logje

  • Bloempie17

    ik had gister een vermoede dat we virussen hadden, en had avast als virusscanner, heb ik avira erop gezet had ie 4 gevonden

    heb ik alle stappen gedaan en hier zijn de logjes

    Malwarebytes' Anti-Malware 1.34

    Database version: 1888

    Windows 5.1.2600 Service Pack 3

    23-3-2009 18:21:05

    mbam-log-2009-03-23 (18-21-05).txt

    Scan type: Quick Scan

    Objects scanned: 118037

    Time elapsed: 29 minute(s), 55 second(s)

    Memory Processes Infected: 0

    Memory Modules Infected: 0

    Registry Keys Infected: 0

    Registry Values Infected: 0

    Registry Data Items Infected: 0

    Folders Infected: 0

    Files Infected: 0

    Memory Processes Infected:

    (No malicious items detected)

    Memory Modules Infected:

    (No malicious items detected)

    Registry Keys Infected:

    (No malicious items detected)

    Registry Values Infected:

    (No malicious items detected)

    Registry Data Items Infected:

    (No malicious items detected)

    Folders Infected:

    (No malicious items detected)

    Files Infected:

    (No malicious items detected)

    —————————————————————

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 19:11:25, on 23-3-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

    C:\Program Files\Palm\Hotsync.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.home.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O3 - Toolbar: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog0.dll (file missing)

    O4 - HKLM\..\Run: C:\WINDOWS\SiSUSBrg.exe

    O4 - HKLM\..\Run: Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe” WINDOWCALL

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Winamp\winampa.exe”

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: C:\Documenten en settings\All Users\Application Data\Jump Poll Poke Mp3\Dent up.exe

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre6\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe”

    O4 - HKUS\S-1-5-19\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Lokale service’)

    O4 - HKUS\S-1-5-20\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Netwerkservice’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\DOCUME~1\maarten\APPLIC~1\OPTION~1\Link About.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1008\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Jonne’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1009\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Elke’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1009\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘Elke’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - S-1-5-21-1343024091-1229272821-1177238915-1004 Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (User ‘maarten’)

    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra ‘Tools’ menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra button: MyCom - {3E085E5E-40AF-4A93-B006-9F20BAE83AA3} - http://www.mycom.nl (file missing) (HKCU)

    O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab

    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.30.136.78/activex/AxisCamControl.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {FACEE739-329B-4C23-9FCC-C85B0270CFDC} (Launcher Control) - http://www.smootsy.com/launcher.cab

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    End of file - 11495 bytes

    ——————————————

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 19:06:52, on 23-3-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\Program Files\Avira\AntiVir Desktop\update.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Palm\Hotsync.exe

    C:\Program Files\Common Files\Teleca Shared\Generic.exe

    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://nl.youtube.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O3 - Toolbar: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog0.dll (file missing)

    O4 - HKLM\..\Run: C:\WINDOWS\SiSUSBrg.exe

    O4 - HKLM\..\Run: Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe” WINDOWCALL

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Winamp\winampa.exe”

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: C:\Documenten en settings\All Users\Application Data\Jump Poll Poke Mp3\Dent up.exe

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre6\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe”

    O4 - HKCU\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client”

    O4 - HKUS\S-1-5-19\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Lokale service’)

    O4 - HKUS\S-1-5-20\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Netwerkservice’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\DOCUME~1\maarten\APPLIC~1\OPTION~1\Link About.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1008\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Jonne’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - S-1-5-21-1343024091-1229272821-1177238915-1004 Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (User ‘maarten’)

    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra ‘Tools’ menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra button: MyCom - {3E085E5E-40AF-4A93-B006-9F20BAE83AA3} - http://www.mycom.nl (file missing) (HKCU)

    O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab

    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.30.136.78/activex/AxisCamControl.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {FACEE739-329B-4C23-9FCC-C85B0270CFDC} (Launcher Control) - http://www.smootsy.com/launcher.cab

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    End of file - 11553 bytes

    —————————————————————-

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 19:01:38, on 23-3-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

    C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Real\RealPlayer\RealPlay.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    C:\Program Files\Windows Media Player\WMPNSCFG.exe

    C:\Program Files\Palm\Hotsync.exe

    C:\Program Files\Common Files\Teleca Shared\Generic.exe

    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

    C:\Program Files\Avira\AntiVir Desktop\update.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.spitsnieuws.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O3 - Toolbar: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog0.dll (file missing)

    O4 - HKLM\..\Run: C:\WINDOWS\SiSUSBrg.exe

    O4 - HKLM\..\Run: Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe” WINDOWCALL

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Winamp\winampa.exe”

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: C:\Documenten en settings\All Users\Application Data\Jump Poll Poke Mp3\Dent up.exe

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre6\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - HKCU\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O4 - HKCU\..\Run: “C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe”

    O4 - HKCU\..\Run: C:\DOCUME~1\Jonne\APPLIC~1\OPTION~1\Link About.exe

    O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKUS\S-1-5-19\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Lokale service’)

    O4 - HKUS\S-1-5-20\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Netwerkservice’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\DOCUME~1\maarten\APPLIC~1\OPTION~1\Link About.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘maarten’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - S-1-5-21-1343024091-1229272821-1177238915-1004 Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (User ‘maarten’)

    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe

    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm

    O8 - Extra context menu item: Add to AMV Convert Tool… - C:\Documenten en settings\Jonne\Menu Start\AMVConverter\grab.html

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Documenten en settings\Jonne\Menu Start\MediaManager\grab.html

    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra ‘Tools’ menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra button: MyCom - {3E085E5E-40AF-4A93-B006-9F20BAE83AA3} - http://www.mycom.nl (file missing) (HKCU)

