Logfile of HijackThis v1.99.1

  • thomas

    Logfile of HijackThis v1.99.1

    Scan saved at 8:41:47, on 10-11-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\Hitman Pro\srhelper.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Norton AntiVirus\navapsvc.exe

    C:\Program Files\Eset\nod32krn.exe

    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe

    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Aware.exe

    c:\program files\InterMute\SpySubtract\CWShredder.exe

    C:\Documents and Settings\Dhr. te Orré\Bureaublad\hijackthis.exe

    C:\Program Files\Messenger\msmsgs.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - URLSearchHook: ScriptInocUI Class - - (no file)

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”

    O4 - HKCU\..\Run: “C:\Program Files\Hitman Pro\srhelper.exe”

    O4 - HKCU\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm

    O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm

    O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm

    O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O20 - Winlogon Notify: Control Panel - C:\WINDOWS\system32\dnprop.dll (file missing)

    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll

    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

    O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe

    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    dit is mijn logfile. ik heb/had een virus..trojen ik heb hiervoor hitman pro gebruikt alleen bij het uitvoeren in veiligmodus ging hij niet 100% door maar als ik het in normaal modus doe doet hij het wel goed en hij geeft niets meer aan. alleen nu heb ik het probleem dak me programma's niet meer kan gebruiken: norton, ATI Catalyst Control Center, en krijg steets reclame. heel vervelend als je bv fifa aan het doen bent. help aub

  • thomas

    help aub

  • pablo

    hoi thomas

    Download L2Mfix.

    -Plaats het bestand op je bureaublad.

    -Klik op l2mfix.exe.

    -Klik op Accept.

    -Zorg dat de l2mfix-map op je bureaublad geplaatst wordt.

    -Klik op Install.

    -Op je bureaublad open je de map l2mfix.

    -Klik op l2fix.bat.

    -Klik op “1” om optie te 1 selecteren: Run Find Log.

    -Dit gaat even duren. Na een tijdje wordt er een kladblokbestand geopend.

    kopieer die tekst en plaats die hier, samen met een nieuw HijackThis-logje.

    paul :)

  • thomas

    bedankt

    dit duurde maar 2 sec maar hier is het

    L2MFIX find log 1.04a

    These are the registry keys present

    **********************************************************************************

    Winlogon/notify:

    Windows Registry Editor Version 5.00

    “DLLName”=“Ati2evxx.dll”

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000001

    “Lock”=“AtiLockEvent”

    “Logoff”=“AtiLogoffEvent”

    “Logon”=“AtiLogonEvent”

    “Disconnect”=“AtiDisConnectEvent”

    “Reconnect”=“AtiReConnectEvent”

    “Safe”=dword:00000000

    “Shutdown”=“AtiShutdownEvent”

    “StartScreenSaver”=“AtiStartScreenSaverEvent”

    “StartShell”=“AtiStartShellEvent”

    “Startup”=“AtiStartupEvent”

    “StopScreenSaver”=“AtiStopScreenSaverEvent”

    “Unlock”=“AtiUnLockEvent”

    Logfile of HijackThis v1.99.1

    Scan saved at 22:16:45, on 10-11-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Norton AntiVirus\navapsvc.exe

    C:\Program Files\Eset\nod32krn.exe

    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\WINDOWS\system32\cmd.exe

    C:\WINDOWS\system32\ntvdm.exe

    C:\WINDOWS\system32\NOTEPAD.EXE

    C:\Documents and Settings\Dhr. te Orré\Bureaublad\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    O4 - HKLM\..\Run: C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

    O4 - HKLM\..\Run: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    O4 - HKLM\..\Run: “C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” runtime

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”

    O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe

    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

    O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe

    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    oke en verder???

  • thomas

    help

  • pablo

    hoi thomas,

    je hebt maar een half log van het L2M tooltje geplaatst :?:)

    plaats dat nog even helemaal ;)

    paul :)

  • thomas

    dit is hem dan maar ik heb echt alles er op gezet vage shit

    hopenlijk kun je me nu helpen want norton werkt niet en windows kan ik niet meer updaten want hij zegt dat hij iligaal is:S maar heb gwn orgineel.

