Volledige versie bekijken : Verschillende problemen



LotA
13 January 2008, 18:07
Onlangs is m'n abonnement op Northon verlopen en sindsdien komt er niets dan miserie bij.

-Northon zelf geeft aan dat er een fout is opgetreden en de scanner opnieuw moet installeren.

-Er staan twee pictogrammen van Windows Update en Help & support center die steeds blijven terugkomen na verwijderen.

- De foutmeldingen lopen langs alle kanten binnen:
Important - Potential errors found in the system During a scan of files at the systemstartup, potentional errors in the system registry were found.
p-07-0100 irql: 1fSYSVER 0xff00024 NT_Kernel error 1256
KMODE_EXCEPTION_NOT__HANDLED
Your system could become unstable
A potentional problem has been detected and Windows has been shutdown buggy application to prevent damage to your computer ****WXYZ.SYS - Address F73120AE base at C00000, Datestamp 36b072A3 Kernel debugger using COM2 (Port 0x28f, Baud Rate 192000)Recent ben ik zelfs niet meer ins staat om 'mijn documenten' te open, de zoekfunctie, etc...

Ik denk dat m'n pc redelijk om zeep is...

Hopelijk zijn jullie in staat mij te helpen, ik ga alleszins in het vervolg m'n abonnement op tijd verlengen

Thx a lot, LotA

M'n Hiijack:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:05:43, on 13/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = http://www.kliksafe.nl;http://www;refdag.nl;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F3 - REG:win.ini: load=C:\WINDOWS\system32\pmkjj.exe
O1 - Hosts: 222.111.150.111 gwgt1.joymax.com
O2 - BHO: (no name) - {0156B101-C067-49F2-B1E4-DB963DF75EEB} - C:\WINDOWS\system32\pmkjj.dll
O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: {ae060999-aac1-8f5b-5274-8fa18aef3162} - {2613fea8-1af8-4725-b5f8-1caa999060ea} - C:\WINDOWS\system32\oumyhuik.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\vvoyovaf.dll
O2 - BHO: (no name) - {FD03C949-1F23-41EA-B53A-C31EE0154454} - C:\WINDOWS\system32\cbxywvu.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [772809e2] rundll32.exe "C:\WINDOWS\system32\avycyqem.dll",b
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZK
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NL_BE&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://lauraverbrugghe.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/NL-BE/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9602.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {E055C02E-6258-40FF-80A7-3BDA52FACAD7} - http://activex.matcash.com/speedtest2.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - Winlogon Notify: cbxywvu - cbxywvu.dll (file missing)
O20 - Winlogon Notify: vvoyovaf - C:\WINDOWS\SYSTEM32\vvoyovaf.dll
O20 - Winlogon Notify: winzwr32 - C:\WINDOWS\SYSTEM32\winzwr32.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762# # (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\wdrlrkgn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Wachtwoordvalidatie voor Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 10792 bytes

Rosty
13 January 2008, 20:46
Hoi,

mooie collectie heb je daar!

Download Combofix (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) naar je Bureaublad.
Indien je Combofix al eerder hebt gebruikt, gelieve die versie te verwijderen en Combofix opnieuw te downloaden via bovenstaande link, want Combofix wordt dagelijks geupdate.

OPMERKING: indien je, tijdens of na het downloaden van Combofix of tijdens het gebruik van Combofix een melding krijgt van je Antivirus- of een andere realtime scanner, schakel dan deze scanner uit en download Combofix opnieuw. Sommige scanners zien bepaalde componenten die Combofix gebruikt als verdacht en gaan deze blokkeren of verwijderen!

Dubbelklik op Combofix.exe
Volg de instructies, aanvaard de disclaimer door 1 (continue) te typen, gevolgd door ENTER.
Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.
Wanneer de fix voltooid is en na herstart, zal de log combofix.txt openen.
Plaats deze log in je volgende post samen met een nieuw HijackThis log.

LotA
13 January 2008, 20:52
Hela,

Ik ga combofix zo meteen nog eens laten runnen.
De vorige keer duurde dit zeer lang (+20 min), nu alles voor m'n pc'tje.

