virus II

  • Rolf

    Hallo,

    ik kan weer redelijk vrij door de pc hen en heb de nieuwste updates van alle scans eroverheen gehaald. Dit is het resultaat. Fouten zichtbaar? De vorige log is dus achterhaald. Dank dank

    rolf

    Logfile of HijackThis v1.99.1

    Scan saved at 12:56:10, on 11-11-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe

    C:\Program Files\Logitech\iTouch\iTouch.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe

    C:\Program Files\Logitech\MouseWare\system\em_exec.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\Program Files\MSN Apps\Updater\01.05.0000.1009\nl\msnappau.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Outlook Express\msimn.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    D:\temp\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.home.nl/?from=start.home.nl

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.home.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer aangeboden door @Home

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)

    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O4 - HKLM\..\Run: C:\WINDOWS\System32\NeroCheck.exe

    O4 - HKLM\..\Run: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: nwiz.exe /install

    O4 - HKLM\..\Run: C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe

    O4 - HKLM\..\Run: C:\Program Files\Logitech\iTouch\iTouch.exe

    O4 - HKLM\..\Run: Logi_MwX.Exe

    O4 - HKLM\..\Run: F:\cleandiskpro\cleandisk.exe

    O4 - HKLM\..\Run: “F:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”

    O4 - HKLM\..\Run: C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “F:\Program Files\D-Tools\daemon.exe” -lang 1033

    O4 - HKLM\..\Run: C:\WINDOWS\BQTray.exe

    O4 - HKLM\..\Run: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    O4 - HKLM\..\Run: F:\Program Files\@Home veiligheid\AntiVirus\AVRealTime.exe

    O4 - HKLM\..\Run: C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe

    O4 - HKLM\..\Run: F:\Program Files\Anti-Blaxx\Anti-Blaxx.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: rundll32.exe nview.dll,nViewLoadHook

    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

    O4 - Startup: PowerReg Scheduler V3.exe

    O4 - Startup: PowerReg Scheduler.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html

    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html

    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html

    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://start.home.nl/

    O16 - DPF: FreedomAudio - http://download.worldchessnetwork.com/freedomaudio/freedominstaller.cab

    O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab

    O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab

    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

    O16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} - http://down.plaxo.com/down/release/instub.cab

    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab

    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

    O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://www.kennelclub.nl/media/scripts/ScriptX.cab

    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab

    O16 - DPF: {5D8844F9-1CB8-11D2-A0A0-00600859EB9F} (PatchCtl Class) - file://F:\Games\update.1.1\patchx2.cab

    O16 - DPF: {6211AC26-A1B4-422A-AC52-1E70B7D24465} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/nl/filesharingctrl.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100278409547

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/2003080601/housecall.antivirus.com/housecall/xscan53.cab

    O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37380.cab

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.bibliotheekzevenaar.nl/catalogus/msrdp.cab

    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab

    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab

    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game13.zylomgames.com/activex/zylomgamesplayer.cab

    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab

    O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab

    O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://game12.zylomgames.com/activex/zylomloader.cab

    O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab

    O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://gto.postbank.nl/GTO/PBGNX.cab

    O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/74914090/activex/IPSUploader.cab

    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab

    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.hema.nl/site/xupload/XUpload.ocx

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4618/mcfscan.cab

    O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/yiebio5_1_3_0.cab

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - “C:\PROGRA~1\MSNMES~1\msgrapp.dll” (file missing)

    O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\

    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Unknown owner - F:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe (file missing)

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

  • pablo

    hoi rolf

    start hijack,klik op scan en vink alleen de onderstaande regels aan

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    O4 - Startup: PowerReg Scheduler V3.exe

    O4 - Startup: PowerReg Scheduler.exe

    O16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} - down.plaxo.com/down/release/instub.cab

    O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\

    sluit alle vensters behalve hijack en klik op “fix checked”

    Download L2Mfix.

    -Plaats het bestand op je bureaublad.

    -Klik op l2mfix.exe.

    -Klik op Accept.

    -Zorg dat de l2mfix-map op je bureaublad geplaatst wordt.

    -Klik op Install.

    -Op je bureaublad open je de map l2mfix.

    -Klik op l2fix.bat.

    -Klik op “1” om optie te 1 selecteren: Run Find Log.

