in golven zeer trage laptop

  • maria

    hallo , sinds een week bij golven zeer trage laptop. windows xp.

    eergisteren extra scan , vond 1 trojan en 1 worm en heeft deze alletwee verwijderd. gisteren mbam gedaan , wormenplaag ,225 stuks , heeft deze verwijderd. vandaag gaat alles een stuk beter. nu een hjt logje gemaakt .kan iemand a.u.b. kijken of er nog problemen zijn ? alvast veel dank.Malwarebytes' Anti-Malware 1.46

    www.malwarebytes.org

    Databaseversie: 4052

    Windows 5.1.2600 Service Pack 3

    Internet Explorer 7.0.5730.13

    10-8-2010 21:45:56

    mbam-log-2010-08-10 (21-45-56).txt

    Scantype: Snelle scan

    Objecten gescand: 118766

    Verstreken tijd: 12 minuut/minuten, 31 seconde(n)

    Geheugenprocessen geïnfecteerd: 0

    Geheugenmodulen geïnfecteerd: 0

    Registersleutels geïnfecteerd: 0

    Registerwaarden geïnfecteerd: 0

    Registerdata geïnfecteerd: 0

    Mappen geïnfecteerd: 1

    Bestanden geïnfecteerd: 224

    Geheugenprocessen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen geïnfecteerd:

    C:\Documents and Settings\…….\Application Data\drivers\downld (Worm.Bagle) -> Quarantined and deleted successfully.

    Bestanden geïnfecteerd:

    C:\Documents and Settings\……\Application Data\drivers\downld\242921.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\246296.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\246312.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\255796.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\258046.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\258765.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\291734.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\292718.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\293312.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\308500.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\308906.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\309078.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\384390.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\384671.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\384875.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\110015.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\112343.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\112359.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\145734.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\149921.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\150765.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\185750.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\186921.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\198203.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\198453.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\198500.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\278703.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\278828.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\278890.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\307375.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\308109.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\308156.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\310421.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\311093.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\311109.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\321984.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\323312.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\324078.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\325109.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\330484.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\331078.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\355812.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\356718.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\357265.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\375078.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\375515.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\375546.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\470875.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\471406.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\471703.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\87953.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\94906.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\94921.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\102875.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\103859.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\104562.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\139125.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\139937.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\154125.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\154390.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\154437.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\227953.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\228203.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\228234.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\253703.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\254500.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\254546.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\256718.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\257296.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\257328.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\266968.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\268609.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\269734.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\270843.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\271703.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\272109.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\293281.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\294187.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\294765.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\312140.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\312390.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\312406.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\405375.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\406031.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\406125.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\82015.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\88578.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\88609.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\96921.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\98156.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\98890.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\134781.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\136015.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\147687.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\147937.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\148093.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\226250.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\226562.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\226593.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\293750.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\294921.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\294968.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\297250.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\297968.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\297984.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\327312.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\328937.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\329718.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\330703.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\331656.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\332312.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\354500.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\355250.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\355828.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\372203.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\372359.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\372375.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\458984.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\460437.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\460578.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\80062.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\83078.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\114093.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\115484.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\116953.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\131234.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\132718.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\133765.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\146828.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\147234.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\147296.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\222875.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\223046.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\223062.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\286234.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\287359.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\287406.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\289984.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\291093.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\302750.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\303890.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\304328.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\305296.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\306328.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\307031.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\351656.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\352687.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\353250.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\369078.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\369437.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\369500.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\462203.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\463015.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\463109.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\85187.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\92437.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\92453.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\101312.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\102843.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\104093.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\139640.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\141046.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\155375.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\156093.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\156125.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\229437.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\230140.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\230203.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\261453.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\262625.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\262656.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\265484.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\267187.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\267203.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\278437.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\279734.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\280609.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\281578.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\282703.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\283484.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\306265.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\307921.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\308984.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\325328.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\325515.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\325578.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\414218.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\414859.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\415015.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\88687.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\92062.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\92171.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\99953.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\101015.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\101328.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\194937.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\196109.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\196687.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\207375.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\208078.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\208109.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\287437.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\287578.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\287593.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\320703.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\321500.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\323546.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\324250.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\324312.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\341890.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\345750.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\347218.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\348000.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\349000.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\349984.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\350609.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\370125.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\370937.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\371531.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\387687.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\387859.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\474718.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\475203.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    C:\Documents and Settings\……\Application Data\drivers\downld\475343.exe (Worm.Bagle) -> Quarantined and deleted successfully.

