opstarten in bios steeds

  • Dennis

    Hallo

    mijn pc doet steeds opstarten in bios , na 3 a 4 x een koude start loopt ie door

    ik draai nog op xp, komt een pc met win7 in aantocht (tu)

    wil iemand logjes uitlezen ivm ik de voeding mischien kan uitsluiten

    # AdwCleaner v3.014 - Report created 06/12/2013 at 11:45:14

    # Updated 01/12/2013 by Xplode

    # Operating System : Microsoft Windows XP Service Pack 3 (32 bits)

    # Username : Dennis - DENNIS-B7152B1D

    # Running from : C:\Documents and Settings\Dennis\Bureaublad\adwcleaner.exe

    # Option : Clean

    ***** *****

    ***** *****

    Folder Deleted : C:\Documents and Settings\Dennis\Local Settings\Application Data\eSupport.com

    ***** *****

    ***** *****

    Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho

    Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyFreeCodec

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{9FA57E32-3D16-4FF8-884B-174A5A257F01}

    ***** *****

    -\\ Internet Explorer v8.0.6001.18702

    -\\ Google Chrome v23.0.1271.64

    Deleted : icon_url

    Deleted : search_url

    Deleted : keyword

    *************************

    AdwCleaner.txt - -

    AdwCleaner.txt - -

    ########## EOF - C:\AdwCleaner\AdwCleaner.txt - ##########

    Logfile of random's system information tool 1.09 (written by random/random)

    Run by Dennis at 2013-12-06 11:52:43

    Microsoft Windows XP Professional Service Pack 3

    System drive C: has 29 GB (39%) free of 76 GB

    Total RAM: 2048 MB (76% free)

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 11:52:53, on 6-12-2013

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    c:\Program Files\Microsoft Security Client\MsMpEng.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Java\jre7\bin\jqs.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Microsoft Security Client\msseces.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Documents and Settings\Dennis\Bureaublad\RSIT.exe

    C:\Program Files\trend micro\Dennis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: “C:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Dennis\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} (Bitdefender QuickScan Control) - http://quickscan.bitdefender.com/qsax/qsax.cab

    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab

    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com//activex/ractrl.cab?lmi=1058

    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe

    End of file - 5139 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\Adobe Flash Player Updater.job

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job

    C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

    C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

    C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job

    C:\WINDOWS\tasks\User_Feed_Synchronization-{3EB3E3FD-665D-4BC4-85B4-9AEBE8DCF8B0}.job

    ======Registry dump======

    Java™ Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll

    Windows Live Aanmelden - Help - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll

    Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll

    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    “MSC”=C:\Program Files\Microsoft Security Client\msseces.exe

    “ctfmon.exe”=C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe /Manual

    C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe

    C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe

    C:\Program Files\Epson Software\Event Manager\EEventManager.exe

    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHJE.EXE /FU C:\WINDOWS\TEMP\E_S9E.tmp /EF HKCU

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe

    C:\WINDOWS\system32\dumprep 0 -k

    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

    C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe

    C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe

    C:\Program Files\Driver-Soft\DriverGenius\StarterW3i.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    “NMIndexingService”=3

    “StarWindServiceAE”=2

    “ose”=3

    “odserv”=3

    “MBAMService”=3

    “JavaQuickStarterService”=2

    “Crypkey License”=2

    “Bonjour Service”=3

    “Apple Mobile Device”=3

    “WMDM PMSP Service”=2

    “AdvancedSystemCareService5”=3

    “PLFlash DeviceIoControl Service”=2

    “Nero BackItUp Scheduler 3”=2

    “WMPNetworkSvc”=3

    “gupdatem”=3

    “gupdate”=3

    “Sony SCSI Helper Service”=3

    “ABBYY.Licensing.FineReader.Sprint.9.0”=2

    “gusvc”=3

    C:\WINDOWS\system32\WgaLogon.dll

    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

    “dontdisplaylastusername”=0

    “legalnoticecaption”=

    “legalnoticetext”=

    “shutdownwithoutlogon”=1

    “undockwithoutlogon”=1

    “NoDriveTypeAutoRun”=323

    “”=

    “NoDriveAutoRun”=67108863

    “NoDriveAutoRun”=67108863

    “NoDriveTypeAutoRun”=323

    “%windir%\Network Diagnostic\xpnetdiag.exe”=“%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000”

    “%windir%\system32\sessmgr.exe”=“%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019”

    “C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE”=“C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook”

    “C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE”=“C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote”

    “C:\Program Files\Windows Live\Messenger\wlcsdk.exe”=“C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call”