    -Dit gaat even duren. Na een tijdje wordt er een kladblokbestand geopend.

    kopieer die tekst en plaats die hier, samen met een nieuw HijackThis-logje.

    paul :)

  • Rolf

    Dag pablo, erik, lucas en silly,

    Dit is een flinke reutel. Iig vast bedankt voor alle moeite. Is al dit gelazer ook de oorzaak van het niet meer kunnen ophalen en oploaden via een ftp verbinding (dat gaat nmlk niet meer en moet wel voor mijn werk…)

    L2MFIX find log 1.04a

    These are the registry keys present

    **********************************************************************************

    Winlogon/notify:

    Windows Registry Editor Version 5.00

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000000

    “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\

    6c,00,00,00

    “Logoff”=“ChainWlxLogoffEvent”

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000000

    “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Logoff”=“CryptnetWlxLogoffEvent”

    “DLLName”=“cscdll.dll”

    “Logon”=“WinlogonLogonEvent”

    “Logoff”=“WinlogonLogoffEvent”

    “ScreenSaver”=“WinlogonScreenSaverEvent”

    “Startup”=“WinlogonStartupEvent”

    “Shutdown”=“WinlogonShutdownEvent”

    “StartShell”=“WinlogonStartShellEvent”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000001

    “DLLName”=“wlnotify.dll”

    “Logon”=“SCardStartCertProp”

    “Logoff”=“SCardStopCertProp”

    “Lock”=“SCardSuspendCertProp”

    “Unlock”=“SCardResumeCertProp”

    “Enabled”=dword:00000001

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Impersonate”=dword:00000000

    “StartShell”=“SchedStartShell”

    “Logoff”=“SchedEventLogOff”

    “Logoff”=“WLEventLogoff”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000001

    “DllName”=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “DLLName”=“WlNotify.dll”

    “Lock”=“SensLockEvent”

    “Logon”=“SensLogonEvent”

    “Logoff”=“SensLogoffEvent”

    “Safe”=dword:00000001

    “MaxWait”=dword:00000258

    “StartScreenSaver”=“SensStartScreenSaverEvent”

    “StopScreenSaver”=“SensStopScreenSaverEvent”

    “Startup”=“SensStartupEvent”

    “Shutdown”=“SensShutdownEvent”

    “StartShell”=“SensStartShellEvent”

    “PostShell”=“SensPostShellEvent”

    “Disconnect”=“SensDisconnectEvent”

    “Reconnect”=“SensReconnectEvent”

    “Unlock”=“SensUnlockEvent”

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Impersonate”=dword:00000000

    “Logoff”=“TSEventLogoff”

    “Logon”=“TSEventLogon”

    “PostShell”=“TSEventPostShell”

    “Shutdown”=“TSEventShutdown”

    “StartShell”=“TSEventStartShell”

    “Startup”=“TSEventStartup”

    “MaxWait”=dword:00000258

    “Reconnect”=“TSEventReconnect”

    “Disconnect”=“TSEventDisconnect”

    “DLLName”=“wlnotify.dll”

    “Logon”=“RegisterTicketExpiredNotificationEvent”

    “Logoff”=“UnregisterTicketExpiredNotificationEvent”

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above

    Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)

    This program is Freeware, use it on your own risk!

    Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:

    (NI) ALLOW Full access NT AUTHORITY\SYSTEM

    (IO) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-NI) ALLOW Read INGEBOUWD\Gebruikers

    (ID-IO) ALLOW Read INGEBOUWD\Gebruikers

    (ID-NI) ALLOW Full access INGEBOUWD\Administrators

    (ID-IO) ALLOW Full access INGEBOUWD\Administrators

    (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-IO) ALLOW Full access MAKER EIGENAAR

    **********************************************************************************

    useragent:

    Windows Registry Editor Version 5.00

    “{47DB67E0-AAA9-A1D4-B790-44937DAA901C}”=“”

    “SV1”=“”

    **********************************************************************************

    Shell Extension key:

    Windows Registry Editor Version 5.00

    “{C169E5F0-E2B3-41F3-B81A-7BA529CBE193}”=“ZipGenius Shell Extension”

    “{2E5AC2E0-406D-11D4-86B3-FA5861508E25}”=“ZipGenius Zip InfoTip”

    “{FE8D01BF-610A-4261-9C6E-32D65A42C907}”=“ZipGenius 5.5 DnD Extract handler”

    “{310A0C95-EA11-42AE-A8E4-53E69E650310}”=“ZipGenius Zip Drop handler”

    @=“”

    “{1530F7EE-5128-43BD-9977-84A4B0FAD7DF}”=“PhotoToys”

    “{eb9ebda0-b3e7-11cf-81c9-0000c0aa665f}”=“FTP Explorer Shell Extension”

    “{BDEADF00-C265-11D0-BCED-00A0C90AB50F}”=“Webmappen”

    “{42042206-2D85-11D3-8CFF-005004838597}”=“Microsoft Office HTML Icon Handler”

    “{1EBC3533-B289-409F-9924-B84B3F0717D2}”=“AceFTP Context Menu Shell Extension”