    O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab

    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.30.136.78/activex/AxisCamControl.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {FACEE739-329B-4C23-9FCC-C85B0270CFDC} (Launcher Control) - http://www.smootsy.com/launcher.cab

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    End of file - 11825 bytes

    —————————————————————————–

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 18:51:55, on 23-3-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\wuauclt.exe

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Windows Media Player\WMPNSCFG.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE

    C:\Program Files\Palm\Hotsync.exe

    C:\Program Files\Hamachi\hamachi.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.spitsnieuws.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://toggleen.ourtoolbar.com/Uninstall?toolbarid=CT2077543&version=4.5.188.7&uid=UN20081216204053609

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O3 - Toolbar: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog0.dll (file missing)

    O4 - HKLM\..\Run: C:\WINDOWS\SiSUSBrg.exe

    O4 - HKLM\..\Run: Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe” WINDOWCALL

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Winamp\winampa.exe”

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: C:\Documenten en settings\All Users\Application Data\Jump Poll Poke Mp3\Dent up.exe

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre6\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe” AcRdB7_0_7 -reboot 1

    O4 - HKCU\..\Run: C:\DOCUME~1\maarten\APPLIC~1\OPTION~1\Link About.exe

    O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKCU\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O4 - HKCU\..\Run: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    O4 - HKCU\..\Run: C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE

    O4 - HKCU\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client”

    O4 - HKUS\S-1-5-19\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Lokale service’)

    O4 - HKUS\S-1-5-20\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Netwerkservice’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe

    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra ‘Tools’ menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab

    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.30.136.78/activex/AxisCamControl.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {FACEE739-329B-4C23-9FCC-C85B0270CFDC} (Launcher Control) - http://www.smootsy.com/launcher.cab

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    End of file - 10735 bytes

  • Teaser

    Zet Teatimer van spybot even uit, omdat deze de fix in de weg kan zitten:

    - Start Spybot

    - Ga naar Mode > selecteer Advanced Mode

    - Ga naar Tools en klik op het Resident-icoon in de lijst

    - Haal het vinkje weg bij Resident TeaTimer en klik OK

    - Herstart de computer

    - Download vervolgens ResetTeaTimer.bat naar je Bureaublad.

    Dubbelklik op ResetTeaTimer.bat om alle entries in TeaTimer te verwijderen.

    Als de computer schoon is, kun je dezelfde stappen weer herhalen om hem weer aan te zetten.

    Download Combofix naar je Bureaublad.

    Indien je Combofix al eerder hebt gebruikt, gelieve die versie te verwijderen en Combofix opnieuw te downloaden via bovenstaande link,

    want Combofix wordt dagelijks geupdate.

    OPMERKING: indien je, tijdens of na het downloaden van Combofix of tijdens het gebruik van Combofix een melding krijgt

    van je Antivirus- of een andere realtime scanner, schakel dan deze scanner uit en download Combofix opnieuw.

    Sommige scanners zien bepaalde componenten die Combofix gebruikt als verdacht en gaan deze blokkeren of verwijderen!

    • Dubbelklik op Combofix.exe

      Volg de instructies, aanvaard de disclaimer.

      Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.

    Wanneer de fix voltooid is en na herstart, zal de log combofix.txt openen.

    Plaats deze log in je volgende post samen met een nieuw HijackThis log.

    Ps het log van antivir waar de gevonden files instaan zou ook wel lekker zijn om even te plaatsen

  • dientje

    http://downloads.subratam.org/ResetTeaTimer.bat

    deze pagina werkt niet

  • Teaser

    verwijder dan even Spybot helemaal.

    lijkt er op dat die site er even uit ligt.

  • dientje

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 11:38:51, on 24-3-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Palm\Hotsync.exe

    C:\Program Files\Common Files\Teleca Shared\Generic.exe

    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://nl.youtube.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O4 - HKLM\..\Run: C:\WINDOWS\SiSUSBrg.exe

    O4 - HKLM\..\Run: Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe” WINDOWCALL

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Winamp\winampa.exe”

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre6\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe”

    O4 - HKCU\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client”

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1007\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Dientje’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1007\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background (User ‘Dientje’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1007\..\Run: “C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe” (User ‘Dientje’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1008\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Jonne’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra button: MyCom - {3E085E5E-40AF-4A93-B006-9F20BAE83AA3} - http://www.mycom.nl (file missing) (HKCU)

    O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab

    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.30.136.78/activex/AxisCamControl.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {FACEE739-329B-4C23-9FCC-C85B0270CFDC} (Launcher Control) - http://www.smootsy.com/launcher.cab

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    End of file - 9599 bytes

    —————————-

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 11:30:53, on 24-3-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Palm\Hotsync.exe

    C:\Program Files\Common Files\Teleca Shared\Generic.exe

    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    End of file - 2310 bytes

    ————————–

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 11:43:16, on 24-3-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Windows Media Player\WMPNSCFG.exe

    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE

    C:\Program Files\Palm\Hotsync.exe

    C:\Program Files\Hamachi\hamachi.exe

    C:\Program Files\Common Files\Teleca Shared\Generic.exe

    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.spitsnieuws.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://toggleen.ourtoolbar.com/Uninstall?toolbarid=CT2077543&version=4.5.188.7&uid=UN20081216204053609

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O4 - HKLM\..\Run: C:\WINDOWS\SiSUSBrg.exe

    O4 - HKLM\..\Run: Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe” WINDOWCALL

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Winamp\winampa.exe”

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre6\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe” AcRdB7_0_7 -reboot 1