    L2MFIX find log 1.04a

    These are the registry keys present

    **********************************************************************************

    Winlogon/notify:

    Windows Registry Editor Version 5.00

    “DLLName”=“Ati2evxx.dll”

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000001

    “Lock”=“AtiLockEvent”

    “Logoff”=“AtiLogoffEvent”

    “Logon”=“AtiLogonEvent”

    “Disconnect”=“AtiDisConnectEvent”

    “Reconnect”=“AtiReConnectEvent”

    “Safe”=dword:00000000

    “Shutdown”=“AtiShutdownEvent”

    “StartScreenSaver”=“AtiStartScreenSaverEvent”

    “StartShell”=“AtiStartShellEvent”

    “Startup”=“AtiStartupEvent”

    “StopScreenSaver”=“AtiStopScreenSaverEvent”

    “Unlock”=“AtiUnLockEvent”

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000000

    “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\

    6c,00,00,00

    “Logoff”=“ChainWlxLogoffEvent”

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000000

    “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Logoff”=“CryptnetWlxLogoffEvent”

    “DLLName”=“cscdll.dll”

    “Logon”=“WinlogonLogonEvent”

    “Logoff”=“WinlogonLogoffEvent”

    “ScreenSaver”=“WinlogonScreenSaverEvent”

    “Startup”=“WinlogonStartupEvent”

    “Shutdown”=“WinlogonShutdownEvent”

    “StartShell”=“WinlogonStartShellEvent”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000001

    “DLLName”=“wlnotify.dll”

    “Logon”=“SCardStartCertProp”

    “Logoff”=“SCardStopCertProp”

    “Lock”=“SCardSuspendCertProp”

    “Unlock”=“SCardResumeCertProp”

    “Enabled”=dword:00000001

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Impersonate”=dword:00000000

    “StartShell”=“SchedStartShell”

    “Logoff”=“SchedEventLogOff”

    “Logoff”=“WLEventLogoff”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000001

    “DllName”=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “DLLName”=“WlNotify.dll”

    “Lock”=“SensLockEvent”

    “Logon”=“SensLogonEvent”

    “Logoff”=“SensLogoffEvent”

    “Safe”=dword:00000001

    “MaxWait”=dword:00000258

    “StartScreenSaver”=“SensStartScreenSaverEvent”

    “StopScreenSaver”=“SensStopScreenSaverEvent”

    “Startup”=“SensStartupEvent”

    “Shutdown”=“SensShutdownEvent”

    “StartShell”=“SensStartShellEvent”

    “PostShell”=“SensPostShellEvent”

    “Disconnect”=“SensDisconnectEvent”

    “Reconnect”=“SensReconnectEvent”

    “Unlock”=“SensUnlockEvent”

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Impersonate”=dword:00000000

    “Logoff”=“TSEventLogoff”

    “Logon”=“TSEventLogon”

    “PostShell”=“TSEventPostShell”

    “Shutdown”=“TSEventShutdown”

    “StartShell”=“TSEventStartShell”

    “Startup”=“TSEventStartup”

    “MaxWait”=dword:00000258

    “Reconnect”=“TSEventReconnect”

    “Disconnect”=“TSEventDisconnect”

    “DLLName”=“wlnotify.dll”

    “Logon”=“RegisterTicketExpiredNotificationEvent”

    “Logoff”=“UnregisterTicketExpiredNotificationEvent”

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “DLLName”=“wzcdlg.dll”

    “Logon”=“WZCEventLogon”

    “Logoff”=“WZCEventLogoff”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000000

    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above

    Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)

    This program is Freeware, use it on your own risk!

    Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:

    (NI) ALLOW Full access NT AUTHORITY\SYSTEM

    (IO) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-CI) DENY –C——- INGEBOUWD\Administrators

    (ID-NI) ALLOW Read INGEBOUWD\Gebruikers

    (ID-IO) ALLOW Read INGEBOUWD\Gebruikers

    (ID-NI) ALLOW Full access INGEBOUWD\Administrators

    (ID-IO) ALLOW Full access INGEBOUWD\Administrators

    (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-IO) ALLOW Full access MAKER EIGENAAR

    **********************************************************************************

    useragent:

    Windows Registry Editor Version 5.00

    “{C253BB1A-4D0A-0840-1D6A-698F79EA25A6}”=“”

    **********************************************************************************

    Shell Extension key:

    Windows Registry Editor Version 5.00

    “{00022613-0000-0000-C000-000000000046}”=“Eigenschappenvenster van multimediabestand”

    “{176d6597-26d3-11d1-b350-080036a75b03}”=“ICM-scannerbeheer”

    “{1F2E5C40-9550-11CE-99D2-00AA006E086C}”=“Het tabblad Beveiliging”

    “{3EA48300-8CF6-101B-84FB-666CCB9BCD32}”=“Eigenschappenblad voor OLE-docbestand”

    “{40dd6e20-7c17-11ce-a804-00aa003ca9f6}”=“Shell-uitbreidingen voor delen”

    “{41E300E0-78B6-11ce-849B-444553540000}”=“PlusPack CPL Extension”

    “{42071712-76d4-11d1-8b24-00a0c9068ff3}”=“Configuratiescherm-uitbreiding Beeldschermadapter”

    “{42071713-76d4-11d1-8b24-00a0c9068ff3}”=“Configuratiescherm-uitbreiding Monitor”

    “{42071714-76d4-11d1-8b24-00a0c9068ff3}”=“Configuratiescherm-uitbreiding Beeldscherm-panning”

    “{4E40F770-369C-11d0-8922-00A024AB2DBB}”=“Het tabblad Beveiliging”

    “{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}”=“Compatibiliteitspagina”

    “{56117100-C0CD-101B-81E2-00AA004AE837}”=“Knipselgegevensverwerker van shell”

    “{59099400-57FF-11CE-BD94-0020AF85B590}”=“Schijfkopieer-uitbreiding”

    “{59be4990-f85c-11ce-aff7-00aa003ca9f6}”=“Shell-uitbreidingen voor Microsoft Windows Network-objecten”

    “{5DB2625A-54DF-11D0-B6C4-0800091AA605}”=“ICM-monitorbeheer”

    “{675F097E-4C4D-11D0-B6C1-0800091AA605}”=“ICM-printerbeheer”

    “{764BF0E1-F219-11ce-972D-00AA00A14F56}”=“Shell-uitbreidingen voor bestandscompressie”

    “{77597368-7b15-11d0-a0c2-080036af3f03}”=“Shell-uitbreiding voor Web Printer”

    “{7988B573-EC89-11cf-9C00-00AA00A14F56}”=“Disk Quota UI”

    “{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}”=“Snelmenu Codering”

    “{85BBD920-42A0-1069-A2E4-08002B30309D}”=“Werkmap”

    “{88895560-9AA2-1069-930E-00AA0030EBC8}”=“HyperTerminal-pictogramuitbreiding”

    “{BD84B380-8CA2-1069-AB1D-08000948F534}”=“Fonts”

    “{DBCE2480-C732-101B-BE72-BA78E9AD5B27}”=“ICC-profiel”

    “{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}”=“Het tabblad Beveiliging voor printers”

    “{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}”=“Shell-uitbreidingen voor delen”

    “{f92e8c40-3d33-11d2-b1aa-080036a75b03}”=“Display TroubleShoot CPL Extension”

    “{7444C717-39BF-11D1-8CD9-00C04FC29D45}”=“Crypto PKO-extensie”

    “{7444C719-39BF-11D1-8CD9-00C04FC29D45}”=“Crypto-handtekeningextensie”

    “{7007ACC7-3202-11D1-AAD2-00805FC1270E}”=“Netwerkverbindingen”

    “{992CFFA0-F557-101A-88EC-00DD010CCC48}”=“Netwerkverbindingen”

    “{E211B736-43FD-11D1-9EFB-0000F8757FCD}”=“Scanners en camera's”

    “{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}”=“Scanners en camera's”

    “{905667aa-acd6-11d2-8080-00805f6596d2}”=“Scanners en camera's”

    “{3F953603-1008-4f6e-A73A-04AAC7A992F1}”=“Scanners en camera's”

    “{83bbcbf3-b28a-4919-a5aa-73027445d672}”=“Scanners en camera's”