Ik heb ook nog een probleem erbij, in m'n documenten heb ik plots 3000 TMP files erbij... ik kan ze niet verwijderen... alle hulp is welkom ;-)

LotA
13 January 2008, 21:11
Btw, je zei in je eerste post dat ik nogal een boeltje staan heb? In welke mate is dit erg :rolleyes:

Zie hier de combo en nieuwe hijack,

Thx voor al die moeite


LOG COMBOFIX

ComboFix 08-01-13.1 - Junior Allewaert 2008-01-13 19:53:36.3 - NTFSx86
Gestart vanuit: C:\Documents and Settings\Junior Allewaert\Bureaublad\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((( Bestanden Gemaakt van 2007-12-13 to 2008-01-13 ))))))))))))))))))))))))))))))
.

2008-01-13 19:20 . 2008-01-13 19:20 <DIR> d-------- C:\VundoFix Backups
2008-01-13 19:18 . 2008-01-13 19:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-13 18:33 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-13 18:00 . 2008-01-13 19:14 <DIR> dr-h----- C:\Documents and Settings\Junior Allewaert\Onlangs geopend
2008-01-13 17:57 . 2008-01-13 17:57 <DIR> d-------- C:\Program Files\Yahoo!
2008-01-13 17:57 . 2008-01-13 17:57 <DIR> d-------- C:\Program Files\CCleaner
2008-01-13 16:42 . 2008-01-13 16:42 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-13 15:03 . 2008-01-13 17:10 <DIR> d-------- C:\Documents and Settings\Junior Allewaert\Application Data\AVG7
2008-01-13 15:00 . 2008-01-13 15:00 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-13 15:00 . 2008-01-13 15:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-13 15:00 . 2008-01-13 16:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-01-13 14:55 . 2008-01-13 16:18 4,338 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-13 14:12 . 2008-01-13 14:12 90,176 --a------ C:\WINDOWS\system32\avycyqem.dll
2008-01-13 14:09 . 2008-01-13 14:09 74,304 --a------ C:\WINDOWS\system32\hothtuhg.exe
2008-01-12 21:57 . 2008-01-12 21:57 90,176 --a------ C:\WINDOWS\system32\corbxgak.dll
2008-01-12 21:54 . 2008-01-12 21:54 79,424 --a------ C:\WINDOWS\system32\yqifsvxr.dll
2008-01-12 21:51 . 2008-01-12 21:51 74,304 --a------ C:\WINDOWS\system32\uvkwmlcd.exe
2008-01-10 17:25 . 2008-01-10 17:25 74,304 --a------ C:\WINDOWS\system32\exhvphsk.exe
2008-01-10 17:22 . 2008-01-10 17:22 79,424 --a------ C:\WINDOWS\system32\vduftrhv.dll
2008-01-10 12:16 . 2008-01-10 12:16 294 ---hs---- C:\WINDOWS\system32\mjuqjpud.ini
2008-01-10 12:13 . 2008-01-10 12:13 79,936 --a------ C:\WINDOWS\system32\roqhevkj.dll
2008-01-10 12:10 . 2008-01-10 12:10 74,304 --a------ C:\WINDOWS\system32\ppyiygyb.exe
2008-01-09 12:16 . 2008-01-09 12:16 90,176 --a------ C:\WINDOWS\system32\kukdakxi.dll
2008-01-09 12:13 . 2008-01-09 12:13 79,936 --a------ C:\WINDOWS\system32\hsofidig.dll
2008-01-09 12:10 . 2008-01-09 12:10 74,304 --a------ C:\WINDOWS\system32\wdrlrkgn.exe
2008-01-08 11:40 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-01-08 11:40 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-01-08 11:40 . 2007-12-20 23:11 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-01-08 11:40 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-01-08 11:40 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-01-08 11:40 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-01-04 17:04 . 2008-01-05 08:45 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
2008-01-04 12:24 . 2006-03-13 15:07 1,766,940 --a------ C:\Program Files\Feeding Frenzy 2.exe
2008-01-04 12:13 . 2008-01-04 12:24 <DIR> d-------- C:\Program Files\GameHouse
2008-01-04 12:13 . 2008-01-04 12:13 <DIR> d-------- C:\Documents and Settings\Junior Allewaert\Application Data\GameHouse