    O4 - HKCU\..\Run: C:\DOCUME~1\maarten\APPLIC~1\OPTION~1\Link About.exe

    O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKCU\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O4 - HKCU\..\Run: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    O4 - HKCU\..\Run: C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE

    O4 - HKCU\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client”

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1007\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Dientje’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1007\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background (User ‘Dientje’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1007\..\Run: “C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe” (User ‘Dientje’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1008\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Jonne’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1009\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Elke’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1009\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘Elke’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe

    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab

    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.30.136.78/activex/AxisCamControl.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {FACEE739-329B-4C23-9FCC-C85B0270CFDC} (Launcher Control) - http://www.smootsy.com/launcher.cab

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    End of file - 11044 bytes

    —————————–

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 11:46:35, on 24-3-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Media Player\WMPNSCFG.exe

    C:\Program Files\Palm\Hotsync.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Program Files\Common Files\Teleca Shared\Generic.exe

    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

    C:\WINDOWS\system32\notepad.exe

    C:\WINDOWS\explorer.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.spitsnieuws.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O4 - HKLM\..\Run: C:\WINDOWS\SiSUSBrg.exe

    O4 - HKLM\..\Run: Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe” WINDOWCALL

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Winamp\winampa.exe”

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre6\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: “C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe” AcRdB7_0_7 -reboot 1 (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\DOCUME~1\maarten\APPLIC~1\OPTION~1\Link About.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1007\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Dientje’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1009\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Elke’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1009\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘Elke’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - S-1-5-21-1343024091-1229272821-1177238915-1004 Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (User ‘maarten’)

    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe

    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm

    O8 - Extra context menu item: Add to AMV Convert Tool… - C:\Documenten en settings\Jonne\Menu Start\AMVConverter\grab.html

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Documenten en settings\Jonne\Menu Start\MediaManager\grab.html

    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra button: MyCom - {3E085E5E-40AF-4A93-B006-9F20BAE83AA3} - http://www.mycom.nl (file missing) (HKCU)

    O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab

    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.30.136.78/activex/AxisCamControl.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {FACEE739-329B-4C23-9FCC-C85B0270CFDC} (Launcher Control) - http://www.smootsy.com/launcher.cab

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    End of file - 11314 bytes

    —————————–

    ComboFix 09-03-23.01 - Jonne 2009-03-24 10:39:36.1 - NTFSx86

    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1043.18.479.157

    Gestart vanuit: c:\documenten en settings\Jonne\Bureaublad\ComboFix.exe

    AV: AntiVir Desktop *On-access scanning disabled* (Updated)

    * Nieuw herstelpunt werd aangemaakt

    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    C:\install.exe

    c:\windows\Downloaded Program Files\launcher.ocx

    c:\windows\system32\_000005_.tmp.dll

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2009-02-24 to 2009-03-24 ))))))))))))))))))))))))))))))

    .

    2031-10-02 18:57 . 2031-10-02 18:57 3,120 –a–c— c:\windows\MF_C421.lfa

    2031-10-02 18:57 . 2031-10-02 18:57 3,120 –a–c— c:\windows\MF_C420.lfa

    2009-03-23 18:24 . 2009-03-23 18:24 d——– c:\program files\Trend Micro

    2009-03-23 16:51 . 2009-03-23 16:51 d——– c:\program files\CleanUp!

    2009-03-22 22:25 . 2009-03-23 20:37 dr-h—– c:\documenten en settings\maarten\Onlangs geopend

    2009-03-22 22:24 . 2009-03-09 20:06 15,688 –a—— c:\windows\system32\lsdelete.exe

    2009-03-22 22:17 . 2009-03-22 22:17 d——– c:\documenten en settings\LocalService\Bureaublad

    2009-03-22 21:58 . 2009-03-22 21:58 d–h-c— c:\documenten en settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}

    2009-03-22 21:58 . 2009-03-09 20:06 64,160 –a—— c:\windows\system32\drivers\Lbd.sys

    2009-03-22 10:12 . 2009-03-22 10:12 d——– c:\program files\Avira

    2009-03-22 10:12 . 2009-03-22 10:12 d——– c:\documenten en settings\All Users\Application Data\Avira

    2009-03-22 10:12 . 2009-02-13 11:31 55,640 –a—— c:\windows\system32\drivers\avgntflt.sys

    2009-03-15 12:52 . 2008-11-10 03:39 73,728 –a—— c:\windows\system32\javacpl.cpl

    2009-03-15 09:50 . 2009-03-15 09:56 d——– c:\program files\Hyves Desktop

    2009-03-01 02:23 . 2009-03-01 02:23 3,768 –a—— c:\windows\system32\PerfStringBackup.TMP

    2009-02-28 18:31 . 2009-02-28 18:31 d——– c:\windows\system32\nl

    2009-02-28 18:31 . 2009-02-28 18:31 d——– c:\windows\system32\bits

    2009-02-28 18:31 . 2009-02-28 18:31 d——– c:\windows\l2schemas

    2009-02-28 18:19 . 2009-02-28 18:32 d——– c:\windows\ServicePackFiles

    2009-02-28 13:36 . 2009-02-28 13:36 d——– c:\program files\SUPERAntiSpyware

    2009-02-28 13:36 . 2009-02-28 13:36 d——– c:\documenten en settings\maarten\Application Data\SUPERAntiSpyware.com

    2009-02-28 13:36 . 2009-02-28 13:36 d——– c:\documenten en settings\All Users\Application Data\SUPERAntiSpyware.com

    2009-02-28 13:35 . 2009-02-28 13:35 d——– c:\program files\Common Files\Wise Installation Wizard