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 20:46:08, on 11-8-2010

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.17055)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Acer\eManager\anbmServ.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Sitecom\Bluetooth Software\bin\btwdins.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Windows Internet Name Service\wins.exe

    C:\WINDOWS\system32\igfxtray.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\acer\epm\epm-dm.exe

    C:\Program Files\Arcade\PCMService.exe

    C:\Program Files\Launch Manager\LaunchAp.exe

    C:\Program Files\Launch Manager\PowerKey.exe

    C:\Program Files\Launch Manager\HotkeyApp.exe

    C:\Program Files\Launch Manager\OSDCtrl.exe

    C:\Program Files\Launch Manager\Wbutton.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Microsoft ActiveSync\wcescomm.exe

    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    C:\Program Files\Sitecom\Bluetooth Software\BTTray.exe

    C:\PROGRA~1\MICROS~4\rapimgr.exe

    C:\Program Files\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe

    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe

    C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN

    C:\Program Files\eMule\emule.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\WINDOWS\system32\msiexec.exe

    C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = “C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe”

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

    O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)

    O4 - HKLM\..\Run: C:\Windows\RUNXMLPL.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: c:\acer\epm\epm-dm.exe

    O4 - HKLM\..\Run: C:\Acer\ePM\ePM.exe boot

    O4 - HKLM\..\Run: “C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE” /Spoil /RemAdvDef /Migration32

    O4 - HKLM\..\Run: C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

    O4 - HKLM\..\Run: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

    O4 - HKLM\..\Run: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

    O4 - HKLM\..\Run: “C:\Program Files\Arcade\PCMService.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\LaunchAp.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\PowerKey.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\HotkeyApp.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\CtrlVol.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\OSDCtrl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\Wbutton.exe”

    O4 - HKLM\..\Run: C:\Program Files\Acer\eRecovery\Monitor.exe

    O4 - HKLM\..\Run: rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

    O4 - HKLM\..\Run: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 “EPSON Stylus DX3800 Series” /O6 “USB001” /M “Stylus DX3800”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: KHALMNPR.EXE

    O4 - HKLM\..\Run: KHALMNPR.EXE

    O4 - HKLM\..\Run: “C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe” /hide /waitservice

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Java\Java Update\jusched.exe”

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - HKCU\..\Run: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 “EPSON Stylus DX3800 Series” /M “Stylus DX3800” /EF “HKCU”

    O4 - HKCU\..\Run: “C:\Program Files\Microsoft ActiveSync\wcescomm.exe”

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - Startup: OpenOffice.org 2.4 .lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    O4 - Global Startup: BTTray.lnk = ?

    O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: MBCameraMonitor.lnk = ?

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O8 - Extra context menu item: Verzenden naar &Bluetooth - C:\Program Files\Sitecom\Bluetooth Software\btsendto_ie_ctx.htm

    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll

    O9 - Extra ‘Tools’ menuitem: Mobiele favorieten maken - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll

    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Bluetooth Software\btsendto_ie.htm

    O9 - Extra ‘Tools’ menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Bluetooth Software\btsendto_ie.htm

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O9 - Extra ‘Tools’ menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://global.acer.com/

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167511626765

    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://real.gamehouse.com/games/luxor/mjolauncher.cab

    O16 - DPF: {91F52A42-C10D-49A7-B941-882C657C604F} (Installation Helper Object) - http://kitcentral.wanadoo.nl/download/install/win32/nl/instwact/instwact.dll

    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab

    O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file:///E:/CDVIEWER/CdViewer.cab

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)

    O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)

    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe

    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Sitecom\Bluetooth Software\bin\btwdins.exe

    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

    O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe

    O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe (file missing)

    O23 - Service: Windows Internet Name Service - Unknown owner - C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Windows Internet Name Service\wins.exe

    End of file - 12001 bytes

  • fazantje

    Hoi Maria,

    Als niemand verder helpt, zal ik morgen ff kijken.