    “{F0152790-D56E-4445-850E-4F3117DB740C}”=“Remote Sessions CPL Extension”

    “{60254CA5-953B-11CF-8C96-00AA00B8708C}”=“Shell-uitbreidingen voor Windows Script Host”

    “{2206CDB2-19C1-11D1-89E0-00C04FD7A829}”=“Microsoft Data Link”

    “{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}”=“Tasks Folder Icon Handler”

    “{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}”=“Tasks Folder Shell Extension”

    “{D6277990-4C6A-11CF-8D87-00AA0060F5BF}”=“Geplande taken”

    “{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}”=“Set Program Access and Defaults”

    “{5F327514-6C5E-4d60-8F16-D07FA08A78ED}”=“Auto Update Property Sheet Extension”

    “{0DF44EAA-FF21-4412-828E-260A8728E7F1}”=“Taakbalk en menu Start”

    “{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}”=“Zoeken”

    “{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}”=“Help en ondersteuning”

    “{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}”=“Help en ondersteuning”

    “{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}”=“Uitvoeren…”

    “{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}”=“Internet”

    “{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}”=“E-mail”

    “{D20EA4E1-3957-11d2-A40B-0C5020524152}”=“Lettertypen”

    “{D20EA4E1-3957-11d2-A40B-0C5020524153}”=“Systeembeheer”

    “{596AB062-B4D2-4215-9F74-E9109B0A8153}”=“Eigenschappenpagina van vorige versies”

    “{9DB7A13C-F208-4981-8353-73CC61AE2783}”=“Vorige versies”

    “{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}”=“Audio Media Properties Handler”

    “{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}”=“Video Media Properties Handler”

    “{E4B29F9D-D390-480b-92FD-7DDB47101D71}”=“Wav Properties Handler”

    “{87D62D94-71B3-4b9a-9489-5FE6850DC73E}”=“Avi Properties Handler”

    “{A6FD9E45-6E44-43f9-8644-08598F5A74D9}”=“Midi Properties Handler”

    “{c5a40261-cd64-4ccf-84cb-c394da41d590}”=“Video Thumbnail Extractor”

    “{5E6AB780-7743-11CF-A12B-00AA004AE837}”=“Microsoft Internet-werkbalk”

    “{22BF0C20-6DA7-11D0-B373-00A0C9034938}”=“Downloadstatus”

    “{91EA3F8B-C99B-11d0-9815-00C04FD91972}”=“Uitgebreide shell-map”

    “{6413BA2C-B461-11d1-A18A-080036B11A03}”=“Uitgebreide shell-map 2”

    “{F61FFEC1-754F-11d0-80CA-00AA005B4383}”=“BandProxy”

    “{7BA4C742-9E81-11CF-99D3-00AA004AE837}”=“Microsoft-browserbalk”

    “{30D02401-6A81-11d0-8274-00C04FD5AE38}”=“Zoekbalk”

    “{169A0691-8DF9-11d1-A1C4-00C04FD75D13}”=“Zoeken binnen deelvenster”

    “{07798131-AF23-11d1-9111-00A0C98BA67D}”=“Zoeken op het web”

    “{AF4F6510-F982-11d0-8595-00AA004CD6D8}”=“Hulpprogramma met opties voor registerboomstructuur”

    “{01E04581-4EEE-11d0-BFE9-00AA005B4383}”=“&Adres”

    “{A08C11D2-A228-11d0-825B-00AA005B4383}”=“Address EditBox”

    “{00BB2763-6A77-11D0-A535-00C04FD7D062}”=“Microsoft AutoAanvullen”

    “{7376D660-C583-11d0-A3A5-00C04FD706EC}”=“TridentImageExtractor”

    “{6756A641-DE71-11d0-831B-00AA005B4383}”=“MRU-lijst voor AutoAanvullen”

    “{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}”=“Aangepaste MRU-lijst voor AutoAanvullen”

    “{7e653215-fa25-46bd-a339-34a2790f3cb7}”=“Toegankelijk”

    “{acf35015-526e-4230-9596-becbe19f0ac9}”=“Pop-upbalk Volgen”