    “{32020A01-506E-484D-A2A8-BE3CF17601C3}”=“AlcoholShellEx”

    “{1CDB2949-8F65-4355-8456-263E7C208A5D}”=“Bureaubladverkenner”

    “{1E9B04FB-F9E5-4718-997B-B8DA88302A47}”=“Desktop Explorer Menu”

    “{5F327514-6C5E-4d60-8F16-D07FA08A78ED}”=“Auto Update Property Sheet Extension”

    “{640167b4-59b0-47a6-b335-a6b3c0695aea}”=“Portable Media Devices”

    “{cc86590a-b60a-48e6-996b-41d25ed39a1e}”=“Portable Media Devices Menu”

    “{8DD448E6-C188-4aed-AF92-44956194EB1F}”=“Windows Media Player Play as Playlist Context Menu Handler”

    “{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}”=“Windows Media Player Burn Audio CD Context Menu Handler”

    “{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}”=“Windows Media Player Add to Playlist Context Menu Handler”

    “{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}”=“Shell Extensions for RealOne Player”

    “{043308A2-3CF7-4ED5-A668-2B4FB0BD307A}”=“dBpowerAMP dAP Scripting”

    “{FED7043D-346A-414D-ACD7-550D052499A7}”=“dBpowerAMP Popup Info”

    “{88901EED-E612-4C1A-B54E-EFBFB2E499E2}”=“SxContextMenu1”

    “{19EA5CFC-FADD-4F5B-884D-A1359B07550F}”=“SxContextMenu1”

    “{B521F599-A3A6-4C10-BD1E-4778DFCF0ACB}”=“”

    “{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}”=“Set Program Access and Defaults”

    “{596AB062-B4D2-4215-9F74-E9109B0A8153}”=“Previous Versions Property Page”

    “{9DB7A13C-F208-4981-8353-73CC61AE2783}”=“Previous Versions”

    “{692F0339-CBAA-47e6-B5B5-3B84DB604E87}”=“Extensions Manager Folder”

    **********************************************************************************

    HKEY ROOT CLASSIDS:

    Windows Registry Editor Version 5.00

    @=“”

    “IDEx”=“AD”

    @=“”

    @=“”

    “ThreadingModel”=“Apartment”

    **********************************************************************************

    Files Found are not all bad files:

    C:\WINDOWS\SYSTEM32\

    browseui.dll Sat 3 Sep 2005 0:54:56 A…. 1.020.416 996,50 K

    cdfview.dll Sat 3 Sep 2005 0:54:56 A…. 151.552 148,00 K

    cdosys.dll Sat 10 Sep 2005 2:55:38 A…. 2.067.968 1,97 M

    clauth1.dll Wed 2 Nov 2005 21:50:20 A…. 1.025 1,00 K

    clauth2.dll Wed 2 Nov 2005 21:50:20 A…. 1.025 1,00 K

    danim.dll Sat 3 Sep 2005 0:54:58 A…. 1.056.768 1,01 M

    dxtrans.dll Sat 3 Sep 2005 0:54:58 A…. 205.312 200,50 K

    extmgr.dll Sat 3 Sep 2005 0:54:58 ….. 55.808 54,50 K

    gdi32.dll Thu 6 Oct 2005 4:19:02 A…. 280.064 273,50 K

    hr2u05~1.dll Tue 4 Oct 2005 10:21:58 ..S.R 232.245 226,80 K

    iepeers.dll Sat 3 Sep 2005 0:54:58 A…. 251.392 245,50 K

    inseng.dll Sat 3 Sep 2005 0:54:58 A…. 96.768 94,50 K

    linkinfo.dll Thu 1 Sep 2005 3:28:26 A…. 19.968 19,50 K

    lsprst7.dll Thu 3 Nov 2005 20:46:40 A…. 339 0,33 K

    mshtml.dll Tue 4 Oct 2005 17:27:36 A…. 3.013.120 2,87 M

    mshtmled.dll Sat 3 Sep 2005 0:55:02 A…. 448.512 438,00 K

    msrating.dll Sat 3 Sep 2005 0:55:02 A…. 146.432 143,00 K

    mstime.dll Sat 3 Sep 2005 0:55:04 A…. 530.432 518,00 K

    netman.dll Mon 22 Aug 2005 19:36:16 A…. 197.632 193,00 K

    pngfilt.dll Sat 3 Sep 2005 0:55:04 A…. 39.424 38,50 K

    quartz.dll Tue 30 Aug 2005 4:56:40 A…. 1.291.264 1,23 M

    shdocvw.dll Sat 3 Sep 2005 0:55:06 A…. 1.483.776 1,41 M

    shell32.dll Fri 23 Sep 2005 4:08:06 A…. 8.497.664 8,10 M

    shlwapi.dll Sat 3 Sep 2005 0:55:06 A…. 474.112 463,00 K

    sirenacm.dll Mon 19 Sep 2005 6:00:34 A…. 119.856 117,05 K

    ssprs.dll Thu 3 Nov 2005 20:14:04 A…. 73 0,07 K

    sysprs7.dll Wed 2 Nov 2005 21:50:20 A…. 1.025 1,00 K

    umpnpmgr.dll Tue 23 Aug 2005 4:40:36 A…. 124.416 121,50 K

    urlmon.dll Sat 3 Sep 2005 0:55:08 A…. 605.184 591,00 K

    vsdata.dll Mon 29 Aug 2005 18:08:34 A…. 83.712 81,75 K

    vsinit.dll Mon 29 Aug 2005 18:08:46 A…. 141.056 137,75 K

    vsmonapi.dll Mon 29 Aug 2005 18:08:54 A…. 104.192 101,75 K

    vspubapi.dll Mon 29 Aug 2005 18:08:58 A…. 227.072 221,75 K

    vsregexp.dll Mon 29 Aug 2005 18:09:02 A…. 71.424 69,75 K

    vsutil.dll Mon 29 Aug 2005 18:09:14 A…. 382.720 373,75 K

    vsxml.dll Mon 29 Aug 2005 18:09:22 A…. 100.096 97,75 K

    wininet.dll Sat 3 Sep 2005 0:55:08 A…. 661.504 646,00 K

    winsrv.dll Thu 1 Sep 2005 3:28:26 A…. 292.352 285,50 K

    zlcomm.dll Mon 29 Aug 2005 18:09:42 A…. 79.616 77,75 K

    zlcommdb.dll Mon 29 Aug 2005 18:09:46 A…. 71.424 69,75 K

    40 items found: 40 files (1 H/S), 0 directories.

    Total of file sizes: 24.628.740 bytes 23,48 M

    Locate .tmp files:

    No matches found.

    **********************************************************************************

    Directory Listing of system files:

    Het volume in station C heeft geen naam.

    Het volumenummer is 3439-B348

    Map van C:\WINDOWS\System32

    11-11-2005 13:47 11.690 KGyGaAvL.sys

    10-11-2005 13:57 dllcache

    04-10-2005 10:21 232.245 hr2u05f9e.dll

    17-02-2005 13:46 56 743811E9A9.sys

    31-10-2002 19:46 Microsoft

    3 bestand(en) 243.991 bytes

    2 map(pen) 2.679.504.896 bytes beschikbaar

    en de hijack..

    Logfile of HijackThis v1.99.1

    Scan saved at 13:35:35, on 12-11-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Logitech\iTouch\iTouch.exe

    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    C:\Program Files\Logitech\MouseWare\system\em_exec.exe

    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\Program Files\MSN Apps\Updater\01.05.0000.1009\nl\msnappau.exe

    D:\temp\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.home.nl/?from=start.home.nl

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.home.nl/

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer aangeboden door @Home

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)

    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O4 - HKLM\..\Run: C:\WINDOWS\System32\NeroCheck.exe

    O4 - HKLM\..\Run: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: nwiz.exe /install

    O4 - HKLM\..\Run: C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe

    O4 - HKLM\..\Run: C:\Program Files\Logitech\iTouch\iTouch.exe

    O4 - HKLM\..\Run: Logi_MwX.Exe

    O4 - HKLM\..\Run: F:\cleandiskpro\cleandisk.exe

    O4 - HKLM\..\Run: “F:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”

    O4 - HKLM\..\Run: C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “F:\Program Files\D-Tools\daemon.exe” -lang 1033

    O4 - HKLM\..\Run: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    O4 - HKLM\..\Run: F:\Program Files\@Home veiligheid\AntiVirus\AVRealTime.exe

    O4 - HKLM\..\Run: C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe

    O4 - HKLM\..\Run: F:\Program Files\Anti-Blaxx\Anti-Blaxx.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: rundll32.exe nview.dll,nViewLoadHook

    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html

    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html

    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html

    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://start.home.nl/

    O16 - DPF: FreedomAudio - http://download.worldchessnetwork.com/freedomaudio/freedominstaller.cab

    O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab

    O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab

    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab

    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

    O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://www.kennelclub.nl/media/scripts/ScriptX.cab

    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab

    O16 - DPF: {5D8844F9-1CB8-11D2-A0A0-00600859EB9F} (PatchCtl Class) - file://F:\Games\update.1.1\patchx2.cab