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2009-03-24 09:17 ——— d—–w c:\program files\Spybot - Search & Destroy

    2009-03-24 09:16 ——— d—–w c:\documenten en settings\All Users\Application Data\Spybot - Search & Destroy

    2009-03-22 20:57 ——— d—–w c:\program files\Lavasoft

    2009-03-15 11:52 ——— d—–w c:\program files\Java

    2009-03-15 11:48 ——— d—–w c:\program files\Malwarebytes' Anti-Malware

    2009-02-15 10:25 ——— d—–w c:\program files\Alwil Software

    2009-02-11 09:19 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys

    2009-02-11 09:19 15,504 —-a-w c:\windows\system32\drivers\mbam.sys

    2009-02-09 14:08 1,846,912 —-a-w c:\windows\system32\win32k.sys

    2009-01-29 14:40 34 —-a-w c:\documenten en settings\maarten\jagex_runescape_preferences.dat

    2009-01-27 14:46 ——— d—–w c:\program files\TAC

    2009-01-27 14:46 ——— d—–w c:\documenten en settings\maarten\Application Data\TAC

    2006-11-18 22:38 12,965,392 —-a-w c:\documenten en settings\Elke\RealPlayer10-5GOLD.exe

    2006-08-27 00:47 228,875,933 -c–a-w c:\program files\race.wrs

    2006-08-27 00:47 2,658,304 —-a-w c:\program files\acknex.dll

    2006-08-27 00:45 103,748 -c–a-w c:\program files\acknex.wdf

    2006-08-24 18:19 768 -c–a-w c:\program files\PALETTE.RAW

    2006-08-02 05:21 2,774,080 -c–a-w c:\program files\video01.wmv

    2006-07-13 17:13 3,435,213 -c–a-w c:\program files\music03.mp3

    2006-07-13 17:13 2,016,996 -c–a-w c:\program files\music04.mp3

    2006-07-11 01:03 25,214 -c–a-w c:\program files\horse01.ico

    2006-07-01 00:43 36 -c–a-w c:\program files\rect102.dat

    2006-07-01 00:42 38 -c–a-w c:\program files\rect101.dat

    2006-07-01 00:41 15 -c–a-w c:\program files\rect34.dat

    2006-07-01 00:41 15 -c–a-w c:\program files\rect33.dat

    2006-07-01 00:41 15 -c–a-w c:\program files\rect32.dat

    2006-07-01 00:41 15 -c–a-w c:\program files\rect31.dat

    2006-07-01 00:40 15 -c–a-w c:\program files\rect24.dat

    2006-07-01 00:40 15 -c–a-w c:\program files\rect23.dat

    2006-07-01 00:40 15 -c–a-w c:\program files\rect22.dat

    2006-07-01 00:39 15 -c–a-w c:\program files\rect21.dat

    2006-07-01 00:39 15 -c–a-w c:\program files\rect04.dat

    2006-07-01 00:38 15 -c–a-w c:\program files\rect03.dat

    2006-07-01 00:38 15 -c–a-w c:\program files\rect02.dat

    2006-07-01 00:38 15 -c–a-w c:\program files\rect01.dat

    2006-07-01 00:38 15 -c–a-w c:\program files\rech204.dat

    2006-07-01 00:37 15 -c–a-w c:\program files\rech203.dat

    2006-07-01 00:37 15 -c–a-w c:\program files\rech202.dat

    2006-07-01 00:37 14 -c–a-w c:\program files\rech201.dat

    2006-07-01 00:36 15 -c–a-w c:\program files\rech104.dat

    2006-07-01 00:36 15 -c–a-w c:\program files\rech103.dat

    2006-07-01 00:35 15 -c–a-w c:\program files\rech101.dat

    2006-07-01 00:35 13 -c–a-w c:\program files\rech102.dat

    2006-06-30 23:10 130,165 -c–a-w c:\program files\mu-fim.mp3

    2006-06-30 18:39 83,490 -c–a-w c:\program files\mu-dia.mp3

    2006-06-30 18:39 2,865,008 -c–a-w c:\program files\music02.mp3

    2006-06-30 18:35 227,686 -c–a-w c:\program files\mu-perde.mp3

    2006-06-30 18:35 208,878 -c–a-w c:\program files\mu-corre.mp3

    2006-06-30 18:34 3,782,991 -c–a-w c:\program files\music01.mp3

    2006-02-07 22:22 651,040 -c–a-w c:\program files\Incagold.wmv

    2006-02-07 18:20 96,948 -c–a-w c:\program files\incagold.wav

    2005-11-22 23:01 529,920 -c–a-w c:\program files\espa01.mp3

    2005-11-22 05:01 1,989,196 -c–a-w c:\program files\espaco.wmv

    2005-09-18 12:12 25,600 —-a-w c:\program files\race.exe

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    “CTFMON.EXE”=“c:\windows\system32\ctfmon.exe”

    “msnmsgr”=“c:\program files\Windows Live\Messenger\MsnMsgr.Exe”

    “MSMSGS”=“c:\program files\Messenger\msmsgs.exe”

    “WMPNSCFG”=“c:\program files\Windows Media Player\WMPNSCFG.exe”

    “SiSUSBRG”=“c:\windows\SiSUSBrg.exe”

    “SiSRaid”=“c:\program files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe”

    “Ulead AutoDetector v2”=“c:\program files\Common Files\Ulead Systems\AutoDetector\monitor.exe”

    “Ulead Quick-Drop”=“c:\program files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe”

    “USIUDF_Eject_Monitor”=“c:\program files\Common Files\Ulead Systems\DVD\USISrv.exe”

