ongewenste pagina's

  • Tonny

    Alle stappen zijn er doorlopen.

    Er komen steeds ongevraagd en ongewenste pagina's op het beeldscherm.

    De map tempary files loopt steeds vol

    Wie wil er mee kijken?

    Logfile of HijackThis v1.99.1

    Scan saved at 16:06:41, on 1-11-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

    C:\Program Files\Norton AntiVirus\navapsvc.exe

    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\tcpsvcs.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    C:\WINDOWS\system32\RunDll32.exe

    C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe

    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

    C:\WINDOWS\NCLAUNCH.EXe

    C:\WINDOWS\system32\ctfmon.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\Microsoft Office\Office10\msoffice.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE

    C:\DOCUME~1\HARRYT~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4HWP0JY1\hijackthis.exe

    C:\Program Files\Messenger\msmsgs.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.nl/0SENLNL/SAOS01?FORM=TOOLBR

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.nl/0SENLNL/SAOS01?FORM=TOOLBR

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - Default URLSearchHook is missing

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O3 - Toolbar: (no name) - {44BE0690-5429-47f0-85BB-3FFD8020233E} - (no file)

    O4 - HKLM\..\Run: “C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe” /icon

    O4 - HKLM\..\Run: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: nwiz.exe /install

    O4 - HKLM\..\Run: RunDll32 cmicnfg.cpl,CMICtrlWnd

    O4 - HKLM\..\Run: “C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe

    O4 - HKLM\..\Run: C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: “C:\Program Files\HP\hpcoretech\hpcmpmgr.exe”

    O4 - HKLM\..\Run: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”

    O4 - HKLM\..\Run: C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

    O4 - HKLM\..\Run: C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

    O4 - HKCU\..\Run: rundll32.exe nview.dll,nViewLoadHook

    O4 - HKCU\..\Run: C:\WINDOWS\NCLAUNCH.EXe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

    O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab

    O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.doc-ep.nl/wfplayer/tdserver.cab

    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {18D9C485-7EEC-4395-95DA-DC3875B10E81} (TEInstallPlugIn) - http://www.skylinesoft.com/interactive/terraexplorer/install/TEInstallPlugIn.cab

    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab

    O16 - DPF: {3B623D23-2757-4881-A01E-D560EBCA5307} (VacPro.olanda_ver10) - http://advnt01.com/dialer/olanda_ver10.CAB

    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by24fd.bay24.hotmail.msn.com/resources/MsnPUpld.cab

    O16 - DPF: {6211AC26-A1B4-422A-AC52-1E70B7D24465} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/nl/filesharingctrl.cab

    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://www.planet.nl/exent/classes/ExentCtl.ocx

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1130832420101

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab

    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.bibliotheekdoesburg.nl/catalogus/msrdp.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.83.80.197/activex/AxisCamControl.cab

    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab

    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab

    O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab

    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/6c5b0a1ae398e3/player.virtools.com/downloads/player/Install2.5/Installer.exe

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

    O16 - DPF: {E2BBA7AC-2347-4761-AF7A-0DCA61355D53} - http://www.fairtale.com/dialer/fairtale.cab

    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://asp03.photoprintit.de/microsite/defaults/activex/XUpload.ocx

    O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by1fd.bay1.hotmail.msn.com/activex/HMAtchmt.ocx

    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - “C:\PROGRA~1\MSNMES~1\msgrapp.dll” (file missing)

    O20 - Winlogon Notify: MCD - C:\WINDOWS\system32\h0l2la3o1d.dll (file missing)

    O20 - Winlogon Notify: policies - C:\WINDOWS\system32\f0l0la3m1d.dll

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe

    O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe

    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

  • Erik

    Hoi Tony,

    Zet eerst Hijackthis eens in een eigen map of op je buroblad svp.

    Download LQfix.exe en plaats het op je bureaublad.

    Dubbelklik op LQfix.exe en klik install.

    Laat de standaard instellingen zoals ze zijn. Wijzig je die, dan zal de fix niet slagen.

    Je hebt een actieve internetconnectie nodig, dus zorg ervoor dat niks je connectie blokkeert.

    Zorg ervoor dat ‘Launch LQfix’ is aangevinkt vooraleer je op finish klikt.

    Dit zal de fix starten. Volg de aanwijzingen op het scherm.

    Je computer zal opnieuw opstarten na het klikken op Ja.

    Wees geduldig na de reboot, want het kan soms een tijdje duren omdat er een script uitgevoerd wordt op de achtergrond.

    Plaats daarna een nieuw hijackthislogje.

  • Erik

    Verkeerde tooltje, kan geen kwaad maar dit zal beter gaan :-)

    1. Download L2Mfix http://www.downloads.subratam.org/l2mfix.exe

    -Plaats het bestand op je bureaublad.

    -Klik op l2mfix.exe.

    -Klik op Accept.

    -Zorg dat de l2mfix-map op je bureaublad geplaatst wordt.

    -Klik op Install.

    -Op je bureaublad open je de map l2mfix.

    -Klik op l2fix.bat.

    -Klik op “1” om optie te 1 selecteren: Run Find Log.

    -Dit gaat even duren. Na een tijdje wordt er een kladblokbestand geopend.

    2. kopieer die tekst en plaats die hier.