    O16 - DPF: {6211AC26-A1B4-422A-AC52-1E70B7D24465} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/nl/filesharingctrl.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100278409547

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/2003080601/housecall.antivirus.com/housecall/xscan53.cab

    O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37380.cab

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.bibliotheekzevenaar.nl/catalogus/msrdp.cab

    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab

    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab

    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game13.zylomgames.com/activex/zylomgamesplayer.cab

    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab

    O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab

    O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://game12.zylomgames.com/activex/zylomloader.cab

    O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab

    O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://gto.postbank.nl/GTO/PBGNX.cab

    O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/74914090/activex/IPSUploader.cab

    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab

    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.hema.nl/site/xupload/XUpload.ocx

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4618/mcfscan.cab

    O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/yiebio5_1_3_0.cab

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - “C:\PROGRA~1\MSNMES~1\msgrapp.dll” (file missing)

    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Unknown owner - F:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe (file missing)

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    groet rolf

  • pablo

    hoi rolf,

    of dit iets met je ftp verbinding te maken heeft betwijfel ik :?:)

    maar het zou kunnen ;)

    -Sluit alle openstaande programma's.

    -Dubbelklik op l2mfix.bat.

    -Klik op “2” om optie 2 te selecteren: Run Fix.

    -Druk op Enter.

    -Druk op een toets om de computer opnieuw te starten wanneer dit gevraagd wordt.

    Na de reboot verschijnen de ikonen op je desktop. Deze zullen weer verdwijnen. (dat is normaal).

    L2mfix gaat je computer scannen

    Wanneer het klaar is wordt er een nieuw kladblokbestand geopend.

    kopieer die tekst en plaats die hier, samen met een nieuw HijackThis-logje.

    paul :)

  • Rolf

    Hallo Pablo (of eenieder),

    mijn pc loopt vast (?) als ik de scan uitvoer. Dwz deze komt of niet voorbij het welkomscherm of staat een uur niets te doen zonder de icoonen. Of is het normaal dat dit zo lang duren kan.

    Ik heb iig geen fix bestandje. Wel een hijack log bij deze nog maar.

    Logfile of HijackThis v1.99.1

    Scan saved at 12:06:34, on 15-11-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe

    C:\Program Files\Logitech\iTouch\iTouch.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Logitech\MouseWare\system\em_exec.exe

    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\Program Files\MSN Apps\Updater\01.05.0000.1009\nl\msnappau.exe

    C:\WINDOWS\system32\wuauclt.exe

    D:\temp\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.home.nl/?from=start.home.nl

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.home.nl/

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer aangeboden door @Home

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)

    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\nl\msntb.dll

    O4 - HKLM\..\Run: C:\WINDOWS\System32\NeroCheck.exe

    O4 - HKLM\..\Run: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: nwiz.exe /install

    O4 - HKLM\..\Run: C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe

    O4 - HKLM\..\Run: C:\Program Files\Logitech\iTouch\iTouch.exe

    O4 - HKLM\..\Run: Logi_MwX.Exe

    O4 - HKLM\..\Run: F:\cleandiskpro\cleandisk.exe

    O4 - HKLM\..\Run: “F:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”

    O4 - HKLM\..\Run: C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “F:\Program Files\D-Tools\daemon.exe” -lang 1033

    O4 - HKLM\..\Run: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    O4 - HKLM\..\Run: F:\Program Files\@Home veiligheid\AntiVirus\AVRealTime.exe

    O4 - HKLM\..\Run: C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe

    O4 - HKLM\..\Run: F:\Program Files\Anti-Blaxx\Anti-Blaxx.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: rundll32.exe nview.dll,nViewLoadHook

    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html

    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html

    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html

    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://start.home.nl/

    O16 - DPF: FreedomAudio - http://download.worldchessnetwork.com/freedomaudio/freedominstaller.cab

    O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab

    O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab

    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab

    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

    O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://www.kennelclub.nl/media/scripts/ScriptX.cab

    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab

    O16 - DPF: {5D8844F9-1CB8-11D2-A0A0-00600859EB9F} (PatchCtl Class) - file://F:\Games\update.1.1\patchx2.cab

    O16 - DPF: {6211AC26-A1B4-422A-AC52-1E70B7D24465} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/nl/filesharingctrl.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100278409547

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/2003080601/housecall.antivirus.com/housecall/xscan53.cab

    O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37380.cab

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.bibliotheekzevenaar.nl/catalogus/msrdp.cab

    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab

    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab

    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game13.zylomgames.com/activex/zylomgamesplayer.cab

    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab

    O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab

    O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://game12.zylomgames.com/activex/zylomloader.cab

