: wupfyny.exe

    O4 - HKCU\..\Run: RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: C:\DOCUME~1\Eigenaar\APPLIC~1\LOADSH~1\Time Stop.exe

    O4 - HKCU\..\Run: “C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized

    O4 - HKCU\..\Run: “C:\Program Files\Logitech\Video\ManifestEngine.exe” boot

    O4 - HKCU\..\Run: wkssvc32.exe

    O4 - HKCU\..\Run: “C:\Program Files\MSN Messenger\msnmsgr.exe” /background

    O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe

    O4 - Global Startup: Image Transfer.lnk = ?

    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

    O4 - Global Startup: Microsoft Office OneNote 2003 Snel Starten.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE

    O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab

    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409

    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab

    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-30.cab

    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab

    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/148119a2571ca3/housecall.antivirus.com/housecall/xscan53.cab

    O16 - DPF: {8731163E-77B9-4F91-9122-F112521C28AF} (MMSPlayerX Class) - http://212.41.157.233:8080/mmawap/jsp/composer/player/mmsPlayer.cab

    O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

    O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab

    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab

    O16 - DPF: {C2326BDF-43B0-431F-940A-52D042621188} (Dial.getdial) - http://www.mediaswitch.nl/eromedia/mediaswitch.cab

    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab

    O16 - DPF: {FE8400F2-C848-4379-989F-DF2ED39040BE} (Eyeball Instant Messaging Control) - http://www.onehello.nl/chat/RSVPChat.cab

    O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\SYSTEM32\Brmfrmps.exe" -service (file missing)

    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe

    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe

    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    morgen plaats ik er dan nog 1!

    en thanx voor de tips!