    “NeroFilterCheck”=“c:\windows\system32\NeroCheck.exe”

    “TkBellExe”=“c:\program files\Common Files\Real\Update_OB\realsched.exe”

    “Sony Ericsson PC Suite”=“c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe”

    “Adobe Photo Downloader”=“c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    “Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    “WinampAgent”=“c:\program files\Winamp\winampa.exe”

    “RemoteControl”=“c:\program files\CyberLink\PowerDVD\PDVDServ.exe”

    “iTunesHelper”=“c:\program files\iTunes\iTunesHelper.exe”

    “QuickTime Task”=“c:\program files\QuickTime\qttask.exe”

    “SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe”

    “avgnt”=“c:\program files\Avira\AntiVir Desktop\avgnt.exe”

    “Ad-Watch”=“c:\program files\Lavasoft\Ad-Aware\AAWTray.exe”

    “SiSPower”=“SiSPower.dll”

    “SoundMan”=“SOUNDMAN.EXE”

    “CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE”

    c:\documenten en settings\maarten\Menu Start\Programma's\Opstarten\

    hamachi.lnk - c:\program files\Hamachi\hamachi.exe

    c:\documenten en settings\All Users\Menu Start\Programma's\Opstarten\

    HOTSYNCSHORTCUTNAME.lnk - c:\program files\Palm\Hotsync.exe

    “{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}”= “c:\program files\SUPERAntiSpyware\SASSEH.DLL”

    2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

    “msacm.dvacm”= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm

    “msacm.mpegacm”= mpegacm.acm

    “msacm.ulmp3acm”= ulmp3acm.acm

    @=“Service”

    “%windir%\\system32\\sessmgr.exe”=

    “c:\\Program Files\\LimeWire\\LimeWire.exe”=

    “c:\\StubInstaller.exe”=

    “c:\\BorgIRC 2\\mirc.exe”=

    “c:\\Documenten en settings\\Jonne\\Mijn documenten\\winks\\mcoinstall- www.freewinks.net.exe”=

    “%windir%\\Network Diagnostic\\xpnetdiag.exe”=

    “c:\\Program Files\\Windows Media Player\\wmplayer.exe”=

    “c:\\Program Files\\Bonjour\\mDNSResponder.exe”=

    “c:\\Program Files\\iTunes\\iTunes.exe”=

    “c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe”=

    “c:\\Program Files\\Windows Live\\Messenger\\livecall.exe”=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys

    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys

    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS

    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe

    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe

    S1 mchInjDrv;madCodeHook DLL injection driver;\??\c:\windows\system32\Drivers\mchInjDrv.sys –> c:\windows\system32\Drivers\mchInjDrv.sys

    S3 hitmanpro2;Hitman Pro 2 Driver;c:\program files\Hitman Pro\hitmanpro2.sys

    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS

    .

    Inhoud van de ‘Gedeelde Taken’ map

    2009-03-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job

    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe

    2009-03-23 c:\windows\Tasks\ADCE8F7F9189070B.job

    - c:\docume~1\maarten\applic~1\option~1\love media okay.exe

    2009-02-26 c:\windows\Tasks\AppleSoftwareUpdate.job

    - c:\program files\Apple Software Update\SoftwareUpdate.exe

    .

    - - - - ORPHANS VERWIJDERD - - - -

    Toolbar-{038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\ToggleEN\tbTog0.dll

    HKCU-Run-HyvesKwekker - c:\program files\Hyves Kwekker\HyvesDesktop_2.exe

    HKCU-Run-DeafBalm - c:\docume~1\Jonne\APPLIC~1\OPTION~1\Link About.exe

    HKLM-Run-poke mp3 cdrom meta - c:\documenten en settings\All Users\Application Data\Jump Poll Poke Mp3\Dent up.exe

    .

    ——- Bijkomende Scan ——-

    .

    uStart Page = hxxp://www.spitsnieuws.nl/

    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

    uInternet Connection Wizard,ShellNext = iexplore

    IE: &Add animation to IncrediMail Style Box - c:\program files\IncrediMail\bin\resources\WebMenuImg.htm

    IE: Add to AMV Convert Tool… - c:\documenten en settings\Jonne\Menu Start\AMVConverter\grab.html

    IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    IE: MediaManager tool grab multimedia file - c:\documenten en settings\Jonne\Menu Start\MediaManager\grab.html

    DPF: {426784E5-24B2-4708-820D-117342FAD009} - hxxp://www.hyves.nl/cab/outlookaddressbook.cab

    DPF: {FACEE739-329B-4C23-9FCC-C85B0270CFDC} - hxxp://www.smootsy.com/launcher.cab

    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2009-03-24 10:46:33

    Windows 5.1.2600 Service Pack 3 NTFS

    scannen van verborgen processen …

    scannen van verborgen autostart items …

    scannen van verborgen bestanden …

    Scan succesvol afgerond

    verborgen bestanden: 0

    **************************************************************************

    .

    ——————— VERGRENDELDE REGISTER SLEUTELS ———————

    “3140211900063D11C8EF10054038389C”=“C?\\WINDOWS\\system32\\FM20ENU.DLL”

    .

    ——————— DLLs Geladen Onder Lopende Processen ———————

    - - - - - - - > ‘winlogon.exe’(656)

    c:\program files\SUPERAntiSpyware\SASWINLO.dll

    .