    O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab

    O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://gto.postbank.nl/GTO/PBGNX.cab

    O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/74914090/activex/IPSUploader.cab

    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab

    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.hema.nl/site/xupload/XUpload.ocx

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4618/mcfscan.cab

    O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/yiebio5_1_3_0.cab

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - “C:\PROGRA~1\MSNMES~1\msgrapp.dll” (file missing)

    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Unknown owner - F:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe (file missing)

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

  • pablo

    hoi rolf,

    open de L2M map en dubbelklik second.bat,plaats dat logje even ;)

    werkt dat ook niet plaats dan nog even een logje van optie 1 van het tooltje :)

    paul :)

  • Rolf

    Paul,

    allebei lopen ze vast.

    Tenzij een half uur gebruikelijk is maar dat geloof ik niet??

    dit is de log van optie 1

    dank vast

    L2MFIX find log 1.04a

    These are the registry keys present

    **********************************************************************************

    Winlogon/notify:

    Windows Registry Editor Version 5.00

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000000

    “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\

    6c,00,00,00

    “Logoff”=“ChainWlxLogoffEvent”

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000000

    “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Logoff”=“CryptnetWlxLogoffEvent”

    “DLLName”=“cscdll.dll”

    “Logon”=“WinlogonLogonEvent”

    “Logoff”=“WinlogonLogoffEvent”

    “ScreenSaver”=“WinlogonScreenSaverEvent”

    “Startup”=“WinlogonStartupEvent”

    “Shutdown”=“WinlogonShutdownEvent”

    “StartShell”=“WinlogonStartShellEvent”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000001

    “DLLName”=“wlnotify.dll”

    “Logon”=“SCardStartCertProp”

    “Logoff”=“SCardStopCertProp”

    “Lock”=“SCardSuspendCertProp”

    “Unlock”=“SCardResumeCertProp”

    “Enabled”=dword:00000001

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Impersonate”=dword:00000000

    “StartShell”=“SchedStartShell”

    “Logoff”=“SchedEventLogOff”

    “Logoff”=“WLEventLogoff”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000001

    “DllName”=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “DLLName”=“WlNotify.dll”

    “Lock”=“SensLockEvent”

    “Logon”=“SensLogonEvent”

    “Logoff”=“SensLogoffEvent”

    “Safe”=dword:00000001

    “MaxWait”=dword:00000258

    “StartScreenSaver”=“SensStartScreenSaverEvent”

    “StopScreenSaver”=“SensStopScreenSaverEvent”

    “Startup”=“SensStartupEvent”

    “Shutdown”=“SensShutdownEvent”

    “StartShell”=“SensStartShellEvent”

    “PostShell”=“SensPostShellEvent”

    “Disconnect”=“SensDisconnectEvent”

    “Reconnect”=“SensReconnectEvent”

    “Unlock”=“SensUnlockEvent”

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Impersonate”=dword:00000000

    “Logoff”=“TSEventLogoff”

    “Logon”=“TSEventLogon”

    “PostShell”=“TSEventPostShell”

    “Shutdown”=“TSEventShutdown”

    “StartShell”=“TSEventStartShell”

    “Startup”=“TSEventStartup”

    “MaxWait”=dword:00000258

    “Reconnect”=“TSEventReconnect”

    “Disconnect”=“TSEventDisconnect”

    “DLLName”=“wlnotify.dll”

    “Logon”=“RegisterTicketExpiredNotificationEvent”

    “Logoff”=“UnregisterTicketExpiredNotificationEvent”

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “DLLName”=“wzcdlg.dll”

    “Logon”=“WZCEventLogon”

    “Logoff”=“WZCEventLogoff”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000000

    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above

    Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)

    This program is Freeware, use it on your own risk!

    Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:

    (NI) ALLOW Full access NT AUTHORITY\SYSTEM

    (IO) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-NI) ALLOW Read INGEBOUWD\Gebruikers

    (ID-IO) ALLOW Read INGEBOUWD\Gebruikers

    (ID-NI) ALLOW Full access INGEBOUWD\Administrators

    (ID-IO) ALLOW Full access INGEBOUWD\Administrators

    (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-IO) ALLOW Full access MAKER EIGENAAR

    **********************************************************************************

    useragent:

    Windows Registry Editor Version 5.00

    “SV1”=“”

    **********************************************************************************

    Shell Extension key:

    Windows Registry Editor Version 5.00

    “{C169E5F0-E2B3-41F3-B81A-7BA529CBE193}”=“ZipGenius Shell Extension”

    “{2E5AC2E0-406D-11D4-86B3-FA5861508E25}”=“ZipGenius Zip InfoTip”