    “C:\Program Files\Windows Live\Messenger\msnmsgr.exe”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger”

    “C:\WINDOWS\system32\mmc.exe”=“C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console”

    “C:\Program Files\Epson Software\Event Manager\EEventManager.exe”=“C:\Program Files\Epson Software\Event Manager\EEventManager.exe:*:Enabled:EEventManager Application”

    “C:\WINDOWS\system32\muzapp.exe”=“C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player”

    “F:\NewsBin\nbpro.exe”=“F:\NewsBin\nbpro.exe:*:Enabled:NewsBin Pro”

    “C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe”=“C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit”

    “C:\Program Files\Bonjour\mDNSResponder.exe”=“C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour-service”

    “C:\Program Files\Internet Explorer\iexplore.exe”=“C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer”

    “C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe”=“C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software”

    “%windir%\Network Diagnostic\xpnetdiag.exe”=“%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000”

    “%windir%\system32\sessmgr.exe”=“%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019”

    “C:\Program Files\Windows Live\Messenger\wlcsdk.exe”=“C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call”

    “C:\Program Files\Windows Live\Messenger\msnmsgr.exe”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger”

    “midimapper”=midimap.dll

    “msacm.imaadpcm”=imaadp32.acm

    “msacm.msadpcm”=msadp32.acm

    “msacm.msg711”=msg711.acm

    “msacm.msgsm610”=msgsm32.acm

    “msacm.trspch”=tssoft32.acm

    “vidc.cvid”=iccvid.dll

    “vidc.I420”=msh263.drv

    “vidc.iv31”=ir32_32.dll

    “vidc.iv32”=ir32_32.dll

    “vidc.iv41”=ir41_32.ax

    “vidc.iyuv”=iyuv_32.dll

    “vidc.mrle”=msrle32.dll

    “vidc.msvc”=msvidc32.dll

    “vidc.uyvy”=msyuv.dll

    “vidc.yuy2”=msyuv.dll

    “vidc.yvu9”=tsbyuv.dll

    “vidc.yvyu”=msyuv.dll

    “wavemapper”=msacm32.drv

    “msacm.msg723”=msg723.acm

    “vidc.M263”=msh263.drv

    “vidc.M261”=msh261.drv

    “msacm.msaudio1”=msaud32.acm

    “msacm.sl_anet”=sl_anet.acm

    “msacm.iac2”=C:\WINDOWS\system32\iac25_32.ax

    “vidc.iv50”=ir50_32.dll

    “msacm.l3acm”=C:\WINDOWS\system32\l3codeca.acm

    “msacm.siren”=sirenacm.dll

    “wave”=wdmaud.drv

    “midi”=wdmaud.drv

    “mixer”=wdmaud.drv

    “wave1”=wdmaud.drv

    “midi1”=wdmaud.drv

    “mixer1”=wdmaud.drv

    “vidc.ffds”=ff_vfw.dll

    “vidc.xvid”=xvidvfw.dll

    “vidc.lags”=lagarith.dll

    “msacm.ac3filter”=ac3filter.acm

    “msacm.divxa32”=DivXa32.acm

    “msacm.lameacm”=LameACM.acm

    ======List of files/folders created in the last 1 month======

    2013-12-06 11:52:43 —-D—- C:\rsit

    2013-12-06 11:42:58 —-D—- C:\AdwCleaner

    2013-12-02 15:02:01 —-D—- C:\Documents and Settings\All Users\Application Data\BlueStacksSetup

    2013-12-02 15:01:55 —-D—- C:\Documents and Settings\All Users\Application Data\BlueStacks