2008-01-04 12:13 . 2008-01-04 12:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-01-04 12:02 . 2008-01-13 16:25 340,992 --a------ C:\WINDOWS\system32\pmkjj.exe
2008-01-04 12:01 . 2008-01-04 12:01 337,408 --a------ C:\WINDOWS\system32\pmkjj.dll
2008-01-04 11:57 . 2008-01-04 11:57 104,448 --a------ C:\WINDOWS\system32\drvlog.dll
2008-01-04 11:57 . 2008-01-04 11:57 36,864 --a------ C:\WINDOWS\system32\ljjjjhi.dll
2008-01-04 11:57 . 2008-01-04 11:57 35,328 --a------ C:\WINDOWS\system32\khffeca.dll
2008-01-04 11:57 . 2008-01-04 11:57 24,576 --a------ C:\WINDOWS\system32\winzwr32.dll
2008-01-04 11:31 . 2004-09-20 16:00 802,816 --a------ C:\WINDOWS\FeedingFrenzy.scr
2008-01-04 10:57 . 2008-01-04 10:57 <DIR> d-------- C:\Program Files\BSHOOTER.com
2008-01-03 15:10 . 2008-01-03 15:10 <DIR> d-------- C:\Documents and Settings\Junior Allewaert\Application Data\Astro Gemini Software
2008-01-02 16:08 . 2008-01-02 16:08 <DIR> d-------- C:\Program Files\The Rise of Atlantis
2008-01-02 16:08 . 2008-01-02 16:08 <DIR> d-------- C:\Program Files\BFG
2007-12-31 13:56 . 2007-12-31 13:56 <DIR> d-------- C:\Program Files\PasswordTools
2007-12-31 13:01 . 2008-01-01 14:53 <DIR> d-------- C:\Program Files\AZPR
2007-12-31 13:01 . 2007-12-31 15:12 1,182 --a------ C:\WINDOWS\AZPR3.INI
2007-12-31 12:50 . 2007-12-31 12:50 <DIR> d-------- C:\TestZip
2007-12-31 12:46 . 2007-12-31 14:48 <DIR> d-------- C:\Program Files\Visual Zip Password Recovery Processor
2007-12-31 12:35 . 2007-12-31 12:35 <DIR> d-------- C:\Program Files\Passware
2007-12-28 20:44 . 2007-12-28 20:54 <DIR> d-------- C:\Program Files\Risk II
2007-12-28 17:47 . 2007-12-28 17:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
2007-12-28 17:27 . 2007-12-28 17:33 <DIR> d-------- C:\Documents and Settings\Junior Allewaert\Application Data\GetRightToGo
2007-12-28 15:05 . 2008-01-04 12:07 <DIR> d-------- C:\Program Files\Zylom Games
2007-12-28 15:05 . 2008-01-04 12:02 <DIR> d-------- C:\Documents and Settings\Junior Allewaert\Application Data\Zylom
2007-12-28 15:05 . 2007-12-28 15:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Zylom
2007-12-28 15:05 . 2007-12-28 15:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TERMINAL Studio
2007-12-27 21:07 . 2008-01-13 12:19 <DIR> d-------- C:\Program Files\Picasa2
2007-12-26 20:41 . 2008-01-13 16:06 <DIR> d-------- C:\Program Files\Cheat Engine
2007-12-26 20:41 . 2006-09-04 19:16 1,970,176 --a------ C:\WINDOWS\system32\d3dx9.dll
2007-12-26 20:41 . 2006-09-04 19:16 679,936 --a------ C:\WINDOWS\system32\D3DX81ab.dll
2007-12-26 10:53 . 2007-12-26 10:53 1,007 --a------ C:\WINDOWS\mozver.dat
2007-12-26 10:08 . 2007-12-26 11:22 <DIR> d-------- C:\Program Files\Active Data Security Solutions
2007-12-26 10:08 . 2004-12-02 15:51 131,072 --a------ C:\WINDOWS\system32\EraserDemo.dll
2007-12-26 09:22 . 2007-12-26 11:59 <DIR> d-------- C:\Program Files\PC Inspector File Recovery
2007-12-26 09:22 . 2002-02-18 18:40 6,200 --a------ C:\WINDOWS\system32\INT13EXT.VXD
2007-12-26 09:10 . 2007-12-08 01:37 311,296 --a------ C:\WINDOWS\system32\Eraser.dll
2007-12-26 09:10 . 2007-12-08 01:41 86,016 --a------ C:\WINDOWS\system32\Erasext.dll
2007-12-22 11:33 . 2007-12-26 11:33 <DIR> d-------- C:\Program Files\Backup meshes obl
2007-12-22 11:32 . 2007-12-26 11:33 <DIR> d-------- C:\Program Files\Back-up obl textures characters
2007-12-22 10:52 . 2007-12-26 11:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Absolutist