    Voltooingstijd: 2009-03-24 10:50:22

    ComboFix-quarantined-files.txt 2009-03-24 09:50:16

    Pre-Run: 50.202.275.840 bytes beschikbaar

    Post-Run: 52,344,946,688 bytes beschikbaar

    WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe

    timeout=2

    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

    c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons

    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=“Microsoft Windows XP Home Edition” /noexecute=optin /fastdetect

    218 — E O F — 2009-03-14 22:57:01

    —————————-

    Avira AntiVir Personal

    Report file date: zondag 22 maart 2009 10:15

    Scanning for 1310879 virus strains and unwanted programs.

    Licensee : Avira AntiVir Personal - FREE Antivirus

    Serial number : 0000149996-ADJIE-0000001

    Platform : Windows XP

    Windows version : (Service Pack 3)

    Boot mode : Normally booted

    Username : SYSTEM

    Computer name : SP2PC

    Version information:

    BUILD.DAT : 9.0.0.386 17962 Bytes 11-3-2009 15:55:00

    AVSCAN.EXE : 9.0.3.3 464641 Bytes 24-2-2009 11:13:26

    AVSCAN.DLL : 9.0.3.0 40705 Bytes 27-2-2009 09:58:24

    LUKE.DLL : 9.0.3.2 209665 Bytes 20-2-2009 10:35:49

    LUKERES.DLL : 9.0.2.0 12033 Bytes 27-2-2009 09:58:52

    ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27-10-2008 11:30:36

    ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11-2-2009 19:33:26

    ANTIVIR2.VDF : 7.1.2.152 749568 Bytes 11-3-2009 09:14:19

    ANTIVIR3.VDF : 7.1.2.198 271872 Bytes 21-3-2009 09:14:19

    Engineversion : 8.2.0.120

    AEVDF.DLL : 8.1.1.0 106868 Bytes 27-1-2009 16:36:42

    AESCRIPT.DLL : 8.1.1.67 364923 Bytes 22-3-2009 09:14:21

    AESCN.DLL : 8.1.1.8 127346 Bytes 22-3-2009 09:14:20

    AERDL.DLL : 8.1.1.3 438645 Bytes 29-10-2008 17:24:41

    AEPACK.DLL : 8.1.3.10 397686 Bytes 4-3-2009 12:06:10

    AEOFFICE.DLL : 8.1.0.36 196987 Bytes 26-2-2009 19:01:56

    AEHEUR.DLL : 8.1.0.107 1663352 Bytes 22-3-2009 09:14:20

    AEHELP.DLL : 8.1.2.2 119158 Bytes 26-2-2009 19:01:56

    AEGEN.DLL : 8.1.1.30 336245 Bytes 22-3-2009 09:14:19

    AEEMU.DLL : 8.1.0.9 393588 Bytes 9-10-2008 13:32:40

    AECORE.DLL : 8.1.6.6 176501 Bytes 17-2-2009 13:22:44

    AEBB.DLL : 8.1.0.3 53618 Bytes 9-10-2008 13:32:40

    AVWINLL.DLL : 9.0.0.3 18177 Bytes 12-12-2008 07:47:59

    AVPREF.DLL : 9.0.0.1 43777 Bytes 5-12-2008 09:32:15

    AVREP.DLL : 8.0.0.3 155905 Bytes 20-1-2009 13:34:28

    AVREG.DLL : 9.0.0.0 36609 Bytes 5-12-2008 09:32:09

    AVARKT.DLL : 9.0.0.1 292609 Bytes 9-2-2009 06:52:24

    AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30-1-2009 09:37:08

    SQLITE3.DLL : 3.6.1.0 326401 Bytes 28-1-2009 14:03:49

    SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2-2-2009 07:21:33

    NETNT.DLL : 9.0.0.0 11521 Bytes 5-12-2008 09:32:10

    RCIMAGE.DLL : 9.0.0.21 2438401 Bytes 9-2-2009 10:45:45

    RCTEXT.DLL : 9.0.35.0 87297 Bytes 11-3-2009 14:55:12

    Configuration settings for the scan:

    Jobname………………………..: Complete system scan

    Configuration file………………: c:\program files\avira\antivir desktop\sysscan.avp

    Logging………………………..: low

    Primary action………………….: interactive

    Secondary action………………..: ignore

    Scan master boot sector………….: on

    Scan boot sector………………..: on

    Boot sectors……………………: C:,

    Process scan……………………: on

    Scan registry…………………..: on

    Search for rootkits……………..: on

    Integrity checking of system files..: on

    Scan all files………………….: All files

    Scan archives…………………..: on

    Recursion depth…………………: 20

    Smart extensions………………..: on

    Macro heuristic…………………: on

    File heuristic………………….: medium

    Start of the scan: zondag 22 maart 2009 10:15

    Initiating scan of system files:

    Signed -> ‘C:\WINDOWS\system32\svchost.exe’

    Signed -> ‘C:\WINDOWS\system32\winlogon.exe’

    Signed -> ‘C:\WINDOWS\explorer.exe’

    Signed -> ‘C:\WINDOWS\system32\smss.exe’

    Signed -> ‘C:\WINDOWS\system32\wininet.DLL’

    Signed -> ‘C:\WINDOWS\system32\wsock32.DLL’

    Signed -> ‘C:\WINDOWS\system32\ws2_32.DLL’

    Signed -> ‘C:\WINDOWS\system32\services.exe’

    Signed -> ‘C:\WINDOWS\system32\lsass.exe’

    Signed -> ‘C:\WINDOWS\system32\csrss.exe’

    Signed -> ‘C:\WINDOWS\system32\drivers\kbdclass.sys’

    Signed -> ‘C:\WINDOWS\system32\spoolsv.exe’

    Signed -> ‘C:\WINDOWS\system32\alg.exe’

    Signed -> ‘C:\WINDOWS\system32\wuauclt.exe’

    Signed -> ‘C:\WINDOWS\system32\advapi32.DLL’

    Signed -> ‘C:\WINDOWS\system32\user32.DLL’

    Signed -> ‘C:\WINDOWS\system32\gdi32.DLL’

    Signed -> ‘C:\WINDOWS\system32\kernel32.DLL’

    Signed -> ‘C:\WINDOWS\system32\ntdll.DLL’

    Signed -> ‘C:\WINDOWS\system32\ntoskrnl.exe’

    Signed -> ‘C:\WINDOWS\system32\ctfmon.exe’

    The system files were scanned ('21' files)

    Starting search for hidden objects.