  • Tonny

    L2MFIX find log 1.04a

    These are the registry keys present

    **********************************************************************************

    Winlogon/notify:

    Windows Registry Editor Version 5.00

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000000

    “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\

    6c,00,00,00

    “Logoff”=“ChainWlxLogoffEvent”

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000000

    “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Logoff”=“CryptnetWlxLogoffEvent”

    “DLLName”=“cscdll.dll”

    “Logon”=“WinlogonLogonEvent”

    “Logoff”=“WinlogonLogoffEvent”

    “ScreenSaver”=“WinlogonScreenSaverEvent”

    “Startup”=“WinlogonStartupEvent”

    “Shutdown”=“WinlogonShutdownEvent”

    “StartShell”=“WinlogonStartShellEvent”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=“C:\\WINDOWS\\system32\\h0l2la3o1d.dll”

    “Impersonate”=dword:00000000

    “Logon”=“WinLogon”

    “Logoff”=“WinLogoff”

    “Shutdown”=“WinShutdown”

    “Asynchronous”=dword:00000000

    “DllName”=“C:\\WINDOWS\\system32\\m0pola731d.dll”

    “Impersonate”=dword:00000000

    “Logon”=“WinLogon”

    “Logoff”=“WinLogoff”

    “Shutdown”=“WinShutdown”

    “DLLName”=“wlnotify.dll”

    “Logon”=“SCardStartCertProp”

    “Logoff”=“SCardStopCertProp”

    “Lock”=“SCardSuspendCertProp”

    “Unlock”=“SCardResumeCertProp”

    “Enabled”=dword:00000001

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Impersonate”=dword:00000000

    “StartShell”=“SchedStartShell”

    “Logoff”=“SchedEventLogOff”

    “Logoff”=“WLEventLogoff”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000001

    “DllName”=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “DLLName”=“WlNotify.dll”

    “Lock”=“SensLockEvent”

    “Logon”=“SensLogonEvent”

    “Logoff”=“SensLogoffEvent”

    “Safe”=dword:00000001

    “MaxWait”=dword:00000258

    “StartScreenSaver”=“SensStartScreenSaverEvent”

    “StopScreenSaver”=“SensStopScreenSaverEvent”

    “Startup”=“SensStartupEvent”

    “Shutdown”=“SensShutdownEvent”

    “StartShell”=“SensStartShellEvent”

    “PostShell”=“SensPostShellEvent”

    “Disconnect”=“SensDisconnectEvent”

    “Reconnect”=“SensReconnectEvent”

    “Unlock”=“SensUnlockEvent”

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Impersonate”=dword:00000000

    “Logoff”=“TSEventLogoff”

    “Logon”=“TSEventLogon”

    “PostShell”=“TSEventPostShell”

    “Shutdown”=“TSEventShutdown”

    “StartShell”=“TSEventStartShell”

    “Startup”=“TSEventStartup”

    “MaxWait”=dword:00000258

    “Reconnect”=“TSEventReconnect”

    “Disconnect”=“TSEventDisconnect”

    “DLLName”=“wlnotify.dll”

    “Logon”=“RegisterTicketExpiredNotificationEvent”

    “Logoff”=“UnregisterTicketExpiredNotificationEvent”

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above

    Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)

    This program is Freeware, use it on your own risk!

    Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:

    (NI) ALLOW Full access NT AUTHORITY\SYSTEM

    (IO) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-NI) ALLOW Read INGEBOUWD\Gebruikers

    (ID-IO) ALLOW Read INGEBOUWD\Gebruikers

    (ID-NI) ALLOW Full access INGEBOUWD\Administrators

    (ID-IO) ALLOW Full access INGEBOUWD\Administrators

    (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-IO) ALLOW Full access MAKER EIGENAAR

    **********************************************************************************

    useragent:

    Windows Registry Editor Version 5.00

    “{15BD9E8F-B19E-9B0C-2877-1A5DAD4C6A63}”=“”

    **********************************************************************************

    Shell Extension key:

    Windows Registry Editor Version 5.00

    “{00022613-0000-0000-C000-000000000046}”=“Eigenschappenvenster van multimediabestand”

    “{176d6597-26d3-11d1-b350-080036a75b03}”=“ICM-scannerbeheer”

    “{1F2E5C40-9550-11CE-99D2-00AA006E086C}”=“Het tabblad Beveiliging”

    “{3EA48300-8CF6-101B-84FB-666CCB9BCD32}”=“Eigenschappenblad voor OLE-docbestand”

    “{40dd6e20-7c17-11ce-a804-00aa003ca9f6}”=“Shell-uitbreidingen voor delen”

    “{41E300E0-78B6-11ce-849B-444553540000}”=“PlusPack CPL Extension”

    “{42071712-76d4-11d1-8b24-00a0c9068ff3}”=“Configuratiescherm-uitbreiding Beeldschermadapter”

    “{42071713-76d4-11d1-8b24-00a0c9068ff3}”=“Configuratiescherm-uitbreiding Monitor”

    “{42071714-76d4-11d1-8b24-00a0c9068ff3}”=“Configuratiescherm-uitbreiding Beeldscherm-panning”

    “{4E40F770-369C-11d0-8922-00A024AB2DBB}”=“Het tabblad Beveiliging”

    “{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}”=“Compatibiliteitspagina”

    “{56117100-C0CD-101B-81E2-00AA004AE837}”=“Knipselgegevensverwerker van shell”

    “{59099400-57FF-11CE-BD94-0020AF85B590}”=“Schijfkopieer-uitbreiding”

    “{59be4990-f85c-11ce-aff7-00aa003ca9f6}”=“Shell-uitbreidingen voor Microsoft Windows Network-objecten”

    “{5DB2625A-54DF-11D0-B6C4-0800091AA605}”=“ICM-monitorbeheer”

    “{675F097E-4C4D-11D0-B6C1-0800091AA605}”=“ICM-printerbeheer”

    “{764BF0E1-F219-11ce-972D-00AA00A14F56}”=“Shell-uitbreidingen voor bestandscompressie”

    “{77597368-7b15-11d0-a0c2-080036af3f03}”=“Shell-uitbreiding voor Web Printer”

    “{7988B573-EC89-11cf-9C00-00AA00A14F56}”=“Disk Quota UI”

    “{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}”=“Snelmenu Codering”

    “{85BBD920-42A0-1069-A2E4-08002B30309D}”=“Werkmap”

    “{88895560-9AA2-1069-930E-00AA0030EBC8}”=“HyperTerminal-pictogramuitbreiding”

    “{BD84B380-8CA2-1069-AB1D-08000948F534}”=“Fonts”