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-01-13 18:40 --------- d-----w C:\Program Files\MSN Messenger
2008-01-13 16:11 --------- d-----w C:\Program Files\Norton AntiVirus
2008-01-13 16:11 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-13 10:35 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\uTorrent
2008-01-12 20:47 --------- d-----w C:\Program Files\Combined Community Codec Pack
2007-12-27 20:07 --------- d-----w C:\Program Files\Google
2007-12-26 18:51 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-26 18:51 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-26 18:51 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-26 18:51 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-26 18:51 --------- d-----w C:\Program Files\Symantec
2007-12-26 18:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-26 11:25 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Applicati on Data\Symantec
2007-12-26 11:03 --------- d-----w C:\Program Files\WinHTTrack
2007-12-26 11:03 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-26 11:03 --------- d-----w C:\Program Files\Windows Live Safety Center
2007-12-26 11:03 --------- d-----w C:\Program Files\Webteh
2007-12-26 11:03 --------- d-----w C:\Program Files\uTorrent
2007-12-26 11:03 --------- d-----w C:\Program Files\TPB Reader
2007-12-26 11:03 --------- d-----w C:\Program Files\Synaptics
2007-12-26 11:02 --------- d-----w C:\Program Files\Sony Corporation
2007-12-26 11:01 --------- d-----w C:\Program Files\Sony
2007-12-26 10:59 --------- d-----w C:\Program Files\Sonic
2007-12-26 10:59 --------- d-----w C:\Program Files\ReflexiveArcade
2007-12-26 10:59 --------- d-----w C:\Program Files\QuickTime
2007-12-26 10:59 --------- d-----w C:\Program Files\PIXELA
2007-12-26 10:59 --------- d-----w C:\Program Files\Photo To Sketch
2007-12-26 10:58 --------- d-----w C:\Program Files\NetWaiting
2007-12-26 10:58 --------- d-----w C:\Program Files\MUSICMATCH
2007-12-26 10:58 --------- d-----w C:\Program Files\MSXML 4.0
2007-12-26 10:58 --------- d-----w C:\Program Files\Microsoft.NET
2007-12-26 10:58 --------- d-----w C:\Program Files\Microsoft Works
2007-12-26 10:56 --------- d-----w C:\Program Files\Microsoft Games
2007-12-26 10:55 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-26 10:55 --------- d-----w C:\Program Files\MagicISO
2007-12-26 10:54 --------- d-----w C:\Program Files\Logitech
2007-12-26 10:54 --------- d-----w C:\Program Files\LimeWire
2007-12-26 10:54 --------- d-----w C:\Program Files\Lavasoft
2007-12-26 10:54 --------- d-----w C:\Program Files\JoWooD
2007-12-26 10:53 --------- d-----w C:\Program Files\Java
2007-12-26 10:53 --------- d-----w C:\Program Files\InterActual
2007-12-26 10:53 --------- d-----w C:\Program Files\Intel
2007-12-26 10:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-26 10:52 --------- d-----w C:\Program Files\IGN
2007-12-26 10:52 --------- d-----w C:\Program Files\HPQ
2007-12-26 10:51 --------- d-----w C:\Program Files\Hp
2007-12-26 10:50 --------- d-----w C:\Program Files\Hewlett-Packard
2007-12-26 10:50 --------- d-----w C:\Program Files\GustoSoft
2007-12-26 10:50 --------- d-----w C:\Program Files\FLVPlayer
2007-12-26 10:47 --------- d-----w C:\Program Files\FLStudio4
2007-12-26 10:47 --------- d-----w C:\Program Files\ElcomSoft
2007-12-26 10:47 --------- d-----w C:\Program Files\Easy Computing
2007-12-26 10:46 --------- d-----w C:\Program Files\EA GAMES
2007-12-26 10:46 --------- d-----w C:\Program Files\DivX
2007-12-26 10:46 --------- d-----w C:\Program Files\DAEMON Tools
2007-12-26 10:46 --------- d-----w C:\Program Files\CONEXANT
2007-12-26 10:46 --------- d-----w C:\Program Files\Common Files\TiVo Shared
2007-12-26 10:45 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2007-12-26 10:44 --------- d-----w C:\Program Files\Common Files\Sony Shared
2007-12-26 10:44 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2007-12-26 10:44 --------- d-----w C:\Program Files\Common Files\muvee Technologies
2007-12-26 10:43 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-12-26 10:43 --------- d-----w C:\Program Files\Common Files\Logitech
2007-12-26 10:43 --------- d-----w C:\Program Files\Common Files\LightScribe
2007-12-26 10:43 --------- d-----w C:\Program Files\Common Files\Java
2007-12-26 10:42 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-26 10:42 --------- d-----w C:\Program Files\Common Files\HP
2007-12-26 10:42 --------- d-----w C:\Program Files\Common Files\Everstrike Software
2007-12-26 10:42 --------- d-----w C:\Program Files\Common Files\DirectX
2007-12-26 10:42 --------- d-----w C:\Program Files\Common Files\Crystal Decisions
2007-12-26 10:34 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-26 10:33 --------- d-----w C:\Program Files\Bonjour
2007-12-26 10:33 --------- d-----w C:\Program Files\Bethesda Softworks
2007-12-26 10:16 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\teamspeak2
2007-12-26 10:15 --------- d--h--r C:\Documents and Settings\Junior Allewaert\Application Data\SecuROM
2007-12-26 10:15 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\Sony Corporation
2007-12-26 10:15 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\Sonic
2007-12-26 10:15 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\Serif
2007-12-26 10:13 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\Media Player Classic
2007-12-26 10:12 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\Logitech
2007-12-26 10:12 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\Leadertech
2007-12-26 10:11 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\Lavasoft
2007-12-26 10:11 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\IDS_COMPANY
2007-12-26 10:11 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\HP
2007-12-26 10:11 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\DivX
2007-12-26 10:11 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\CyberLink
2007-12-26 10:11 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\Apple Computer
2007-12-26 10:11 --------- d-----w C:\Documents and Settings\Junior Allewaert\Application Data\AdobeUM
2007-12-26 10:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2007-12-26 10:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Corporation
2007-12-26 10:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
2007-12-26 10:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBSI
2007-12-26 10:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-12-26 10:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-12-26 10:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2007-12-26 10:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-26 10:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2007-12-26 10:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-26 10:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Age of Empires 3
2007-11-30 22:57 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
.