    “{FE8D01BF-610A-4261-9C6E-32D65A42C907}”=“ZipGenius 5.5 DnD Extract handler”

    “{310A0C95-EA11-42AE-A8E4-53E69E650310}”=“ZipGenius Zip Drop handler”

    @=“”

    “{1530F7EE-5128-43BD-9977-84A4B0FAD7DF}”=“PhotoToys”

    “{eb9ebda0-b3e7-11cf-81c9-0000c0aa665f}”=“FTP Explorer Shell Extension”

    “{BDEADF00-C265-11D0-BCED-00A0C90AB50F}”=“Webmappen”

    “{42042206-2D85-11D3-8CFF-005004838597}”=“Microsoft Office HTML Icon Handler”

    “{1EBC3533-B289-409F-9924-B84B3F0717D2}”=“AceFTP Context Menu Shell Extension”

    “{32020A01-506E-484D-A2A8-BE3CF17601C3}”=“AlcoholShellEx”

    “{1CDB2949-8F65-4355-8456-263E7C208A5D}”=“Bureaubladverkenner”

    “{1E9B04FB-F9E5-4718-997B-B8DA88302A47}”=“Desktop Explorer Menu”

    “{5F327514-6C5E-4d60-8F16-D07FA08A78ED}”=“Auto Update Property Sheet Extension”

    “{640167b4-59b0-47a6-b335-a6b3c0695aea}”=“Portable Media Devices”

    “{cc86590a-b60a-48e6-996b-41d25ed39a1e}”=“Portable Media Devices Menu”

    “{8DD448E6-C188-4aed-AF92-44956194EB1F}”=“Windows Media Player Play as Playlist Context Menu Handler”

    “{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}”=“Windows Media Player Burn Audio CD Context Menu Handler”

    “{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}”=“Windows Media Player Add to Playlist Context Menu Handler”

    “{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}”=“Shell Extensions for RealOne Player”

    “{043308A2-3CF7-4ED5-A668-2B4FB0BD307A}”=“dBpowerAMP dAP Scripting”

    “{FED7043D-346A-414D-ACD7-550D052499A7}”=“dBpowerAMP Popup Info”

    “{88901EED-E612-4C1A-B54E-EFBFB2E499E2}”=“SxContextMenu1”

    “{19EA5CFC-FADD-4F5B-884D-A1359B07550F}”=“SxContextMenu1”

    “{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}”=“Set Program Access and Defaults”

    “{596AB062-B4D2-4215-9F74-E9109B0A8153}”=“Previous Versions Property Page”

    “{9DB7A13C-F208-4981-8353-73CC61AE2783}”=“Previous Versions”

    “{692F0339-CBAA-47e6-B5B5-3B84DB604E87}”=“Extensions Manager Folder”

    “{7444C717-39BF-11D1-8CD9-00C04FC29D45}”=“Crypto PKO-extensie”

    “{7444C719-39BF-11D1-8CD9-00C04FC29D45}”=“Crypto-handtekeningextensie”

    **********************************************************************************

    HKEY ROOT CLASSIDS:

    **********************************************************************************

    Files Found are not all bad files:

    C:\WINDOWS\SYSTEM32\

    browseui.dll Sat 3 Sep 2005 0:54:56 A…. 1.020.416 996,50 K

    cdfview.dll Sat 3 Sep 2005 0:54:56 A…. 151.552 148,00 K

    cdosys.dll Sat 10 Sep 2005 2:55:38 A…. 2.067.968 1,97 M

    clauth1.dll Wed 2 Nov 2005 21:50:20 A…. 1.025 1,00 K

    clauth2.dll Wed 2 Nov 2005 21:50:20 A…. 1.025 1,00 K

    danim.dll Sat 3 Sep 2005 0:54:58 A…. 1.056.768 1,01 M

    dxtrans.dll Sat 3 Sep 2005 0:54:58 A…. 205.312 200,50 K

    extmgr.dll Sat 3 Sep 2005 0:54:58 ….. 55.808 54,50 K

    gdi32.dll Thu 6 Oct 2005 4:19:02 A…. 280.064 273,50 K

    iepeers.dll Sat 3 Sep 2005 0:54:58 A…. 251.392 245,50 K

    inseng.dll Sat 3 Sep 2005 0:54:58 A…. 96.768 94,50 K

    linkinfo.dll Thu 1 Sep 2005 3:28:26 A…. 19.968 19,50 K

    lsprst7.dll Thu 3 Nov 2005 20:46:40 A…. 339 0,33 K

    mshtml.dll Tue 4 Oct 2005 17:27:36 A…. 3.013.120 2,87 M

    mshtmled.dll Sat 3 Sep 2005 0:55:02 A…. 448.512 438,00 K

    msrating.dll Sat 3 Sep 2005 0:55:02 A…. 146.432 143,00 K

    mstime.dll Sat 3 Sep 2005 0:55:04 A…. 530.432 518,00 K

    netman.dll Mon 22 Aug 2005 19:36:16 A…. 197.632 193,00 K

    pngfilt.dll Sat 3 Sep 2005 0:55:04 A…. 39.424 38,50 K

    quartz.dll Tue 30 Aug 2005 4:56:40 A…. 1.291.264 1,23 M

    shdocvw.dll Sat 3 Sep 2005 0:55:06 A…. 1.483.776 1,41 M

    shell32.dll Fri 23 Sep 2005 4:08:06 A…. 8.497.664 8,10 M

    shlwapi.dll Sat 3 Sep 2005 0:55:06 A…. 474.112 463,00 K

    sirenacm.dll Mon 19 Sep 2005 6:00:34 A…. 119.856 117,05 K

    ssprs.dll Thu 3 Nov 2005 20:14:04 A…. 73 0,07 K

    sysprs7.dll Wed 2 Nov 2005 21:50:20 A…. 1.025 1,00 K

    umpnpmgr.dll Tue 23 Aug 2005 4:40:36 A…. 124.416 121,50 K

    urlmon.dll Sat 3 Sep 2005 0:55:08 A…. 605.184 591,00 K

    vsdata.dll Mon 29 Aug 2005 18:08:34 A…. 83.712 81,75 K

    vsinit.dll Mon 29 Aug 2005 18:08:46 A…. 141.056 137,75 K

    vsmonapi.dll Mon 29 Aug 2005 18:08:54 A…. 104.192 101,75 K

    vspubapi.dll Mon 29 Aug 2005 18:08:58 A…. 227.072 221,75 K

    vsregexp.dll Mon 29 Aug 2005 18:09:02 A…. 71.424 69,75 K

    vsutil.dll Mon 29 Aug 2005 18:09:14 A…. 382.720 373,75 K

    vsxml.dll Mon 29 Aug 2005 18:09:22 A…. 100.096 97,75 K

    wininet.dll Sat 3 Sep 2005 0:55:08 A…. 661.504 646,00 K

    winsrv.dll Thu 1 Sep 2005 3:28:26 A…. 292.352 285,50 K

    zlcomm.dll Mon 29 Aug 2005 18:09:42 A…. 79.616 77,75 K

    zlcommdb.dll Mon 29 Aug 2005 18:09:46 A…. 71.424 69,75 K

    39 items found: 39 files, 0 directories.

    Total of file sizes: 24.396.495 bytes 23,27 M

    Locate .tmp files:

    No matches found.

    **********************************************************************************

    Directory Listing of system files:

    Het volume in station C heeft geen naam.

    Het volumenummer is 3439-B348

    Map van C:\WINDOWS\System32

    11-11-2005 13:47 11.690 KGyGaAvL.sys

    10-11-2005 13:57 dllcache

    17-02-2005 13:46 56 743811E9A9.sys

    31-10-2002 19:46 Microsoft

    2 bestand(en) 11.746 bytes

    2 map(pen) 2.577.944.576 bytes beschikbaar

  • pablo

    hoi rolf,

    je logje is schoon,het tooltje heeft zijn werk toch goed gedaan ;):)

    hoe is het verder met je problemen nu?

    paul :)

  • rolf

    Dat is prachtig Paul, en

    ja ik zit nog altijd met een F: die D: heet en een extra dvd speler (die ik niet heb) die F: heet. Ik draai home edition dus even simpel editten is er niet bij. Misschien dat je dat nog even kan richtlijnen voor me? Daarna moet alles weer naar behoren functioneren..hoop ik.

    Ik ben niet helemaal leek. Dus met een klein stappen en wat vooral niet tedoen kom ik een heel eind.

    Waar moet het de fles wijn heen?

    groet rolf

  • pablo

    hoi rolf,

    proost maar een keer op me,dan is het ook goed ;):D

    en lukt het om het te veranderen als je rechtsklikt op “deze computer” en beheren-schijfbeheer kiest?

    je kan dan eerst die nieuwe F: schijf hernoemen naar G: en dan kan je D: hernoemen naar F:

    ( rechtsklikken op een schijf en kiezen voor “stationsletters en paden wijzigen” )

    let wel op dat als je een partitie van schijfletter verandert dat dat gevolgen heeft voor de op die partitie geinstalleerde programma's,je registerverwijzingen kloppen dan niet meer :)

    anders kan je die vraag beter even bij de buren stellen:

    http://www.prikpagina.nl/read.php?f=571

    paul