    “{DBCE2480-C732-101B-BE72-BA78E9AD5B27}”=“ICC-profiel”

    “{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}”=“Het tabblad Beveiliging voor printers”

    “{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}”=“Shell-uitbreidingen voor delen”

    “{f92e8c40-3d33-11d2-b1aa-080036a75b03}”=“Display TroubleShoot CPL Extension”

    “{7444C717-39BF-11D1-8CD9-00C04FC29D45}”=“Crypto PKO-extensie”

    “{7444C719-39BF-11D1-8CD9-00C04FC29D45}”=“Crypto-handtekeningextensie”

    “{7007ACC7-3202-11D1-AAD2-00805FC1270E}”=“Netwerkverbindingen”

    “{992CFFA0-F557-101A-88EC-00DD010CCC48}”=“Netwerkverbindingen”

    “{E211B736-43FD-11D1-9EFB-0000F8757FCD}”=“Scanners en camera's”

    “{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}”=“Scanners en camera's”

    “{905667aa-acd6-11d2-8080-00805f6596d2}”=“Scanners en camera's”

    “{3F953603-1008-4f6e-A73A-04AAC7A992F1}”=“Scanners en camera's”

    “{83bbcbf3-b28a-4919-a5aa-73027445d672}”=“Scanners en camera's”

    “{F0152790-D56E-4445-850E-4F3117DB740C}”=“Remote Sessions CPL Extension”

    “{60254CA5-953B-11CF-8C96-00AA00B8708C}”=“Shell-uitbreidingen voor Windows Script Host”

    “{2206CDB2-19C1-11D1-89E0-00C04FD7A829}”=“Microsoft Data Link”

    “{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}”=“Tasks Folder Icon Handler”

    “{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}”=“Tasks Folder Shell Extension”

    “{D6277990-4C6A-11CF-8D87-00AA0060F5BF}”=“Geplande taken”

    “{0DF44EAA-FF21-4412-828E-260A8728E7F1}”=“Taakbalk en menu Start”

    “{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}”=“Zoeken”

    “{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}”=“Help en ondersteuning”

    “{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}”=“Help en ondersteuning”

    “{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}”=“Uitvoeren…”

    “{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}”=“Internet”

    “{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}”=“E-mail”

    “{D20EA4E1-3957-11d2-A40B-0C5020524152}”=“Lettertypen”

    “{D20EA4E1-3957-11d2-A40B-0C5020524153}”=“Systeembeheer”

    “{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}”=“Audio Media Properties Handler”

    “{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}”=“Video Media Properties Handler”

    “{E4B29F9D-D390-480b-92FD-7DDB47101D71}”=“Wav Properties Handler”

    “{87D62D94-71B3-4b9a-9489-5FE6850DC73E}”=“Avi Properties Handler”

    “{A6FD9E45-6E44-43f9-8644-08598F5A74D9}”=“Midi Properties Handler”

    “{c5a40261-cd64-4ccf-84cb-c394da41d590}”=“Video Thumbnail Extractor”

    “{5E6AB780-7743-11CF-A12B-00AA004AE837}”=“Microsoft Internet-werkbalk”

    “{22BF0C20-6DA7-11D0-B373-00A0C9034938}”=“Downloadstatus”

    “{91EA3F8B-C99B-11d0-9815-00C04FD91972}”=“Uitgebreide shell-map”

    “{6413BA2C-B461-11d1-A18A-080036B11A03}”=“Uitgebreide shell-map 2”

    “{F61FFEC1-754F-11d0-80CA-00AA005B4383}”=“BandProxy”

    “{7BA4C742-9E81-11CF-99D3-00AA004AE837}”=“Microsoft-browserbalk”

    “{30D02401-6A81-11d0-8274-00C04FD5AE38}”=“Zoekbalk”

    “{32683183-48a0-441b-a342-7c2a440a9478}”=“Mediabalk”

    “{169A0691-8DF9-11d1-A1C4-00C04FD75D13}”=“Zoeken binnen deelvenster”

    “{07798131-AF23-11d1-9111-00A0C98BA67D}”=“Zoeken op het web”

    “{AF4F6510-F982-11d0-8595-00AA004CD6D8}”=“Hulpprogramma met opties voor registerboomstructuur”

    “{01E04581-4EEE-11d0-BFE9-00AA005B4383}”=“&Adres”

    “{A08C11D2-A228-11d0-825B-00AA005B4383}”=“Address EditBox”

    “{00BB2763-6A77-11D0-A535-00C04FD7D062}”=“Microsoft AutoAanvullen”

    “{7376D660-C583-11d0-A3A5-00C04FD706EC}”=“TridentImageExtractor”

    “{6756A641-DE71-11d0-831B-00AA005B4383}”=“MRU-lijst voor AutoAanvullen”

    “{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}”=“Aangepaste MRU-lijst voor AutoAanvullen”

    “{7e653215-fa25-46bd-a339-34a2790f3cb7}”=“Toegankelijk”

    “{acf35015-526e-4230-9596-becbe19f0ac9}”=“Pop-upbalk Volgen”

    “{E0E11A09-5CB8-4B6C-8332-E00720A168F2}”=“Parser voor adresbalk”

    “{00BB2764-6A77-11D0-A535-00C04FD7D062}”=“Lijst voor AutoAanvullen: Microsoft Geschiedenis”

    “{03C036F1-A186-11D0-824A-00AA005B4383}”=“Lijst voor AutoAanvullen: Microsoft Shell-map”

    “{00BB2765-6A77-11D0-A535-00C04FD7D062}”=“Microsoft-container met meervoudige lijst voor AutoAanvullen”

    “{ECD4FC4E-521C-11D0-B792-00A0C90312E1}”=“Sitemenu van shell-band”

    “{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}”=“Shell DeskBarApp”

    “{ECD4FC4C-521C-11D0-B792-00A0C90312E1}”=“Shell DeskBar”