<pre>
----a-w 40,048 2008-01-13 15:25:54 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
----a-w 115,816 2008-01-13 15:25:53 C:\Program Files\Common Files\Symantec Shared\ccApp .exe
----a-w 579,072 2008-01-13 15:25:56 C:\Program Files\Grisoft\AVG7\avgcc .exe
----a-w 49,152 2008-01-13 15:25:48 C:\Program Files\Hp\HP Software Update\HPWuSchd2 .exe
----a-w 102,400 2008-01-13 15:25:35 C:\Program Files\Hp\QuickPlay\QPService .exe
----a-w 40,960 2008-01-13 15:25:50 C:\Program Files\HPQ\Default Settings\cpqset .exe
----a-w 454,656 2008-01-13 15:25:47 C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
----a-w 83,608 2008-01-13 15:25:26 C:\Program Files\Java\jre1.6.0_01\bin\jusched .exe
----a-w 67,128 2008-01-13 15:26:00 C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
----a-w 5,674,352 2008-01-13 15:26:06 C:\Program Files\MSN Messenger\MsnMsgr .Exe
----a-w 81,920 2008-01-13 15:25:27 C:\Program Files\Sony\SonicStage\SsAAD .exe
----a-w 761,948 2008-01-13 15:25:25 C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
----a-w 1,187,840 2008-01-13 15:25:35 C:\WINDOWS\SMINST\RecGuard .exe
----a-w 15,360 2008-01-05 07:45:16 C:\WINDOWS\system32\ctfmon .exe
</pre>