    “{00BB2764-6A77-11D0-A535-00C04FD7D062}”=“Lijst voor AutoAanvullen: Microsoft Geschiedenis”

    “{03C036F1-A186-11D0-824A-00AA005B4383}”=“Lijst voor AutoAanvullen: Microsoft Shell-map”

    “{00BB2765-6A77-11D0-A535-00C04FD7D062}”=“Microsoft-container met meervoudige lijst voor AutoAanvullen”

    “{ECD4FC4E-521C-11D0-B792-00A0C90312E1}”=“Sitemenu van shell-band”

    “{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}”=“Shell DeskBarApp”

    “{ECD4FC4C-521C-11D0-B792-00A0C90312E1}”=“Shell DeskBar”

    “{ECD4FC4D-521C-11D0-B792-00A0C90312E1}”=“Shell Rebar BandSite”

    “{DD313E04-FEFF-11d1-8ECD-0000F87A470C}”=“Gebruikersondersteuning”

    “{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}”=“Globale mapinstellingen”

    “{EFA24E61-B078-11d0-89E4-00C04FC9E26E}”=“Favorites Band”

    “{0A89A860-D7B1-11CE-8350-444553540000}”=“Shell Automation Inproc Service”

    “{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}”=“Shell DocObject Viewer”

    “{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}”=“Microsoft Browser Architecture”

    “{FBF23B40-E3F0-101B-8488-00AA003E56F8}”=“InternetShortcut”

    “{3C374A40-BAE4-11CF-BF7D-00AA006946EE}”=“Microsoft Url-geschiedenisservice”

    “{FF393560-C2A7-11CF-BFF4-444553540000}”=“Geschiedenis”

    “{7BD29E00-76C1-11CF-9DD0-00A0C9034933}”=“Tijdelijke Internet-bestanden”

    “{7BD29E01-76C1-11CF-9DD0-00A0C9034933}”=“Tijdelijke Internet-bestanden”

    “{CFBFAE00-17A6-11D0-99CB-00C04FD64497}”=“Microsoft Url-zoeken Hook”

    “{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}”=“IE4 Suite-welkomstscherm”

    “{67EA19A0-CCEF-11d0-8024-00C04FD75D13}”=“CDF Extension Copy Hook”

    “{131A6951-7F78-11D0-A979-00C04FD705A2}”=“ISFBand OC”

    “{9461b922-3c5a-11d2-bf8b-00c04fb93661}”=“Search Assistant OC”

    “{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}”=“Het Internet”

    “{871C5380-42A0-1069-A2EA-08002B30309D}”=“Internet Name Space”

    “{EFA24E64-B078-11d0-89E4-00C04FC9E26E}”=“Explorer-band”

    “{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}”=“Sendmail service”

    “{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}”=“Sendmail service”

    “{88C6C381-2E85-11D0-94DE-444553540000}”=“Cachemap van ActiveX”

    “{E6FB5E20-DE35-11CF-9C87-00AA005127ED}”=“WebCheck”

    “{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}”=“Subscription Mgr”

    “{F5175861-2688-11d0-9C5E-00AA00A45957}”=“Map met abonnementen”

    “{08165EA0-E946-11CF-9C87-00AA005127ED}”=“WebCheckWebCrawler”

    “{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}”=“WebCheckChannelAgent”

    “{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}”=“TrayAgent”

    “{7D559C10-9FE9-11d0-93F7-00AA0059CE02}”=“Code Download Agent”

    “{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}”=“ConnectionAgent”

    “{D8BD2030-6FC9-11D0-864F-00AA006809D9}”=“PostAgent”

    “{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}”=“WebCheck SyncMgr Handler”

    “{352EC2B7-8B9A-11D1-B8AE-006008059382}”=“Shell Toepassingsbeheer”

    “{0B124F8F-91F0-11D1-B8B5-006008059382}”=“Programma voor inventarisatie van ge‹nstalleerde toepassingen”

    “{CFCCC7A0-A282-11D1-9082-006008059382}”=“Darwin App Publisher”

    “{e84fda7c-1d6a-45f6-b725-cb260c236066}”=“Shell Image Verbs”

    “{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}”=“Shell Image Data Factory”

    “{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}”=“Autoplay for SlideShow”