    “{ECD4FC4D-521C-11D0-B792-00A0C90312E1}”=“Shell Rebar BandSite”

    “{DD313E04-FEFF-11d1-8ECD-0000F87A470C}”=“Gebruikersondersteuning”

    “{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}”=“Globale mapinstellingen”

    “{EFA24E61-B078-11d0-89E4-00C04FC9E26E}”=“Favorites Band”

    “{0A89A860-D7B1-11CE-8350-444553540000}”=“Shell Automation Inproc Service”

    “{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}”=“Shell DocObject Viewer”

    “{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}”=“Microsoft Browser Architecture”

    “{FBF23B40-E3F0-101B-8488-00AA003E56F8}”=“InternetShortcut”

    “{3C374A40-BAE4-11CF-BF7D-00AA006946EE}”=“Microsoft Url-geschiedenisservice”

    “{FF393560-C2A7-11CF-BFF4-444553540000}”=“Geschiedenis”

    “{7BD29E00-76C1-11CF-9DD0-00A0C9034933}”=“Tijdelijke Internet-bestanden”

    “{7BD29E01-76C1-11CF-9DD0-00A0C9034933}”=“Tijdelijke Internet-bestanden”

    “{CFBFAE00-17A6-11D0-99CB-00C04FD64497}”=“Microsoft Url-zoeken Hook”

    “{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}”=“IE4 Suite-welkomstscherm”

    “{67EA19A0-CCEF-11d0-8024-00C04FD75D13}”=“CDF Extension Copy Hook”

    “{131A6951-7F78-11D0-A979-00C04FD705A2}”=“ISFBand OC”

    “{9461b922-3c5a-11d2-bf8b-00c04fb93661}”=“Search Assistant OC”

    “{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}”=“Het Internet”

    “{871C5380-42A0-1069-A2EA-08002B30309D}”=“Internet Name Space”

    “{EFA24E64-B078-11d0-89E4-00C04FC9E26E}”=“Explorer-band”

    “{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}”=“Sendmail service”

    “{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}”=“Sendmail service”

    “{88C6C381-2E85-11D0-94DE-444553540000}”=“Cachemap van ActiveX”

    “{E6FB5E20-DE35-11CF-9C87-00AA005127ED}”=“WebCheck”

    “{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}”=“Subscription Mgr”

    “{F5175861-2688-11d0-9C5E-00AA00A45957}”=“Map met abonnementen”

    “{08165EA0-E946-11CF-9C87-00AA005127ED}”=“WebCheckWebCrawler”

    “{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}”=“WebCheckChannelAgent”

    “{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}”=“TrayAgent”

    “{7D559C10-9FE9-11d0-93F7-00AA0059CE02}”=“Code Download Agent”

    “{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}”=“ConnectionAgent”

    “{D8BD2030-6FC9-11D0-864F-00AA006809D9}”=“PostAgent”

    “{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}”=“WebCheck SyncMgr Handler”

    “{352EC2B7-8B9A-11D1-B8AE-006008059382}”=“Shell Toepassingsbeheer”

    “{0B124F8F-91F0-11D1-B8B5-006008059382}”=“Programma voor inventarisatie van ge‹nstalleerde toepassingen”

    “{CFCCC7A0-A282-11D1-9082-006008059382}”=“Darwin App Publisher”

    “{e84fda7c-1d6a-45f6-b725-cb260c236066}”=“Shell Image Verbs”

    “{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}”=“Shell Image Data Factory”

    “{3F30C968-480A-4C6C-862D-EFC0897BB84B}”=“GDI- en bestandsextractieprogramma voor miniaturen”

    “{9DBD2C50-62AD-11d0-B806-00C04FD706EC}”=“Informatie over de handler voor miniatuurweergaven (DOCFILES)”

    “{EAB841A0-9550-11cf-8C16-00805F1408F3}”=“HTML-extractie voor miniatuurweergaven”

    “{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}”=“Shell Image Property Handler”

    “{CC6EEFFB-43F6-46c5-9619-51D571967F7D}”=“Wizard Webpublicaties”

    “{add36aa8-751a-4579-a266-d66f5202ccbb}”=“Afdrukken via het web bestellen”

    “{6b33163c-76a5-4b6c-bf21-45de9cd503a1}”=“Shell-object voor publicatiewizard”

    “{58f1f272-9240-4f51-b6d4-fd63d1618591}”=“Wizard Passport”

    “{7A9D77BD-5403-11d2-8785-2E0420524153}”=“Gebruikersaccounts”

    “{BD472F60-27FA-11cf-B8B4-444553540000}”=“Compressed (zipped) Folder Right Drag Handler”

    “{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}”=“Compressed (zipped) Folder SendTo Target”

    “{f39a0dc0-9cc8-11d0-a599-00c04fd64433}”=“Kanaal-bestand”

    “{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}”=“Kanaal-snelkoppeling”

    “{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}”=“Handler-object voor kanalen”

    “{f3da0dc0-9cc8-11d0-a599-00c04fd64437}”=“Channel Menu”

    “{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}”=“Channel Properties”

    “{63da6ec0-2e98-11cf-8d82-444553540000}”=“FTP Folders Webview”

    “{883373C3-BF89-11D1-BE35-080036B11A03}”=“Microsoft DocProp Shell Ext”

    “{A9CF0EAE-901A-4739-A481-E35B73E47F6D}”=“Microsoft DocProp Inplace Edit Box Control”

    “{8EE97210-FD1F-4B19-91DA-67914005F020}”=“Microsoft DocProp Inplace ML Edit Box Control”

    “{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}”=“Microsoft DocProp Inplace Droplist Combo Control”

    “{6A205B57-2567-4A2C-B881-F787FAB579A3}”=“Microsoft DocProp Inplace Calendar Control”

    “{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}”=“Microsoft DocProp Inplace Time Control”

    “{8A23E65E-31C2-11d0-891C-00A024AB2DBB}”=“Directory Query UI”

    “{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}”=“Shell properties for a DS object”