((((((((((((((((((((((((((((( snapshot@2008-01-13_19.01.55.57 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-13 17:33:37 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-13 18:16:22 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-13 17:33:37 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-13 18:16:22 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-13 17:33:37 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-13 18:16:22 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-13 17:33:37 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-13 18:16:22 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-13 17:33:37 7,344,128 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-13 18:16:22 7,344,128 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-13 17:33:37 471,040 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-13 18:16:22 471,040 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2008-01-13 13:07:48 29,926 ----a-r C:\WINDOWS\Installer\{9816B8B8-4B53-4D3D-9235-AD931252001D}\MsblIco.Exe
+ 2008-01-13 18:40:31 29,926 ----a-r C:\WINDOWS\Installer\{9816B8B8-4B53-4D3D-9235-AD931252001D}\MsblIco.Exe
- 2006-07-29 18:32:50 48,936 ----a-w C:\WINDOWS\system32\sirenacm.dll
+ 2007-01-19 11:53:04 51,056 ----a-w C:\WINDOWS\system32\sirenacm.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
.
REGEDIT4
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0156B101-C067-49F2-B1E4-DB963DF75EEB}]
2008-01-04 12:01 337408 --a------ C:\WINDOWS\system32\pmkjj.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2613fea8-1af8-4725-b5f8-1caa999060ea}]
C:\WINDOWS\system32\oumyhuik.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-15 19:26 7561216]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-07 12:38 131072]
"nwiz"="nwiz.exe" [2006-04-15 19:26 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-15 19:26 86016]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-03-10 13:01 28160 C:\WINDOWS\KHALMNPR.Exe]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 12:29 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"772809e2"="C:\WINDOWS\system32\avycyqem.dll" [2008-01-13 14:12 90176]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-13 15:00 219136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxywvu]
cbxywvu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winzwr32]
winzwr32.dll 2008-01-04 11:57 24576 C:\WINDOWS\system32\winzwr32.dll

*Newly Created Service* - USNJSVC
.
Inhoud van de 'Gedeelde Taken' map
"2008-01-04 19:30:55 C:\WINDOWS\Tasks\Norton AntiVirus - Volledige systeemscan - Junior Allewaert.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
.
************************************************** ************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-13 20:01:11
Windows 5.1.2600 Service Pack 2 NTFS

scannen van verborgen processen ...

scannen van verborgen autostart items ...

scannen van verborgen bestanden ...

Scan succesvol afgerond
verborgen bestanden: 0

************************************************** ************************
.
Voltooingstijd: 2008-01-13 20:04:59
ComboFix-quarantined-files.txt 2008-01-13 19:04:55
ComboFix2.txt 2008-01-13 18:02:27
.
2008-01-10 19:28:38 --- E O F ---






NIEUWE HIJACK


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:08:20, on 13/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = http://www.kliksafe.nl;http://www;refdag.nl;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {0156B101-C067-49F2-B1E4-DB963DF75EEB} - C:\WINDOWS\system32\pmkjj.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2613fea8-1af8-4725-b5f8-1caa999060ea} - C:\WINDOWS\system32\oumyhuik.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [772809e2] rundll32.exe "C:\WINDOWS\system32\avycyqem.dll",b
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZK
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NL_BE&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://lauraverbrugghe.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/NL-BE/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9602.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {E055C02E-6258-40FF-80A7-3BDA52FACAD7} - http://activex.matcash.com/speedtest2.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - Winlogon Notify: cbxywvu - cbxywvu.dll (file missing)
O20 - Winlogon Notify: winzwr32 - C:\WINDOWS\SYSTEM32\winzwr32.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762# # (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Wachtwoordvalidatie voor Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 9503 bytes

Rosty
13 January 2008, 21:58
Hoi LotA,
BELANGRIJK[/b]!!
Die eerst volgende voor je de rest van mijn stappen uitvoert:
Om de Recovery Console te starten voer de volgende stappen uit:

1. Doe de Windows 2000/2003/XP CD in de CD-ROM drive.

2. Klik op Start en vervolgens op uitvoeren.

3. In het Openen venster typ:

D:\i386\winnt32.exe /cmdcons

hier geldt dat D de CD-ROM drive is, dus kijk eerst wat hij bij jou is.