    “{3F30C968-480A-4C6C-862D-EFC0897BB84B}”=“GDI- en bestandsextractieprogramma voor miniaturen”

    “{9DBD2C50-62AD-11d0-B806-00C04FD706EC}”=“Informatie over de handler voor miniatuurweergaven (DOCFILES)”

    “{EAB841A0-9550-11cf-8C16-00805F1408F3}”=“HTML-extractie voor miniatuurweergaven”

    “{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}”=“Shell Image Property Handler”

    “{CC6EEFFB-43F6-46c5-9619-51D571967F7D}”=“Wizard Webpublicaties”

    “{add36aa8-751a-4579-a266-d66f5202ccbb}”=“Afdrukken via het web bestellen”

    “{6b33163c-76a5-4b6c-bf21-45de9cd503a1}”=“Shell-object voor publicatiewizard”

    “{58f1f272-9240-4f51-b6d4-fd63d1618591}”=“Wizard Passport”

    “{7A9D77BD-5403-11d2-8785-2E0420524153}”=“Gebruikersaccounts”

    “{BD472F60-27FA-11cf-B8B4-444553540000}”=“Compressed (zipped) Folder Right Drag Handler”

    “{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}”=“Compressed (zipped) Folder SendTo Target”

    “{692F0339-CBAA-47e6-B5B5-3B84DB604E87}”=“Extensions Manager Folder”

    “{63da6ec0-2e98-11cf-8d82-444553540000}”=“FTP Folders Webview”

    “{883373C3-BF89-11D1-BE35-080036B11A03}”=“Microsoft DocProp Shell Ext”

    “{A9CF0EAE-901A-4739-A481-E35B73E47F6D}”=“Microsoft DocProp Inplace Edit Box Control”

    “{8EE97210-FD1F-4B19-91DA-67914005F020}”=“Microsoft DocProp Inplace ML Edit Box Control”

    “{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}”=“Microsoft DocProp Inplace Droplist Combo Control”

    “{6A205B57-2567-4A2C-B881-F787FAB579A3}”=“Microsoft DocProp Inplace Calendar Control”

    “{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}”=“Microsoft DocProp Inplace Time Control”

    “{8A23E65E-31C2-11d0-891C-00A024AB2DBB}”=“Directory Query UI”

    “{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}”=“Shell properties for a DS object”

    “{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}”=“Directory Object Find”

    “{F020E586-5264-11d1-A532-0000F8757D7E}”=“Directory Start/Search Find”

    “{0D45D530-764B-11d0-A1CA-00AA00C16E65}”=“Directory Property UI”

    “{62AE1F9A-126A-11D0-A14B-0800361B1103}”=“Directory Context Menu Verbs”

    “{ECF03A33-103D-11d2-854D-006008059367}”=“MyDocs Copy Hook”

    “{ECF03A32-103D-11d2-854D-006008059367}”=“MyDocs Drop Target”

    “{4a7ded0a-ad25-11d0-98a8-0800361b1103}”=“MyDocs Properties”

    “{750fdf0e-2a26-11d1-a3ea-080036587f03}”=“Offline Files Menu”

    “{10CFC467-4392-11d2-8DB4-00C04FA31A66}”=“Offline Files Folder Options”

    “{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}”=“Map Off line bestanden”

    “{143A62C8-C33B-11D1-84FE-00C04FA34A14}”=“Microsoft Agent Character Property Sheet Handler”

    “{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}”=“DfsShell”

    “{60fd46de-f830-4894-a628-6fa81bc0190d}”=“%DESC_PublishDropTarget%”

    “{7A80E4A8-8005-11D2-BCF8-00C04F72C717}”=“MMC Icon Handler”

    “{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}”=“.CAB file viewer”

    “{32714800-2E5F-11d0-8B85-00AA0044F941}”=“&Personen…”

    “{8DD448E6-C188-4aed-AF92-44956194EB1F}”=“Windows Media Player Play as Playlist Context Menu Handler”

    “{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}”=“Windows Media Player Burn Audio CD Context Menu Handler”

    “{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}”=“Windows Media Player Add to Playlist Context Menu Handler”