    “{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}”=“Directory Object Find”

    “{F020E586-5264-11d1-A532-0000F8757D7E}”=“Directory Start/Search Find”

    “{0D45D530-764B-11d0-A1CA-00AA00C16E65}”=“Directory Property UI”

    “{62AE1F9A-126A-11D0-A14B-0800361B1103}”=“Directory Context Menu Verbs”

    “{ECF03A33-103D-11d2-854D-006008059367}”=“MyDocs Copy Hook”

    “{ECF03A32-103D-11d2-854D-006008059367}”=“MyDocs Drop Target”

    “{4a7ded0a-ad25-11d0-98a8-0800361b1103}”=“MyDocs Properties”

    “{750fdf0e-2a26-11d1-a3ea-080036587f03}”=“Offline Files Menu”

    “{10CFC467-4392-11d2-8DB4-00C04FA31A66}”=“Offline Files Folder Options”

    “{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}”=“Map Off line bestanden”

    “{143A62C8-C33B-11D1-84FE-00C04FA34A14}”=“Microsoft Agent Character Property Sheet Handler”

    “{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}”=“DfsShell”

    “{60fd46de-f830-4894-a628-6fa81bc0190d}”=“%DESC_PublishDropTarget%”

    “{7A80E4A8-8005-11D2-BCF8-00C04F72C717}”=“MMC Icon Handler”

    “{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}”=“.CAB file viewer”

    “{32714800-2E5F-11d0-8B85-00AA0044F941}”=“&Personen…”

    “{8DD448E6-C188-4aed-AF92-44956194EB1F}”=“Windows Media Player Play as Playlist Context Menu Handler”

    “{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}”=“Windows Media Player Burn Audio CD Context Menu Handler”

    “{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}”=“Windows Media Player Add to Playlist Context Menu Handler”

    “{1CDB2949-8F65-4355-8456-263E7C208A5D}”=“Bureaubladverkenner”

    “{1E9B04FB-F9E5-4718-997B-B8DA88302A47}”=“Desktop Explorer Menu”

    “{BDEADF00-C265-11D0-BCED-00A0C90AB50F}”=“Webmappen”

    “{0006F045-0000-0000-C000-000000000046}”=“Microsoft Outlook Custom Icon Handler”

    “{42042206-2D85-11D3-8CFF-005004838597}”=“Microsoft Office HTML Icon Handler”

    “{5E44E225-A408-11CF-B581-008029601108}”=“Adaptec DirectCD Shell Extension”

    “{5F327514-6C5E-4d60-8F16-D07FA08A78ED}”=“Auto Update Property Sheet Extension”

    “{e57ce731-33e8-4c51-8354-bb4de9d215d1}”=“Universele Plug en Play-apparaten”

    “{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}”=“Set Program Access and Defaults”

    “{596AB062-B4D2-4215-9F74-E9109B0A8153}”=“Previous Versions Property Page”

    “{9DB7A13C-F208-4981-8353-73CC61AE2783}”=“Previous Versions”

    “{692F0339-CBAA-47e6-B5B5-3B84DB604E87}”=“Extensions Manager Folder”

    “{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}”=“TrojanHunter Menu Shell Extension”

    “{1D2680C9-0E2A-469d-B787-065558BC7D43}”=“Fusion Cache”

    “{012DFD1B-6769-4BE8-A431-DA61C94C7FC4}”=“”

    **********************************************************************************

    HKEY ROOT CLASSIDS:

    Windows Registry Editor Version 5.00

    @=“”

    @=“”

    @=“”

    @=“C:\\WINDOWS\\system32\\oveaut32.dll”

    “ThreadingModel”=“Apartment”

    **********************************************************************************

    Files Found are not all bad files:

    C:\WINDOWS\SYSTEM32\

    browseui.dll Sat 3 Sep 2005 0:54:56 A…. 1.020.416 996,50 K

    cdfview.dll Sat 3 Sep 2005 0:54:56 A…. 151.552 148,00 K

    cdosys.dll Sat 10 Sep 2005 2:55:38 A…. 2.067.968 1,97 M

    danim.dll Sat 3 Sep 2005 0:54:58 A…. 1.056.768 1,01 M

    dxtrans.dll Sat 3 Sep 2005 0:54:58 A…. 205.312 200,50 K

    extmgr.dll Sat 3 Sep 2005 0:54:58 ….. 55.808 54,50 K

    h24mlc~1.dll Tue 1 Nov 2005 16:45:20 ..S.R 236.166 230,63 K

    iepeers.dll Sat 3 Sep 2005 0:54:58 A…. 251.392 245,50 K

    inseng.dll Sat 3 Sep 2005 0:54:58 A…. 96.768 94,50 K

    k4no0e~1.dll Mon 31 Oct 2005 22:51:04 ..S.R 234.272 228,78 K

    legitc~1.dll Mon 29 Aug 2005 13:27:12 A…. 520.968 508,76 K

    linkinfo.dll Thu 1 Sep 2005 3:28:26 A…. 19.968 19,50 K

    m0pola~1.dll Tue 1 Nov 2005 16:42:36 ..S.R 235.302 229,79 K

    mshtml.dll Tue 4 Oct 2005 16:27:36 A…. 3.013.120 2,87 M

    mshtmled.dll Sat 3 Sep 2005 0:55:02 A…. 448.512 438,00 K

    msrating.dll Sat 3 Sep 2005 0:55:02 A…. 146.432 143,00 K

    mstime.dll Sat 3 Sep 2005 0:55:04 A…. 530.432 518,00 K

    netman.dll Mon 22 Aug 2005 19:36:16 A…. 197.632 193,00 K

    oveaut32.dll Tue 1 Nov 2005 16:44:20 ..S.R 236.166 230,63 K

    pngfilt.dll Sat 3 Sep 2005 0:55:04 A…. 39.424 38,50 K

    quartz.dll Tue 30 Aug 2005 4:56:40 A…. 1.291.264 1,23 M

    shdocvw.dll Sat 3 Sep 2005 0:55:06 A…. 1.483.776 1,41 M

    shell32.dll Fri 23 Sep 2005 4:08:06 A…. 8.497.664 8,10 M

    shlwapi.dll Sat 3 Sep 2005 0:55:06 A…. 474.112 463,00 K

    sirenacm.dll Sat 13 Aug 2005 20:41:12 A…. 118.784 116,00 K

    umpnpmgr.dll Tue 23 Aug 2005 4:40:36 A…. 124.416 121,50 K

    urlmon.dll Sat 3 Sep 2005 0:55:08 A…. 605.184 591,00 K

    wdn32spl.dll Wed 2 Nov 2005 8:49:26 ..S.R 235.302 229,79 K

    wininet.dll Sat 3 Sep 2005 0:55:08 A…. 661.504 646,00 K

    winsrv.dll Thu 1 Sep 2005 3:28:26 A…. 292.352 285,50 K

    30 items found: 30 files (5 H/S), 0 directories.

    Total of file sizes: 24.548.736 bytes 23,41 M

    Locate .tmp files:

    C:\WINDOWS\SYSTEM32\

    guard.tmp Wed 2 Nov 2005 8:50:26 ..S.R 235.302 229,79 K

    1 item found: 1 file (1 H/S), 0 directories.

    Total of file sizes: 235.302 bytes 229,79 K

    **********************************************************************************

    Directory Listing of system files:

    Het volume in station C heeft geen naam.

    Het volumenummer is 0412-377F

    Map van C:\WINDOWS\System32

    02-11-2005 08:50 235.302 guard.tmp

    02-11-2005 08:49 235.302 wdn32spl.dll

    01-11-2005 16:45 236.166 h24mlch11f4.dll

    01-11-2005 16:44 236.166 oveaut32.dll

    01-11-2005 16:42 235.302 m0pola731d.dll

    31-10-2005 22:51 234.272 k4no0e53eh.dll

    16-10-2005 07:22 dllcache

    07-04-2005 19:29 5.120 Thumbs.db

    16-11-2003 16:13 Microsoft

    7 bestand(en) 1.417.630 bytes

    2 map(pen) 419.598.336 bytes beschikbaar

  • Erik

    Leeg eerst de volgende mappen, de gehele inhoud verwijderen maar niet de map zelf :

    C:\Documents and Settings\gebruiker\Local Settings\Temporary Internet Files\Content.IE5

    C:\Documents and Settings\gebruiker\Local Settings\Temp

    1. Download de trial version van spy sweeper. http://www.webroot.com/shoppingcart/tryme.php?bjpc=64011&vcode=DT02&WRSID=b5af0de1e06a6bf2874ca8069e584a52

    haal alle updates op en doe daarna een volledige systeemscan

    2.

    -Sluit alle openstaande programma's.

    -Dubbelklik op l2mfix.bat.

    -Klik op “2” om optie 2 te selecteren: Run Fix.

    -Druk op Enter.

    -Druk op een toets om de computer opnieuw te starten wanneer dit gevraagd wordt.

    Na de reboot verschijnen de ikonen op je desktop. Deze zullen weer verdwijnen. (dat is normaal).

    L2mfix gaat je computer scannen

    Wanneer het klaar is wordt er een nieuw kladblokbestand geopend.

    3. kopieer die tekst en plaats die hier, samen met een nieuw HijackThis-logje.

  • Tonny

    De log van hijackthis:

    Logfile of HijackThis v1.99.1

    Scan saved at 22:09:07, on 2-11-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

    C:\Program Files\Norton AntiVirus\navapsvc.exe

    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\tcpsvcs.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    C:\WINDOWS\explorer.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Microsoft Office\Office10\msoffice.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\Documents and Settings\Harry Thuss\Local Settings\Temporary Internet Files\Content.IE5\49230X63\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.nl/0SENLNL/SAOS01?FORM=TOOLBR

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.nl/0SENLNL/SAOS01?FORM=TOOLBR

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - Default URLSearchHook is missing

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O4 - HKLM\..\Run: “C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe” /icon

    O4 - HKLM\..\Run: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: nwiz.exe /install

    O4 - HKLM\..\Run: RunDll32 cmicnfg.cpl,CMICtrlWnd

    O4 - HKLM\..\Run: “C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe

    O4 - HKLM\..\Run: C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: “C:\Program Files\HP\hpcoretech\hpcmpmgr.exe”

    O4 - HKLM\..\Run: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”

    O4 - HKLM\..\Run: C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

    O4 - HKLM\..\Run: C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

    O4 - HKLM\..\Run: “C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe” /startintray

    O4 - HKCU\..\Run: rundll32.exe nview.dll,nViewLoadHook

    O4 - HKCU\..\Run: C:\WINDOWS\NCLAUNCH.EXe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

    O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab

    O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.doc-ep.nl/wfplayer/tdserver.cab

    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {18D9C485-7EEC-4395-95DA-DC3875B10E81} (TEInstallPlugIn) - http://www.skylinesoft.com/interactive/terraexplorer/install/TEInstallPlugIn.cab

    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab

    O16 - DPF: {3B623D23-2757-4881-A01E-D560EBCA5307} - http://advnt01.com/dialer/olanda_ver10.CAB

    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by24fd.bay24.hotmail.msn.com/resources/MsnPUpld.cab

    O16 - DPF: {6211AC26-A1B4-422A-AC52-1E70B7D24465} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/nl/filesharingctrl.cab

    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://www.planet.nl/exent/classes/ExentCtl.ocx

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1130832420101

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab

    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.bibliotheekdoesburg.nl/catalogus/msrdp.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.83.80.197/activex/AxisCamControl.cab

    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab

    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab

    O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab

    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/6c5b0a1ae398e3/player.virtools.com/downloads/player/Install2.5/Installer.exe

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

    O16 - DPF: {E2BBA7AC-2347-4761-AF7A-0DCA61355D53} - http://www.fairtale.com/dialer/fairtale.cab

    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://asp03.photoprintit.de/microsite/defaults/activex/XUpload.ocx

    O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by1fd.bay1.hotmail.msn.com/activex/HMAtchmt.ocx

    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - “C:\PROGRA~1\MSNMES~1\msgrapp.dll” (file missing)

    O20 - Winlogon Notify: MCD - C:\WINDOWS\system32\h0l2la3o1d.dll (file missing)

    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe

    O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe

    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    _____________________________________________________________________

    De log van l2mfix:

    Setting Directory

    C:\

    C:\

    System Rebooted!