    '121175' objects were checked, ‘0’ hidden objects were found.

    The scan of running processes will be started

    Scan process ‘avscan.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘avgnt.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘sched.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘avguard.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘msiexec.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘epmworker.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘Generic.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘alg.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘iPodService.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘wmpnetwk.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘ULCDRSvr.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘svchost.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘MDM.EXE’ - ‘1’ Module(s) have been scanned

    Scan process ‘jqs.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘svchost.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘mDNSResponder.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘AppleMobileDeviceService.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘hamachi.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘Hotsync.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘HYVESD~1.EXE’ - ‘1’ Module(s) have been scanned

    Scan process ‘SUPERAntiSpyware.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘TeaTimer.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘wmpnscfg.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘msnmsgr.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘ctfmon.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘jusched.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘iTunesHelper.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘CapabilityManager.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘PDVDServ.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘winampa.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘apdproxy.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘Application Launcher.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘realsched.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘USISrv.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘Monitor.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘Sraid.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘SOUNDMAN.EXE’ - ‘1’ Module(s) have been scanned

    Scan process ‘explorer.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘spoolsv.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘svchost.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘svchost.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘svchost.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘svchost.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘svchost.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘svchost.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘lsass.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘services.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘winlogon.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘csrss.exe’ - ‘1’ Module(s) have been scanned

    Scan process ‘smss.exe’ - ‘1’ Module(s) have been scanned

    50 processes with 50 modules were scanned

    Starting master boot sector scan:

    Start scanning boot sectors:

    Starting to scan executable files (registry).

    The registry was scanned ( ‘61’ files ).

    Starting the file scan:

    Begin scan in ‘C:\’

    C:\pagefile.sys

    The file could not be opened!

    This file is a Windows system file.

    This file cannot be opened for scanning.

    C:\Uninst.exe

    Contains recognition pattern of the ADSPY/Agent.74098 adware or spyware

    C:\Documenten en settings\Dientje\Mijn documenten\Mijn video's\MSN Messenger Winks\winks\TFR3E3.MCO

    Archive type: CAB (Microsoft)

    –> TFR3E3.cab

    Archive type: CAB (Microsoft)

    –> 3065326f.swf

    No further files can be extracted from this archive. The archive will be closed

    No further files can be extracted from this archive. The archive will be closed

    C:\Documenten en settings\Elke\Local Settings\Temporary Internet Files\Content.IE5\8Y0EEP3F\habboz.htm

    Contains recognition pattern of the HTML/Crypted.Gen HTML script virus

    C:\Documenten en settings\Jonne\Mijn documenten\winks\wink and mood adder(www.freewinks.net.exe

    The file contains an executable program that is disguised by a harmless file extension (HIDDENEXT/Crypted)

    C:\Documenten en settings\maarten\Mijn documenten\Incomplete\T-273818-_uncensored_ tavaris 24.wma

    Is the TR/WMA.Wimad.D.1 Trojan

    Beginning disinfection:

    C:\Uninst.exe

    Contains recognition pattern of the ADSPY/Agent.74098 adware or spyware

    The file was moved to ‘4a2f2159.qua’!

    C:\Documenten en settings\Elke\Local Settings\Temporary Internet Files\Content.IE5\8Y0EEP3F\habboz.htm

    Contains recognition pattern of the HTML/Crypted.Gen HTML script virus

    The file was moved to ‘4a28214c.qua’!

    C:\Documenten en settings\Jonne\Mijn documenten\winks\wink and mood adder(www.freewinks.net.exe

    The file contains an executable program that is disguised by a harmless file extension (HIDDENEXT/Crypted)

    The file was moved to ‘4a342154.qua’!

    C:\Documenten en settings\maarten\Mijn documenten\Incomplete\T-273818-_uncensored_ tavaris 24.wma

    Is the TR/WMA.Wimad.D.1 Trojan

    The file was moved to ‘49f82118.qua’!

    End of the scan: zondag 22 maart 2009 12:28

    Used time: 2:00:02 Hour(s)

    The scan has been done completely.

    11574 Scanned directories

    429872 Files were scanned

    4 Viruses and/or unwanted programs were found

    0 Files were classified as suspicious

    0 files were deleted

    0 Viruses and unwanted programs were repaired

    4 Files were moved to quarantine

    0 Files were renamed

    1 Files cannot be scanned

    429867 Files not concerned

    8200 Archives were scanned

    3 Warnings

    5 Notes

    121175 Objects were scanned with rootkit scan

    0 Hidden objects were found

  • Teaser

    teatimer staat nog steeds in je logjes

  • dientje

    ik heb spybot echt verwijderd

    we hebben 4 accounts en op 1 de spybot verwijderd

  • dientje

    ik had alleen vergeten de map weg te gooien

    moet combo fix ook over doen

  • Teaser

    Nee even nieuwe logjes plaatsen dan

  • dientje

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 12:34:36, on 24-3-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Palm\Hotsync.exe

    C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    C:\Program Files\Common Files\Teleca Shared\Generic.exe