    Moet nu naar bed, morgen vroeg eruit voor werk.

    Groetjes Huib:)

  • Luca

    Wacht even met het uitvoeren van het onderstaande tot het goedgekeurd is door één van de vaste helpers hier. Ik ben geen expert namelijk met dit soort dingen.

    Start Hijackthis nog eens, laat het een scan uitvoeren en vink dan de volgende regels aan:

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

    O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)

    O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)

    O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)

    O23 - Service: Windows Internet Name Service - Unknown owner - C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Windows Internet Name Service\wins.exe

    Sluit dan je browser, klik op ‘fix checked’ om op die manier de items door het programma te laten repareren.

    Verwijder het bestand wins.exe uit de map C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Windows Internet Name Service

    Start het systeem daarna opnieuw op, voer nogmaals een scan uit met Hijackthis en plaats het nieuwe logbestand even hier ter controle.

  • fazantje

    Hoi Maria,

    Ik ben het met Luca eens, wat mij betreft mag je het uitvoeren;)

    Succes,

    Huib:)

  • Argus

    FindyKill (by Chiquitine29)

    Platform: Windows XP en Vista

    Deactiveer je Virusscanner en sluit alle vensters

    Download FindyKill.exe naar je Bureaublad

    Dubbelklik Setup

    Kies in het volgende venster: E (Engels)en Enter

    Kies in het volgende venster Optie 1 (Search) en Enter

    Aan het eind zal een log(rapport) verschijnen wat te vinden is op C:\FindyKill.txt

    Post de inhoud in je volgende antwoord

  • maria

    ik heb de aangegeven dingen in hijackthis verwijderd en opnieuw opgestart. waar vind ik het bestand wins.exe om te verwijderen?

    hier een nieuw log , en moet ik doen wat argus zegt ?

    nogmaals alvast dank.Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 18:35:55, on 12-8-2010

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.17055)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Acer\eManager\anbmServ.exe

    C:\Program Files\Sitecom\Bluetooth Software\bin\btwdins.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\igfxtray.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\acer\epm\epm-dm.exe

    C:\Program Files\Arcade\PCMService.exe

    C:\Program Files\Launch Manager\LaunchAp.exe

    C:\Program Files\Launch Manager\PowerKey.exe

    C:\Program Files\Launch Manager\HotkeyApp.exe

    C:\Program Files\Launch Manager\OSDCtrl.exe

    C:\Program Files\Launch Manager\Wbutton.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE

    C:\Program Files\Microsoft ActiveSync\wcescomm.exe

    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    C:\Program Files\Sitecom\Bluetooth Software\BTTray.exe

    C:\Program Files\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe

    C:\PROGRA~1\MICROS~4\rapimgr.exe

    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe

    C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN

    C:\WINDOWS\system32\msiexec.exe

    C:\Program Files\internet explorer\iexplore.exe

    C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = “C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe”

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

    O4 - HKLM\..\Run: C:\Windows\RUNXMLPL.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: c:\acer\epm\epm-dm.exe

    O4 - HKLM\..\Run: C:\Acer\ePM\ePM.exe boot

    O4 - HKLM\..\Run: “C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE” /Spoil /RemAdvDef /Migration32

    O4 - HKLM\..\Run: C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

    O4 - HKLM\..\Run: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

    O4 - HKLM\..\Run: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

    O4 - HKLM\..\Run: “C:\Program Files\Arcade\PCMService.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\LaunchAp.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\PowerKey.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\HotkeyApp.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\CtrlVol.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\OSDCtrl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\Wbutton.exe”

    O4 - HKLM\..\Run: C:\Program Files\Acer\eRecovery\Monitor.exe

    O4 - HKLM\..\Run: rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

    O4 - HKLM\..\Run: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 “EPSON Stylus DX3800 Series” /O6 “USB001” /M “Stylus DX3800”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: KHALMNPR.EXE

    O4 - HKLM\..\Run: KHALMNPR.EXE

    O4 - HKLM\..\Run: “C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe” /hide /waitservice

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Java\Java Update\jusched.exe”

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - HKCU\..\Run: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 “EPSON Stylus DX3800 Series” /M “Stylus DX3800” /EF “HKCU”

    O4 - HKCU\..\Run: “C:\Program Files\Microsoft ActiveSync\wcescomm.exe”

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - Startup: OpenOffice.org 2.4 .lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    O4 - Global Startup: BTTray.lnk = ?