    “{1D2680C9-0E2A-469d-B787-065558BC7D43}”=“Fusion Cache”

    “{640167b4-59b0-47a6-b335-a6b3c0695aea}”=“Portable Media Devices”

    “{cc86590a-b60a-48e6-996b-41d25ed39a1e}”=“Portable Media Devices Menu”

    “{E0D79304-84BE-11CE-9641-444553540000}”=“WinZip”

    “{E0D79305-84BE-11CE-9641-444553540000}”=“WinZip”

    “{E0D79306-84BE-11CE-9641-444553540000}”=“WinZip”

    “{E0D79307-84BE-11CE-9641-444553540000}”=“WinZip”

    “{B41DB860-8EE4-11D2-9906-E49FADC173CA}”=“WinRAR shell extension”

    “{e57ce731-33e8-4c51-8354-bb4de9d215d1}”=“Universele Plug en Play-apparaten”

    “{BDEADF00-C265-11D0-BCED-00A0C90AB50F}”=“Webmappen”

    “{42042206-2D85-11D3-8CFF-005004838597}”=“Microsoft Office HTML Icon Handler”

    “{f39a0dc0-9cc8-11d0-a599-00c04fd64433}”=“Kanaal-bestand”

    “{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}”=“Kanaal-snelkoppeling”

    “{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}”=“Handler-object voor kanalen”

    “{f3da0dc0-9cc8-11d0-a599-00c04fd64437}”=“Channel Menu”

    “{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}”=“Channel Properties”

    “{32020A01-506E-484D-A2A8-BE3CF17601C3}”=“AlcoholShellEx”

    “{22122C53-4438-4A1D-92E8-9E9CA2A4A17B}”=“”

    “{e82a2d71-5b2f-43a0-97b8-81be15854de8}”=“ShellLink for Application References”

    “{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}”=“Shell Icon Handler for Application References”

    “{5E2121EE-0300-11D4-8D3B-444553540000}”=“Catalyst Context Menu extension”

    **********************************************************************************

    HKEY ROOT CLASSIDS:

    **********************************************************************************

    Files Found are not all bad files:

    C:\WINDOWS\SYSTEM32\

    browseui.dll Sat 3 Sep 2005 0:54:56 A…. 1.020.416 996,50 K

    cdfview.dll Sat 3 Sep 2005 0:54:56 A…. 151.552 148,00 K

    cdosys.dll Sat 10 Sep 2005 2:55:38 A…. 2.067.968 1,97 M

    danim.dll Sat 3 Sep 2005 0:54:58 A…. 1.056.768 1,01 M

    dfshim.dll Fri 23 Sep 2005 7:28:38 A…. 83.456 81,50 K

    dxtrans.dll Sat 3 Sep 2005 0:54:58 A…. 205.312 200,50 K

    extmgr.dll Sat 3 Sep 2005 0:54:58 A…. 55.808 54,50 K

    gdi32.dll Thu 6 Oct 2005 4:19:02 A…. 280.064 273,50 K

    iepeers.dll Sat 3 Sep 2005 0:54:58 A…. 251.392 245,50 K

    inseng.dll Sat 3 Sep 2005 0:54:58 A…. 96.768 94,50 K

    jt8607~1.dll Wed 9 Nov 2005 22:00:12 ..S.R 236.086 230,55 K

    legitc~1.dll Mon 29 Aug 2005 12:27:12 A…. 520.968 508,76 K

    linkinfo.dll Thu 1 Sep 2005 3:28:26 A…. 19.968 19,50 K

    mscoree.dll Fri 23 Sep 2005 7:28:52 A…. 270.848 264,50 K

    mscorier.dll Fri 23 Sep 2005 7:28:52 A…. 150.016 146,50 K

    mscories.dll Fri 23 Sep 2005 7:28:52 A…. 74.240 72,50 K

    mshtml.dll Wed 5 Oct 2005 1:27:34 A…. 3.013.120 2,87 M

    mshtmled.dll Sat 3 Sep 2005 0:55:02 A…. 448.512 438,00 K

    msrating.dll Sat 3 Sep 2005 0:55:02 A…. 146.432 143,00 K

    msssc.dll Thu 10 Nov 2005 17:01:16 A…. 44 0,04 K

    mstime.dll Sat 3 Sep 2005 0:55:04 A…. 530.432 518,00 K

    netman.dll Mon 22 Aug 2005 19:36:16 A…. 197.632 193,00 K

    pngfilt.dll Sat 3 Sep 2005 0:55:04 A…. 39.424 38,50 K

    q8860i~1.dll Tue 8 Nov 2005 22:59:48 ..S.R 236.318 230,78 K

    quartz.dll Tue 30 Aug 2005 4:56:40 A…. 1.291.264 1,23 M

    shdocvw.dll Sat 3 Sep 2005 0:55:06 A…. 1.483.776 1,41 M

    shell32.dll Fri 23 Sep 2005 4:08:06 A…. 8.497.664 8,10 M

    shlwapi.dll Sat 3 Sep 2005 0:55:06 A…. 474.112 463,00 K

    sirenacm.dll Wed 12 Oct 2005 23:11:06 A…. 118.784 116,00 K

    umpnpmgr.dll Tue 23 Aug 2005 4:40:36 A…. 124.416 121,50 K

    urlmon.dll Sat 3 Sep 2005 0:55:08 A…. 605.184 591,00 K

    wininet.dll Sat 3 Sep 2005 0:55:08 A…. 661.504 646,00 K

    winsrv.dll Thu 1 Sep 2005 3:28:26 A…. 292.352 285,50 K

    woadmod.dll Tue 8 Nov 2005 22:21:48 ..S.R 236.318 230,78 K

    34 items found: 34 files (3 H/S), 0 directories.

    Total of file sizes: 24.938.918 bytes 23,78 M

    Locate .tmp files:

    No matches found.

    **********************************************************************************

    Directory Listing of system files:

    Het volume in station C heeft geen naam.

    Het volumenummer is F8BE-48D7

    Map van C:\WINDOWS\System32

    10-11-2005 17:01 dllcache

    09-11-2005 22:00 236.086 jt8607lse.dll

    08-11-2005 22:59 236.318 q8860ilse8q60.dll

    08-11-2005 22:21 236.318 woadmod.dll

    11-07-2005 19:20 14.848 Thumbs.db

    30-06-2005 18:29 Microsoft

    4 bestand(en) 723.570 bytes

    2 map(pen) 15.718.019.072 bytes beschikbaar

  • pablo

    hoi thomas,

    -Sluit alle openstaande programma's.

    -Dubbelklik op l2mfix.bat.

    -Klik op “2” om optie 2 te selecteren: Run Fix.

    -Druk op Enter.

    -Druk op een toets om de computer opnieuw te starten wanneer dit gevraagd wordt.

    Na de reboot verschijnen de ikonen op je desktop. Deze zullen weer verdwijnen. (dat is normaal).

    L2mfix gaat je computer scannen

    Wanneer het klaar is wordt er een nieuw kladblokbestand geopend.

    als dat niet automatisch gebeurd open dan de l2m map en dubbelklik second.bat

    kopieer die tekst en plaats die hier, samen met een nieuw HijackThis-logje.

    paul :)

  • thomas

    ik heb het gedaan alleen hij wil niet gaan scannen. bij het opnieuw opstarten voordat hij windows aanmeld geeft hij de fout dat hij het bestand second.bat niet kan vinden:S er staan wel een bestand dat second heet en heb naar dat hij het aangaf second.bat van gemaakt maar dat hielp ook niets. en als ik het bestand gwn aanklik dan begint hij te scannen maar dan loopt hij niet door. is er wat met dat programma of heb ik iets fout gedaan?

    nog bedankt dat je zo helpt pablo.

  • pablo

    hoi thomas,

    zet in configuratiescherm-mapoptie's eerst een vinkje bij “verborgen bestanden en mappen weergeven” en haal het vinkje weg bij “extensie's voor bekende bestandstypen verbergen” en bij “beschermde besturingsbestanden verbergen ( aanbevolen) ”,klik op toepassen en ok

    ga nu naar de L2M map en hernoem second.bat.bat naar second.bat ;)

    dubbelklik nu second.bat en plaats het logje wat gemaakt word ;)

    paul :)