Hijackthis Logfile

  • ralph

    Dank voor de hulp.

  • Teaser

    Graag gedaan hoor :)-D

  • Hannes

    Ik heb dll fouten…wil iemand my helpen:)

    Ik heb een hijack log file gemaakt.

    ______________________________________________________________________________________________________________________________________

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 17:35:25, on 4/09/2009

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\csrss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\acs.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

    C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe

    C:\WINDOWS\system32\wdfmgr.exe

    C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe

    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    C:\WINDOWS\RTHDCPL.EXE

    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\WINDOWS\AGRSMMSG.exe

    C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe

    C:\Program Files\TOSHIBA\Tvs\TvsTray.exe

    C:\WINDOWS\system32\TPSMain.exe

    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe

    C:\Program Files\TOSHIBA\TOSHIBA-zoomutility\SmoothView.exe

    C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe

    C:\WINDOWS\System32\DLA\DLACTRLW.EXE

    C:\WINDOWS\system32\TPSBattM.exe

    C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe

    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\uTorrent\uTorrent.exe

    C:\WINDOWS\System32\alg.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\WINDOWS\system32\msiexec.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    C:\Documents and Settings\Spelletjes\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Spelletjes\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O4 - HKLM\..\Run: “C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe”

    O4 - HKLM\..\Run: RTHDCPL.EXE

    O4 - HKLM\..\Run: ALCMTR.EXE

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: AGRSMMSG.exe

    O4 - HKLM\..\Run: C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe

    O4 - HKLM\..\Run: C:\Program Files\TOSHIBA\Tvs\TvsTray.exe

    O4 - HKLM\..\Run: TPSMain.exe

    O4 - HKLM\..\Run: NDSTray.exe

    O4 - HKLM\..\Run: C:\Program Files\TOSHIBA\TOSHIBA-zoomutility\SmoothView.exe

    O4 - HKLM\..\Run: C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe

    O4 - HKLM\..\Run: C:\WINDOWS\System32\DLA\DLACTRLW.EXE

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe

    O4 - HKLM\..\Run: “C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe” /Traybar

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe”

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe

    O4 - HKCU\..\Run: “C:\Documents and Settings\Spelletjes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe” /c

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\uTorrent\uTorrent.exe”

    O4 - HKUS\S-1-5-19\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Lokale service’)

    O4 - HKUS\S-1-5-20\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Netwerkservice’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

    O9 - Extra ‘Tools’ menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O20 - AppInit_DLLs: C:\WINDOWS\System32\HdAProp32.dll

    O20 - Winlogon Notify: d0cea103660 - C:\WINDOWS\System32\HdAProp32.dll

    O20 - Winlogon Notify: UpdateNf - updatenf.dll (file missing)

    O23 - Service: Atheros-clienthulpprogramma (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe

    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

    O23 - Service: NanoServiceMain - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe

    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe

    End of file - 7326 bytes

  • Ruudje

    Heb je het stappenplan goed gelezen?

    Waar is dan het tweede logje waar om gevraagd wordt?