    O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: MBCameraMonitor.lnk = ?

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O8 - Extra context menu item: Verzenden naar &Bluetooth - C:\Program Files\Sitecom\Bluetooth Software\btsendto_ie_ctx.htm

    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll

    O9 - Extra ‘Tools’ menuitem: Mobiele favorieten maken - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll

    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Bluetooth Software\btsendto_ie.htm

    O9 - Extra ‘Tools’ menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Bluetooth Software\btsendto_ie.htm

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O9 - Extra ‘Tools’ menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://global.acer.com/

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167511626765

    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://real.gamehouse.com/games/luxor/mjolauncher.cab

    O16 - DPF: {91F52A42-C10D-49A7-B941-882C657C604F} (Installation Helper Object) - http://kitcentral.wanadoo.nl/download/install/win32/nl/instwact/instwact.dll

    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab

    O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file:///E:/CDVIEWER/CdViewer.cab

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)

    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe

    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Sitecom\Bluetooth Software\bin\btwdins.exe

    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

    O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe

    O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe (file missing)

    End of file - 11357 bytes

  • maria

    voor dat nog te verwijderen bestand heb ik gekeken bij C en dan windows - toen moest ik een heleboel mappen door om te komen bij windows internet name service.

    is dit de map die bedoeld wordt ?

  • fazantje

    Hoi Maria,

    Alle mappen doorlopen en dan aan het eind zie je de hieronder aangegeven vetgedrukte bestand, en die moet je verwijderen.

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Windows Internet Name Service\wins.exe<——-Dit bestand.

    En ja, het advies van Argus kun je uitvoeren.

    Succes,

    Huib:)

  • maria

    regel verwijderd . herstart , nieuw hijack log en log findykill

    ############################## | FindyKill V5.045 |

    # User : mario croci (Administrators) # ACER-3F7889A49C

    # Update on 23/06/2010 by El Desaparecido

    # Start at: 20:45:16 | 12-8-2010

    # Website : http://pagesperso-orange.fr/NosTools/index.html

    # Contact : FindyKill.Contact@gmail.com

    # Intel(R) Celeron(R) M processor 1.60GHz

    # Microsoft Windows XP Home Edition (5.1.2600 32-bit) # Service Pack 3

    # Internet Explorer 7.0.5730.13

    # Windows Firewall Status : Enabled

    # AV : AVG Anti-Virus 8.0

    # AV : ESET NOD32 Antivirus 3.0 3.0

    # C:\ # Lokale vaste schijf # 26,27 Go (765,3 Mo free) # FAT32

    # D:\ # Lokale vaste schijf # 26,66 Go (3,58 Go free) # FAT32

    # E:\ # Cd-rom-schijf

    ################## | Infected File |

    C:\Documents and Settings\mario croci\Application Data\drivers

    ################## | Registry |

    “KEY540534”

    “KEY540534”

    ################## | State |

    # Showing of hidden files : OK

    # Safe boot mode : OK

    # (!) Ndisuio -> Start = 4 ( Good = 3 | Bad = 4 )

    # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )

    # (!) Ip6Fw -> Start = 4 ( Good = 2 | Bad = 4 )

    # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )

    # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )

    # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

    ################## | End of Report # FindyKill V5.045 ! |Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 20:50:20, on 12-8-2010

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.17055)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\Acer\eManager\anbmServ.exe

    C:\Program Files\Sitecom\Bluetooth Software\bin\btwdins.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\igfxtray.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\acer\epm\epm-dm.exe