    Running From:

    C:\

    killing explorer and rundll32.exe

    Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03

    Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org

    Killing PID 1724 ‘explorer.exe’

    Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03

    Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org

    Killing PID 1736 ‘rundll32.exe’

    Scanning First Pass. Please Wait!

    First Pass Completed

    Second Pass Scanning

    Second pass Completed!

    Backing Up: C:\WINDOWS\system32\h24mlch11f4.dll

    1 bestand(en) gekopieerd.

    Backing Up: C:\WINDOWS\system32\wdn32spl.dll

    1 bestand(en) gekopieerd.

    Backing Up: C:\WINDOWS\system32\guard.tmp

    1 bestand(en) gekopieerd.

    deleting: C:\WINDOWS\system32\h24mlch11f4.dll

    Successfully Deleted: C:\WINDOWS\system32\h24mlch11f4.dll

    deleting: C:\WINDOWS\system32\wdn32spl.dll

    Successfully Deleted: C:\WINDOWS\system32\wdn32spl.dll

    deleting: C:\WINDOWS\system32\guard.tmp

    Successfully Deleted: C:\WINDOWS\system32\guard.tmp

    Zipping up files for submission:

    adding: h24mlch11f4.dll (208 bytes security) (deflated 5%)

    adding: wdn32spl.dll (208 bytes security) (deflated 5%)

    adding: guard.tmp (208 bytes security) (deflated 5%)

    adding: clear.reg (208 bytes security) (deflated 22%)

    adding: lo2.txt (208 bytes security) (deflated 66%)

    adding: test.txt (208 bytes security) (deflated 46%)

    adding: test2.txt (208 bytes security) (stored 0%)

    adding: test3.txt (208 bytes security) (stored 0%)

    adding: test5.txt (208 bytes security) (stored 0%)

    adding: xfind.txt (208 bytes security) (deflated 39%)

    Restoring Registry Permissions:

    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above

    Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)

    This program is Freeware, use it on your own risk!

    Revoking access for predefined group “Administrators”

    Inherited ACE can not be revoked here!

    Inherited ACE can not be revoked here!

    Registry permissions set too:

    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above

    Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)

    This program is Freeware, use it on your own risk!

    Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:

    (NI) ALLOW Full access NT AUTHORITY\SYSTEM

    (IO) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-NI) ALLOW Read INGEBOUWD\Gebruikers

    (ID-IO) ALLOW Read INGEBOUWD\Gebruikers

    (ID-NI) ALLOW Full access INGEBOUWD\Administrators

    (ID-IO) ALLOW Full access INGEBOUWD\Administrators

    (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-IO) ALLOW Full access MAKER EIGENAAR

    Restoring Sedebugprivilege:

    Granting SeDebugPrivilege to Administrators … successful

    Restoring Windows Update Certificates.:

    deleting local copy: h24mlch11f4.dll

    deleting local copy: wdn32spl.dll

    deleting local copy: guard.tmp

    The following Is the Current Export of the Winlogon notify key:

    ****************************************************************************

    Windows Registry Editor Version 5.00

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000000

    “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\

    6c,00,00,00

    “Logoff”=“ChainWlxLogoffEvent”

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000000

    “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Logoff”=“CryptnetWlxLogoffEvent”

    “DLLName”=“cscdll.dll”

    “Logon”=“WinlogonLogonEvent”

    “Logoff”=“WinlogonLogoffEvent”

    “ScreenSaver”=“WinlogonScreenSaverEvent”

    “Startup”=“WinlogonStartupEvent”

    “Shutdown”=“WinlogonShutdownEvent”

    “StartShell”=“WinlogonStartShellEvent”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=“C:\\WINDOWS\\system32\\h0l2la3o1d.dll”

    “Impersonate”=dword:00000000

    “Logon”=“WinLogon”

    “Logoff”=“WinLogoff”

    “Shutdown”=“WinShutdown”

    “DLLName”=“wlnotify.dll”

    “Logon”=“SCardStartCertProp”

    “Logoff”=“SCardStopCertProp”

    “Lock”=“SCardSuspendCertProp”

    “Unlock”=“SCardResumeCertProp”

    “Enabled”=dword:00000001

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Impersonate”=dword:00000000

    “StartShell”=“SchedStartShell”

    “Logoff”=“SchedEventLogOff”

    “Logoff”=“WLEventLogoff”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000001

    “DllName”=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “DLLName”=“WlNotify.dll”

    “Lock”=“SensLockEvent”

    “Logon”=“SensLogonEvent”

    “Logoff”=“SensLogoffEvent”

    “Safe”=dword:00000001

    “MaxWait”=dword:00000258

    “StartScreenSaver”=“SensStartScreenSaverEvent”

    “StopScreenSaver”=“SensStopScreenSaverEvent”

    “Startup”=“SensStartupEvent”

    “Shutdown”=“SensShutdownEvent”

    “StartShell”=“SensStartShellEvent”

    “PostShell”=“SensPostShellEvent”

    “Disconnect”=“SensDisconnectEvent”

    “Reconnect”=“SensReconnectEvent”

    “Unlock”=“SensUnlockEvent”

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Impersonate”=dword:00000000

    “Logoff”=“TSEventLogoff”

    “Logon”=“TSEventLogon”

    “PostShell”=“TSEventPostShell”

    “Shutdown”=“TSEventShutdown”

