Bepaald websites openen niet

  • Sander

    Beste expert,

    Ondanks dat de verbinding helemaal ok is, openen er met regelmaat bepaalde website niet. Van Hotmail en Hyves weet ik het maar er zijn zat andere pagina's die het ook niet doen, ze blijven ontzettend lang laden maar blijven uiteindelijk blank. Het rare is dat als ik het Hotmail-icoontje via Msn.nl gebruik, de website wel opent. In de titelbalk komt overigens wel de naam van de website te staan, dus de verbinding is er duidelijk mee bezig.

    Ik hoop dat iemand, door onderstaande logfiles, mij kan helpen tot een oplossing.

    Met vriendelijke groet,

    Sander

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 16:45:32, on 18-10-2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe

    C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    C:\WINDOWS\system32\nvsvc32.exe

    C:\Program Files\Cyberlink\Shared files\RichVideo.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

    C:\WINDOWS\system32\NOTEPAD.EXE

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vvdevrijbuiters.tk/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Anti-virus\Spybot\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O4 - HKLM\..\Run: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe” /runcleanupscript

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKUS\S-1-5-19\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Lokale service’)

    O4 - HKUS\S-1-5-20\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Netwerkservice’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Anti-virus\Spybot\Spybot - Search & Destroy\SDHelper.dll

    O9 - Extra ‘Tools’ menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Anti-virus\Spybot\Spybot - Search & Destroy\SDHelper.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://www.targa.co.uk

    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159348338640

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe

    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe

    O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe

    O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe

    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe

    End of file - 8182 bytes

    Malwarebytes' Anti-Malware 1.41

    Database versie: 2979

    Windows 5.1.2600 Service Pack 3

    18-10-2009 16:00:28

    mbam-log-2009-10-18 (16-00-28).txt

    Scan type: Snelle Scan

    Objecten gescand: 157579

    Verstreken tijd: 28 minute(s), 2 second(s)

    Geheugenprocessen geïnfecteerd: 0

    Geheugenmodulen geïnfecteerd: 0

    Registersleutels geïnfecteerd: 8

    Registerwaarden geïnfecteerd: 1

    Registerdata bestanden geïnfecteerd: 0

    Mappen geïnfecteerd: 0

    Bestanden geïnfecteerd: 9

    Geheugenprocessen geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Geheugenmodulen geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Registersleutels geïnfecteerd:

    HKEY_CLASSES_ROOT\xml.xml (Worm.Allaple) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\xml.xml.1 (Worm.Allaple) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Typelib\{56acb669-4139-5611-cbba-f5acb0f4db09} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Typelib\{e24211b3-a78a-c6a9-d317-70979ace5058} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Cognac (Rogue.Multiple) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\ColdWare (Malware.Trace) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Monopod (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    Registerwaarden geïnfecteerd:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Delete on reboot.

    Registerdata bestanden geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Mappen geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Bestanden geïnfecteerd:

    C:\RECYCLER\S-1-5-21-4248146393-6527307554-050880164-4233\rundll32.exe (Trojan.Downloader) -> Delete on reboot.

    C:\Documents and Settings\Anouk\Local Settings\Temp\1.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\Documents and Settings\Anouk\Local Settings\Temp\3.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.

    C:\Documents and Settings\Jeroen\Local Settings\Temp\1.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.

    C:\Documents and Settings\Jeroen\Local Settings\Temp\10.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.

    C:\Documents and Settings\Jeroen\Local Settings\Temp\10.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

    C:\Documents and Settings\Jeroen\Local Settings\Temp\3.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.

    C:\WINDOWS\msa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\WINDOWS\msb.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

  • Argus

    ToolBarSD (by eric_71)

    Platform:Windows XP en Vista

    Download ToolBarSD naar je Bureaublad

    Dubbelklik ToolBarSD.exe

    Geef in E en enter en klik bij de Pop-Up ok

    Geef in 1 enter

    Aan het eind verschijnt een log (C:\TB.txt) plaats de inhoud ervan in je volgende antwoord

    Note: ToolBarSD wordt door sommige virusscanners als virus gezien,deactiveer daarom je scanner

    Wat voor een virusscanner gebruik je?

  • Sander

    Nu AVG…

    ———–\\ ToolBar S&D 1.2.9 XP/Vista

    Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3

    X86-based PC ( Multiprocessor Free : AMD Athlon™ 64 X2 Dual Core Processor 4200+ )

    BIOS : Phoenix - AwardBIOS v6.00PG

    USER : Sander ( Administrator )

    BOOT : Normal boot

    C:\ (Local Disk) - NTFS - Total:291 Go (Free:93 Go)

    D:\ (CD or DVD)

    E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)

    F:\ (USB)

    G:\ (USB)

    H:\ (USB)

    I:\ (USB)

    K:\ (USB) - FAT32 - Total:3830 Mo (Free:2 Go)

    “C:\ToolBar SD” ( MAJ : 22-08-2009|18:42 )

    Option : ( ma 19-10-2009|13:12 )

    ———–\\ Searching for Files - Folders …

    C:\Program Files\KaZaA

    C:\Program Files\KaZaA\My Unshared Folder

    C:\Program Files\KaZaA\Topsearch.dll

    ———–\\

    “Start Page”=“http://www.vvdevrijbuiters.tk/”

    “Local Page”=“C:\\WINDOWS\\system32\\blank.htm”

    “Search Page”=“http://www.google.com”

    “Search Bar”=“http://www.google.com/ie”

    “Default_Page_URL”=“http://go.microsoft.com/fwlink/?LinkId=69157”

    “Default_Search_URL”=“http://go.microsoft.com/fwlink/?LinkId=54896”

    “Search Page”=“http://go.microsoft.com/fwlink/?LinkId=54896”

    “Local Page”=“C:\\WINDOWS\\system32\\blank.htm”

    “Start Page”=“http://go.microsoft.com/fwlink/?LinkId=69157”

    ——————–\\ Searching for other infections

    ——————–\\ Cracks & Keygens ..

    C:\DOCUME~1\Sander\Application Data\BitTorrent\Power CD+G burner 1.4.6 + keygen.torrent

    C:\DOCUME~1\Sander\Mijn documenten\Downloads\Power CD+G burner 1.4.6 + keygen

    C:\DOCUME~1\Sander\Mijn documenten\Downloads\Power CD+G burner 1.4.6 + keygen\again.nfo

    C:\DOCUME~1\Sander\Mijn documenten\Downloads\Power CD+G burner 1.4.6 + keygen\cdgburnersetup.exe

    C:\DOCUME~1\Sander\Mijn documenten\Downloads\Power CD+G burner 1.4.6 + keygen\file_id.diz

    C:\DOCUME~1\Sander\Mijn documenten\Downloads\Power CD+G burner 1.4.6 + keygen\Keygen.exe

    1 - “C:\ToolBar SD\TB_1.txt” - ma 19-10-2009|13:14 - Option :

    ———–\\ Scan completed at 13:14:32,00