    C:\Program Files\Sony Ericsson\Mobile2\Connection Wizard\ConnectionWizard.exe

    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.home.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O4 - HKLM\..\Run: C:\WINDOWS\SiSUSBrg.exe

    O4 - HKLM\..\Run: Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe” WINDOWCALL

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Winamp\winampa.exe”

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre6\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe”

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: “C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe” AcRdB7_0_7 -reboot 1 (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\DOCUME~1\maarten\APPLIC~1\OPTION~1\Link About.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1008\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Jonne’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1009\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Elke’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1009\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘Elke’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - S-1-5-21-1343024091-1229272821-1177238915-1004 Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (User ‘maarten’)

    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra button: MyCom - {3E085E5E-40AF-4A93-B006-9F20BAE83AA3} - http://www.mycom.nl (file missing) (HKCU)

    O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab

    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.30.136.78/activex/AxisCamControl.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {FACEE739-329B-4C23-9FCC-C85B0270CFDC} (Launcher Control) - http://www.smootsy.com/launcher.cab

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    End of file - 11163 bytes

    —————————————

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 12:28:44, on 24-3-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Palm\Hotsync.exe

    C:\Program Files\Common Files\Teleca Shared\Generic.exe

    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://nl.youtube.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O4 - HKLM\..\Run: C:\WINDOWS\SiSUSBrg.exe

    O4 - HKLM\..\Run: Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe” WINDOWCALL

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Winamp\winampa.exe”

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre6\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe”

    O4 - HKCU\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client”

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: “C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe” AcRdB7_0_7 -reboot 1 (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\DOCUME~1\maarten\APPLIC~1\OPTION~1\Link About.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1007\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Dientje’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1008\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Jonne’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - S-1-5-21-1343024091-1229272821-1177238915-1004 Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (User ‘maarten’)

    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra button: MyCom - {3E085E5E-40AF-4A93-B006-9F20BAE83AA3} - http://www.mycom.nl (file missing) (HKCU)

    O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab

    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.30.136.78/activex/AxisCamControl.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {FACEE739-329B-4C23-9FCC-C85B0270CFDC} (Launcher Control) - http://www.smootsy.com/launcher.cab

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    End of file - 11097 bytes

    ————————–

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 12:25:34, on 24-3-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Windows Media Player\WMPNSCFG.exe

    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE

    C:\Program Files\Palm\Hotsync.exe

    C:\Program Files\Hamachi\hamachi.exe

    C:\Program Files\Common Files\Teleca Shared\Generic.exe

    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.spitsnieuws.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://toggleen.ourtoolbar.com/Uninstall?toolbarid=CT2077543&version=4.5.188.7&uid=UN20081216204053609

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O4 - HKLM\..\Run: C:\WINDOWS\SiSUSBrg.exe

    O4 - HKLM\..\Run: Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe” WINDOWCALL

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Winamp\winampa.exe”

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre6\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe” AcRdB7_0_7 -reboot 1

    O4 - HKCU\..\Run: C:\DOCUME~1\maarten\APPLIC~1\OPTION~1\Link About.exe

    O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKCU\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O4 - HKCU\..\Run: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    O4 - HKCU\..\Run: C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE

    O4 - HKCU\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client”

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1007\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Dientje’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1007\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background (User ‘Dientje’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1007\..\Run: “C:\Program Files\Hyves Kwekker\HyvesDesktop_2.exe” (User ‘Dientje’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1008\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Jonne’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1009\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Elke’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1009\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘Elke’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe

    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab

    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.30.136.78/activex/AxisCamControl.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {FACEE739-329B-4C23-9FCC-C85B0270CFDC} (Launcher Control) - http://www.smootsy.com/launcher.cab

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    End of file - 11021 bytes

    ——————————

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 12:21:50, on 24-3-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Media Player\WMPNSCFG.exe

    C:\Program Files\Palm\Hotsync.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Program Files\Common Files\Teleca Shared\Generic.exe

    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

    C:\WINDOWS\explorer.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.spitsnieuws.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O4 - HKLM\..\Run: C:\WINDOWS\SiSUSBrg.exe

    O4 - HKLM\..\Run: Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe” WINDOWCALL

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Winamp\winampa.exe”

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre6\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: “C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe” AcRdB7_0_7 -reboot 1 (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\DOCUME~1\maarten\APPLIC~1\OPTION~1\Link About.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\Run: C:\PROGRA~1\HYVESD~1\bin\HYVESD~1.EXE (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1004\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘maarten’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1007\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Dientje’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1009\..\Run: C:\WINDOWS\system32\ctfmon.exe (User ‘Elke’)

    O4 - HKUS\S-1-5-21-1343024091-1229272821-1177238915-1009\..\RunOnce: C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1100465 -“Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={5DD2FAC9-751C-4ca3-A589-364E7026811E}; SIMBAR=0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)” -“http://www.habbo.nl/client” (User ‘Elke’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - S-1-5-21-1343024091-1229272821-1177238915-1004 Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (User ‘maarten’)

    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe

    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm

    O8 - Extra context menu item: Add to AMV Convert Tool… - C:\Documenten en settings\Jonne\Menu Start\AMVConverter\grab.html

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Documenten en settings\Jonne\Menu Start\MediaManager\grab.html

    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra button: MyCom - {3E085E5E-40AF-4A93-B006-9F20BAE83AA3} - http://www.mycom.nl (file missing) (HKCU)

    O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab

    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://84.30.136.78/activex/AxisCamControl.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {FACEE739-329B-4C23-9FCC-C85B0270CFDC} (Launcher Control) - http://www.smootsy.com/launcher.cab

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    End of file - 11363 bytes