    2013-11-28 15:56:22 —-D—- C:\Program Files\Nero

    2013-11-28 15:50:26 —-A—- C:\WINDOWS\system32\NEROINSTAEC43759.DB

    2013-11-28 15:49:54 —-A—- C:\WINDOWS\Irremote.ini

    2013-11-26 14:49:15 —-A—- C:\WINDOWS\system32\javaws.exe

    2013-11-26 14:49:06 —-A—- C:\WINDOWS\system32\WindowsAccessBridge.dll

    2013-11-26 14:49:06 —-A—- C:\WINDOWS\system32\javaw.exe

    2013-11-26 14:49:06 —-A—- C:\WINDOWS\system32\java.exe

    2013-11-14 15:36:05 —-HDC—- C:\WINDOWS\$NtUninstallKB2868626$

    2013-11-14 15:35:25 —-HDC—- C:\WINDOWS\$NtUninstallKB2900986$

    2013-11-14 15:35:09 —-HDC—- C:\WINDOWS\$NtUninstallKB2862152$

    2013-11-14 15:35:01 —-HDC—- C:\WINDOWS\$NtUninstallKB2876331$

    ======List of files/folders modified in the last 1 month======

    2013-12-06 11:52:51 —-D—- C:\WINDOWS\Prefetch

    2013-12-06 11:52:48 —-D—- C:\Program Files\trend micro

    2013-12-06 11:52:34 —-D—- C:\WINDOWS\system32\CatRoot2

    2013-12-06 11:47:08 —-D—- C:\WINDOWS\Temp

    2013-12-06 11:45:36 —-A—- C:\WINDOWS\SchedLgU.Txt

    2013-12-06 11:08:27 —-SD—- C:\WINDOWS\Tasks

    2013-12-04 16:53:44 —-RSHDC—- C:\WINDOWS\system32\dllcache

    2013-12-04 12:59:38 —-D—- C:\WINDOWS\system32\config

    2013-12-03 22:54:35 —-D—- C:\WINDOWS\system32

    2013-12-03 20:36:38 —-SHD—- C:\WINDOWS\Installer

    2013-12-03 20:36:05 —-D—- C:\Config.Msi

    2013-12-03 20:35:54 —-D—- C:\Documents and Settings\All Users\Application Data\Microsoft Help

    2013-12-03 12:22:35 —-D—- C:\WINDOWS\system32\drivers

    2013-11-28 16:05:17 —-D—- C:\Documents and Settings\Dennis\Application Data\Vso

    2013-11-28 15:56:37 —-D—- C:\Program Files\Common Files\Nero

    2013-11-28 15:56:22 —-RD—- C:\Program Files

    2013-11-28 15:56:22 —-D—- C:\Documents and Settings\All Users\Application Data\Nero

    2013-11-28 15:50:08 —-A—- C:\WINDOWS\system32\MsiExec.exe.log

    2013-11-26 14:49:06 —-D—- C:\Program Files\Java

    2013-11-26 09:50:42 —-D—- C:\Program Files\Spotnet

    2013-11-22 18:33:30 —-HD—- C:\WINDOWS\inf

    2013-11-20 06:45:52 —-A—- C:\WINDOWS\system32\FlashPlayerApp.exe

    2013-11-19 11:21:30 —-N—- C:\WINDOWS\system32\MpSigStub.exe

    2013-11-19 07:52:06 —-D—- C:\Program Files\Microsoft Security Client

    2013-11-18 20:05:51 —-D—- C:\WINDOWS\Debug

    2013-11-17 19:52:51 —-A—- C:\WINDOWS\NeroDigital.ini

    2013-11-17 17:46:35 —-SD—- C:\WINDOWS\Downloaded Program Files

    2013-11-15 12:05:30 —-D—- C:\Documents and Settings\Dennis\Application Data\QuickScan

    2013-11-14 15:34:51 —-D—- C:\Program Files\Internet Explorer

    2013-11-14 15:33:17 —-D—- C:\WINDOWS\system32\MRT

    2013-11-14 15:30:07 —-A—- C:\WINDOWS\system32\MRT.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys

    R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys

    R0 viaagp1;VIA AGP Filter; C:\WINDOWS\system32\DRIVERS\viaagp1.sys

    R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys

    R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys

    R1 AmdK7;Stuurprogramma voor AMD K7-processor; C:\WINDOWS\system32\DRIVERS\amdk7.sys

    R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys

    R1 kbdhid;Stuurprogramma voor toetsenbord-HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys

    R1 NetworkX;NetworkX; C:\WINDOWS\system32\ckldrv.sys

    R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys

    R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys

    R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\System32\drivers\ctac32k.sys

    R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys

    R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\System32\drivers\ctprxy2k.sys

    R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\drivers\ctsfm2k.sys

    R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\System32\drivers\emupia2k.sys

    R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys

    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys

    R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys

    R3 hidusb;Microsoft HID Class-stuurprogramma; C:\WINDOWS\system32\DRIVERS\hidusb.sys

    R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys

    R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys

    R3 mouhid;Stuurprogramma voor muis-HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys

    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys

    R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys

    R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys

    R3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys

    R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys

    R3 usbccgp;Microsoft generiek hoofd-USB-stuurprogramma; C:\WINDOWS\system32\DRIVERS\usbccgp.sys