    “StartShell”=“TSEventStartShell”

    “Startup”=“TSEventStartup”

    “MaxWait”=dword:00000258

    “Reconnect”=“TSEventReconnect”

    “Disconnect”=“TSEventDisconnect”

    “DLLName”=“wlnotify.dll”

    “Logon”=“RegisterTicketExpiredNotificationEvent”

    “Logoff”=“UnregisterTicketExpiredNotificationEvent”

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=“WRLogonNTF.dll”

    “Impersonate”=dword:00000001

    “Lock”=“WRLock”

    “StartScreenSaver”=“WRStartScreenSaver”

    “StartShell”=“WRStartShell”

    “Startup”=“WRStartup”

    “StopScreenSaver”=“WRStopScreenSaver”

    “Unlock”=“WRUnlock”

    “Shutdown”=“WRShutdown”

    “Logoff”=“WRLogoff”

    “Logon”=“WRLogon”

    “DLLName”=“wzcdlg.dll”

    “Logon”=“WZCEventLogon”

    “Logoff”=“WZCEventLogoff”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000000

    The following are the files found:

    ****************************************************************************

    C:\WINDOWS\system32\h24mlch11f4.dll

    C:\WINDOWS\system32\wdn32spl.dll

    C:\WINDOWS\system32\guard.tmp

    Registry Entries that were Deleted:

    Please verify that the listing looks ok.

    If there was something deleted wrongly there are backups in the backreg folder.

    ****************************************************************************

    REGEDIT4

    “{012DFD1B-6769-4BE8-A431-DA61C94C7FC4}”=-

    REGEDIT4

    “SV1”=“”

    ****************************************************************************

    Desktop.ini Contents:

    ****************************************************************************

    ****************************************************************************

    

    Er waren een paar tempfiles die niet te verwijderen waren.

    Succes Tonny

  • Erik

    Deze regel nog even fixen met HJT en dan ziet het er weer gezond uit :-)

    O20 - Winlogon Notify: MCD - C:\WINDOWS\system32\h0l2la3o1d.dll (file missing)

  • Tonny

    DitZo moet het weer goed zijn???

    Wat raad je me aan om opnieuw problemen te voorkomen??

    Logfile of HijackThis v1.99.1

    Scan saved at 23:15:09, on 2-11-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

    C:\Program Files\Norton AntiVirus\navapsvc.exe

    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\tcpsvcs.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    C:\WINDOWS\explorer.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Microsoft Office\Office10\msoffice.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\Documents and Settings\Harry Thuss\Local Settings\Temporary Internet Files\Content.IE5\056J85UZ\hijackthis.exe

    C:\Program Files\Messenger\msmsgs.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.nl/0SENLNL/SAOS01?FORM=TOOLBR

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.nl/0SENLNL/SAOS01?FORM=TOOLBR

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - Default URLSearchHook is missing

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O4 - HKLM\..\Run: “C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe” /icon

    O4 - HKLM\..\Run: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: nwiz.exe /install

    O4 - HKLM\..\Run: RunDll32 cmicnfg.cpl,CMICtrlWnd

    O4 - HKLM\..\Run: “C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe

    O4 - HKLM\..\Run: C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: “C:\Program Files\HP\hpcoretech\hpcmpmgr.exe”

    O4 - HKLM\..\Run: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”

    O4 - HKLM\..\Run: C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

    O4 - HKLM\..\Run: C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

    O4 - HKLM\..\Run: “C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe” /startintray

    O4 - HKCU\..\Run: rundll32.exe nview.dll,nViewLoadHook

    O4 - HKCU\..\Run: C:\WINDOWS\NCLAUNCH.EXe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

    O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab

    O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.doc-ep.nl/wfplayer/tdserver.cab

    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {18D9C485-7EEC-4395-95DA-DC3875B10E81} (TEInstallPlugIn) - http://www.skylinesoft.com/interactive/terraexplorer/install/TEInstallPlugIn.cab

    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab

    O16 - DPF: {3B623D23-2757-4881-A01E-D560EBCA5307} - http://advnt01.com/dialer/olanda_ver10.CAB

    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by24fd.bay24.hotmail.msn.com/resources/MsnPUpld.cab

    O16 - DPF: {6211AC26-A1B4-422A-AC52-1E70B7D24465} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/nl/filesharingctrl.cab

    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://www.planet.nl/exent/classes/ExentCtl.ocx

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1130832420101

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab

    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.bibliotheekdoesburg.nl/catalogus/msrdp.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.83.80.197/activex/AxisCamControl.cab

    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab

    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab

    O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab

    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/6c5b0a1ae398e3/player.virtools.com/downloads/player/Install2.5/Installer.exe

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

    O16 - DPF: {E2BBA7AC-2347-4761-AF7A-0DCA61355D53} - http://www.fairtale.com/dialer/fairtale.cab

    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://asp03.photoprintit.de/microsite/defaults/activex/XUpload.ocx

    O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by1fd.bay1.hotmail.msn.com/activex/HMAtchmt.ocx

    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - “C:\PROGRA~1\MSNMES~1\msgrapp.dll” (file missing)

    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe

    O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe

    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    Alvast bedankt, Tonny

  • lucas

    Hoi Tonny,

    Je logje ziet er weer prima uit. Problemen voorkomen begint allereerst met gepast surfgedrag. Voer 1 maal in de week het stappenplan onder lees dit eerst uit.

    Vul dit aan met een online virusscan (panda, kaspersky etc). Het kan geen kwaad eens van online scanner te wisselen.

    Verder kun je ter preventie Spyblaster en SpywareGuard installeren ;)

    1. SpyBlaster

    www.javacoolsoftware.com/sbdownload.html

    Voor uitleg van SpyBlaster www.antispywareoffensief.nl/

    Klik op SpyBlaster (links in het scherm)

    2. SpywareGuard (freeware)

    www.majorgeeks.com/download3045.html

    Lucas :)