4. Er verschijnt een Windows venster waarin de Recovery Console Optie wordt toegelicht.

5. klik op ja om de Recovery Console te installeren.

6. Herstart de PC. Na de deze herstart zal er in het Boot-menu een optie 'Microsoft Windows Recovery Console' te zien.

* Leeg de Cache and Cookies in IE: Sluit Internet Explorer.
Ga naar Configuratiescherm > Internet Opties > tab Algemeen
Klik de Cookies verwijderen knop
Klik op de Bestanden verwijderen knop ernaast
Vink aan: Ook alle off line items verwijderen, klik OK* Leeg de Cache and Cookies in Firefox (In geval Firefox geïnstalleerd is): Ga naar Extra > Opties.
Klik Privacy in het menu.
Klik op de knop Wissen (Geschiedenis, Cookies, Cache).
Klik OK om het venster opnieuw te sluiten. * Leeg andere Temporary files + Prullenbak Ga naar Start > Uitvoeren en typ: cleanmgr en klik ok.
Laat het je systeem scannen op bestanden die moeten verwijderd worden
Zorg er wel voor dat je daar enkel maar 'tijdelijke bestanden', 'tijdelijke internetbestanden'en 'prullenbak'staan aangevinkt.
Klik daarna op OK.
[/list]

Daarna,
Open Kladblok, kopiëer en plak het volgende (vetgedrukte, blauwe tekst) in een leeg venster: [color=blue]

File::
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\system32\avycyqem.dll
C:\WINDOWS\system32\hothtuhg.exe
C:\WINDOWS\system32\corbxgak.dll
C:\WINDOWS\system32\yqifsvxr.dll
C:\WINDOWS\system32\uvkwmlcd.exe
C:\WINDOWS\system32\exhvphsk.exe
C:\WINDOWS\system32\vduftrhv.dll
C:\WINDOWS\system32\mjuqjpud.ini
C:\WINDOWS\system32\roqhevkj.dll
C:\WINDOWS\system32\ppyiygyb.exe
C:\WINDOWS\system32\kukdakxi.dll
C:\WINDOWS\system32\hsofidig.dll
C:\WINDOWS\system32\wdrlrkgn.exe
C:\WINDOWS\system32\pmkjj.exe
C:\WINDOWS\system32\pmkjj.dll
C:\WINDOWS\system32\drvlog.dll
C:\WINDOWS\system32\ljjjjhi.dll
C:\WINDOWS\system32\khffeca.dll
C:\WINDOWS\system32\winzwr32.dll

Folder::
C:\VundoFix Backups

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0156B101-C067-49F2-B1E4-DB963DF75EEB}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2613fea8-1af8-4725-b5f8-1caa999060ea}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"772809e2"="C:\WINDOWS\system32\avycyqem.dll"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxywvu]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winzwr32]

Renv::
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\Program Files\Grisoft\AVG7\avgcc .exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2 .exe
C:\Program Files\Hp\QuickPlay\QPService .exe
C:\Program Files\HPQ\Default Settings\cpqset .exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched .exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
C:\Program Files\MSN Messenger\MsnMsgr .Exe
C:\Program Files\Sony\SonicStage\SsAAD .exe
C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
C:\WINDOWS\SMINST\RecGuard .exe
C:\WINDOWS\system32\ctfmon .exe

Sla dit op op je Bureaublad als CFScript .

Sleep CFScript in ComboFix.exe zoals getoond in onderstaand voorbeeld :


http://img.photobucket.com/albums/v666/sUBs/CFScript.gif

Dit zal ComboFix doen herstarten.
Start opnieuw op als daarom gevraagd wordt,
en post de inhoud van de Combofix.txt in je volgende antwoord.