    R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys

    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys

    R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys

    R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys

    S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS

    S3 aod44joq;aod44joq; C:\WINDOWS\system32\drivers\aod44joq.sys

    S3 catchme;catchme; C:\WINDOWS\system32\drivers\catchme.sys

    S3 ctljystk;Creative SB Live!-spelpoort; C:\WINDOWS\system32\DRIVERS\ctljystk.sys

    S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys

    S3 dgderdrv;dgderdrv; C:\WINDOWS\System32\drivers\dgderdrv.sys

    S3 DrvAgent32;DrvAgent32; \??\C:\WINDOWS\system32\Drivers\DrvAgent32.sys

    S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet-adapter - NT-stuurprogramma; C:\WINDOWS\system32\DRIVERS\fetnd5.sys

    S3 kxwdmdrv;kX WDM Driver Service; C:\WINDOWS\system32\drivers\kx.sys

    S3 RimUsb;BlackBerry Smartphone; C:\WINDOWS\System32\Drivers\RimUsb.sys

    S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\ssadbus.sys

    S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys

    S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\WINDOWS\system32\DRIVERS\ssadmdm.sys

    S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys

    S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys

    S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys

    S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys

    S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudserd.sys

    S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys

    S3 usbscan;Stuurprogramma voor USB-scanner; C:\WINDOWS\system32\DRIVERS\usbscan.sys

    S3 USBSTOR;Stuurprogramma voor USB-massaopslag; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

    S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys

    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe

    R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe

    R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    S3 aspnet_state;ASP.NET-statusservice; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe

    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

    S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe

    S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe

    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE

    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe

    S4 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

    S4 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe

    S4 Crypkey License;Crypkey License; C:\WINDOWS\system32\crypserv.exe

    S4 gupdate;Google Update-service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe

    S4 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe

    S4 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    S4 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe

    S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe

    S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE

    S4 Sony SCSI Helper Service;Sony SCSI Helper Service; C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe

    S4 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

    S4 WMDM PMSP Service;WMDM PMSP Service; C:\WINDOWS\system32\MsPMSPSv.exe

    S4 WMPNetworkSvc;Windows Media Player Network Sharing-service; C:\Program Files\Windows Media Player\WMPNetwk.exe

    —————–EOF—————–

    Malwarebytes Anti-Malware 1.75.0.1300

    www.malwarebytes.org

    Databaseversie: v2013.12.06.04

    Windows XP Service Pack 3 x86 NTFS

    Internet Explorer 8.0.6001.18702

    Dennis :: DENNIS-B7152B1D

    6-12-2013 13:16:42

    mbam-log-2013-12-06 (13-16-42).txt

    Scan type: Snelle scan

    Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

    Uitgeschakelde scan opties: P2P

    Objecten gescand: 230407

    Verstreken tijd: 8 minuut/minuten, 23 seconde(n)

    Geheugenprocessen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 1

    C:\WINDOWS\Installer\250dad5.msi (PUP.Optional.SmartBar) -> Succesvol in quarantaine geplaatst en verwijderd.

    (einde)

  • Ben

    Hallo,

    Ik denk dat het iets hardware matig is;

    Download

    RogueKiller 32 of 64 bit naar het bureaublad

    RogueKiller 32 bit (x86)

    RogueKiller 64 bit (x64)

    Dubbelklik op RogueKiller.exe om de tool te starten, Windows Vista 7 & 8 gebruikers krijgen een melding van UAC (Gebruikersaccountbeheer) klik hier op Uitvoeren / Run.

    Roguekiller zal nu als eerste een pre-scan uitvoeren, wanneer deze gereed is klikt u op accept om de EULA / Disclaimer te accepteren.

    Zorg ervoor dat de volgende opties in RogueKiller staan aangevinkt.

    MBR Scan

    Check Faked

    Anti-Rootkit

    Klik vervolgens rechts bovenin op de knop "Scan"

    Note!!! Wanneer RogueKiller de ZeroAccess infectie detecteert zal er een melding verschijnen en een website met informatie worden geopend, deze mag u sluiten en hoeft u verder niets mee te doen.

    Wacht vervolgens geduldig tot de scan gereed is, gebruik de computer intussen niet voor andere zaken.

    Wanneer de scan gereed is klikt u op de knop "Report", nu wordt het logbestand geopend deze wordt tevens op het bureaublad opgeslagen als (RKreport_S_05292013_02d1206.txt)

    Voeg dit logbestand vervolgens toe aan je volgende bericht.

    Doe nog niks, je mag daarna het programma sluiten.