    C:\Program Files\Arcade\PCMService.exe

    C:\Program Files\Launch Manager\LaunchAp.exe

    C:\Program Files\Launch Manager\PowerKey.exe

    C:\Program Files\Launch Manager\HotkeyApp.exe

    C:\Program Files\Launch Manager\OSDCtrl.exe

    C:\Program Files\Launch Manager\Wbutton.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE

    C:\Program Files\Microsoft ActiveSync\wcescomm.exe

    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    C:\Program Files\Sitecom\Bluetooth Software\BTTray.exe

    C:\Program Files\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe

    C:\PROGRA~1\MICROS~4\rapimgr.exe

    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe

    C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN

    C:\WINDOWS\system32\cmd.exe

    C:\WINDOWS\system32\notepad.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = “C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe”

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

    O4 - HKLM\..\Run: C:\Windows\RUNXMLPL.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: c:\acer\epm\epm-dm.exe

    O4 - HKLM\..\Run: C:\Acer\ePM\ePM.exe boot

    O4 - HKLM\..\Run: “C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE” /Spoil /RemAdvDef /Migration32

    O4 - HKLM\..\Run: C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

    O4 - HKLM\..\Run: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

    O4 - HKLM\..\Run: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

    O4 - HKLM\..\Run: “C:\Program Files\Arcade\PCMService.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\LaunchAp.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\PowerKey.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\HotkeyApp.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\CtrlVol.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\OSDCtrl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Launch Manager\Wbutton.exe”

    O4 - HKLM\..\Run: C:\Program Files\Acer\eRecovery\Monitor.exe

    O4 - HKLM\..\Run: rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

    O4 - HKLM\..\Run: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 “EPSON Stylus DX3800 Series” /O6 “USB001” /M “Stylus DX3800”

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: KHALMNPR.EXE

    O4 - HKLM\..\Run: KHALMNPR.EXE

    O4 - HKLM\..\Run: “C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe” /hide /waitservice

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Java\Java Update\jusched.exe”

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - HKCU\..\Run: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 “EPSON Stylus DX3800 Series” /M “Stylus DX3800” /EF “HKCU”

    O4 - HKCU\..\Run: “C:\Program Files\Microsoft ActiveSync\wcescomm.exe”

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - Startup: OpenOffice.org 2.4 .lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    O4 - Global Startup: BTTray.lnk = ?

    O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: MBCameraMonitor.lnk = ?

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O8 - Extra context menu item: Verzenden naar &Bluetooth - C:\Program Files\Sitecom\Bluetooth Software\btsendto_ie_ctx.htm

    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll

    O9 - Extra ‘Tools’ menuitem: Mobiele favorieten maken - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll

    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Bluetooth Software\btsendto_ie.htm

    O9 - Extra ‘Tools’ menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Bluetooth Software\btsendto_ie.htm

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O9 - Extra ‘Tools’ menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://global.acer.com/

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167511626765

    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://real.gamehouse.com/games/luxor/mjolauncher.cab

    O16 - DPF: {91F52A42-C10D-49A7-B941-882C657C604F} (Installation Helper Object) - http://kitcentral.wanadoo.nl/download/install/win32/nl/instwact/instwact.dll

    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab

    O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file:///E:/CDVIEWER/CdViewer.cab

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)

    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe

    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Sitecom\Bluetooth Software\bin\btwdins.exe

    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

    O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe

    O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe (file missing)

    End of file - 11386 bytes

  • Argus

    Start FindyKill nog een keer en kies:

    Optie 2 (Clean)

    ToolBarSD (by eric_71)

    Platform:Windows XP en Vista

    Download ToolBarSD naar je Bureaublad

    Dubbelklik ToolBarSD.exe

    Geef in E en enter en klik bij de Pop-Up ok

    Geef in 1 enter

    Aan het eind verschijnt een log C:\TB.txt plaats de inhoud ervan in je volgende antwoord

    Note: ToolBarSD wordt door sommige virusscanners als virus gezien,deactiveer daarom je scanner

    Update Malwarebytes Antimalware en doe een volledige scan en plaats het log