  • Dennis

    hoi Ben

    ik heb nix verwijderd

    zie log

    RogueKiller V8.7.11 by Tigzy

    mail : tigzyRKgmailcom

    Feedback : http://www.adlice.com/forum/

    Website : http://www.adlice.com/softwares/roguekiller/

    Blog : http://tigzyrk.blogspot.com/

    besturingssysteem : Windows XP (5.1.2600 Service Pack 3) 32 bits version

    Gestart vanuit : Normale modus

    Gebruiker : Dennis

    Modus : Scan – Datum : 12/06/2013 13:49:34

    | ARK || FAK || MBR |

    ¤¤¤ Kwaadaardige processen : 0 ¤¤¤

    ¤¤¤ Register verwijzingen : 4 ¤¤¤

    HKCU\\Advanced : Start_ShowRecentDocs (0) -> gevonden

    HKCU\\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> gevonden

    HKCU\\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> gevonden

    HKLM\\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> gevonden

    ¤¤¤ geplande taken : 0 ¤¤¤

    ¤¤¤ Startup Entries : 0 ¤¤¤

    ¤¤¤ webbrowsers : 0 ¤¤¤

    ¤¤¤ Speciale Files / Folders: ¤¤¤

    ¤¤¤ Driver : ¤¤¤

    EAT @iexplore.exe (pfnUnmarshallRoutines) : RPCRT4.dll -> HOOKED (Unknown @ 0x799DC2B2)

    ¤¤¤ Externe Hives: ¤¤¤

    ¤¤¤ Infectie : ¤¤¤

    ¤¤¤ HOSTS Bestand: ¤¤¤

    –> %SystemRoot%\System32\drivers\etc\hosts

    127.0.0.1 localhost

    127.0.0.1 serial.alcohol-soft.com

    127.0.0.1 www.alcohol-soft.com

    127.0.0.1 images.alcohol-soft.com

    127.0.0.1 trial.alcohol-soft.com

    127.0.0.1 alcohol-soft.com

    ¤¤¤ MBR Controle: ¤¤¤

    +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD800BB-00CAA1 +++++

    — User —

    d4624c1be1319a72875ed2e057f8d371

    3407261d4f6c09d0cba73d508d4e553c : Windows XP MBR Code

    Partition table:

    0 - NTFS (0x07) Offset (sectors): 63 | Size: 76308 Mo

    User = LL1 … OK!

    User = LL2 … OK!

    +++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) ST380011A +++++

    — User —

    a76e4a359b3b9131716a10b1a979bb35

    a064cf172fbc06385c01bb648ccd7dff : Windows XP MBR Code

    Partition table:

    0 - NTFS (0x07) Offset (sectors): 63 | Size: 76308 Mo

    User = LL1 … OK!

    User = LL2 … OK!

    Gereed : << RKreport_S_12062013_134934.txt >>

  • Ben

    Hallo,

    Hier hoef je niks aan te doen, doe het volgende;

    Ga naar start>uitvoeren en geef daar het volgende commando op sfc /scannow (Let op! de spatie na sfc)

    Waarschijnlijk wordt er gevraagd om de Windows cd of dvd

    Vertel of dit heeft geholpen.

  • Dennis

    Waarschijnlijk wordt er gevraagd om de Windows cd of dvd

    die heb ik dus niet meer helaas

  • Ben

    Hallo,

    Probeer het dan eerst zo.

    Klik daarvoor Computer open en vraag vervolgens de Eigenschappen van –> “C” op.

    Klik nu op de tab Extra

    Klik vervolgens op de knop Nu controleren in het gedeelte waar staat “Hiermee kunt u het station op fouten controleren”.

    In het nieuwe venstertje zorg je ervoor dat beide opties aangevinkt zijn.

    Vervolgens krijg je de melding dat Windows voor die actie moet herstarten.

    Doe dat dan ook.

    Hierdoor wordt de systeemschijf niet alleen op clusterfouten gecontroleerd, maar ook op fouten in het bestandssysteem die dan gerepareerd worden.

    Afhankelijk van de omvanggrootte van Windows en de grootte van de schijven, kan deze scan enige tijd in beslag nemen!

  • Dennis

    klopt die had ik gisteren al laten draaien die vond geen fouten

  • Ben

    Hallo,

    Dan is er hardware matig iets aan de hand, en daar kan ik je niet mee helpen.

  • Dennis

    okee Ben (tu)

    dus geen rotzooi

    aanwezig

    dacht zelf al aan de voeding , maar je wist maar nooit he

    bedankt voor je hulp (tu)

  • Ben

    Hallo,

    De gebruikte programma's mag je weer verwijderen,

    Bedankt en graag gedaan.

Dit topic is gesloten, er kunnen geen reacties meer worden geplaatst.