Partyflock
 
Forumonderwerp · 710662
8115x bekeken

Onderwerp is gesloten!

Dit gebeurt meestal omdat een of meerdere personen het beleid hebben overtreden.
Het kan natuurlijk ook zijn dat er al een actieve discussie over hetzelfde onderwerp was.
Dit soort situaties zijn te voorkomen door op de hoogte te blijven van het beleid.

Waarschuw beheerder
Ik zie weer mensen die last hebben van spyware en denk laat ik maar een groot topic openen dan hoef er niet elke keer weer hetzelfde.. ok:

[SPYWARE: wat is het en wat doet het?]

Spyware zijn kleine programma's (DLLs/executables) die tijdens de installatie van sommige stukken software ongevraagd worden meegeïnstalleerd (ook al staat het meestal wel vermeld in de readme/EULA). Ook kunnen dit soort programma's op je PC komen als je tijdens het surfen op "bepaalde" sites te snel op "OK" klikt, of de beveiligingsinstellingen van Internet Explorer 🇮🇪 te laag hebt staan.

Eenmaal geïnstalleerd verzamelt het programma gegevens (naar welke websites je surft bijvoorbeeld) en zend die via internet naar de softwarefabrikant. Naast de privacyproblemen die je hiermee hebt, gebeurt het vaak dat er om de haverklap reclame in beeld komt, je Internet Explorer vastloopt of erg traag wordt. Ook wil het regelmatig voorkomen dat je een extra "zoekbalk" in beeld krijgt:

[img cacheid=0007335700136d0410e9667f1a00689ff5]http://members.lycos.nl/tinarulez/hpbimg/sp1.gif[/img]

Daarnaast kan het er voor zorgen dat je bij niet gevonden internetpagina's wordt omgeleid naar de webpagina van de spyware makers.

De meeste spyware is te verwijderen met behulp van: Ad-aware en Spybot Search & Destroy. Deze programma's hebben (netzoals een virusscanner) een update-functie om de nieuwste spyware te herkennen, gebruik deze dan ook vóór je op spyware gaat scannen. Als je niet precies weet wat je wel en niet moet doen, kan je dit topic doorlezen of je vragen stellen.

Ook zijn er online scanners, namelijk PestScan en Spywareinfo's online scanner. Beide werken alleen onder Internet Explorer, zie voor meer info:

http://www.pestscan.com/
http://www.spywareinfo.com/xscan.php

Mochten Ad-aware en Spybot S&D het niet weghalen, dan kan je ook nog het programma HijackThis gebruiken. Pas hier wel mee op! HijackThis ziet niet het verschil tussen wat wel en niet op je pc hoort.

Met deze twee programma's kan je kijken wat er allemaal opgestart wordt als je je PC aan zet, en er zo misschien achterkomen wat je PC heeft geïnfecteerd. HijackThis kan ook een log maken, deze zou je eventueel hier kunnen posten of mailen als je er niet uit komt. Als je niet weet wat een bepaald proces doet, kan je de bestandsnaam even inkloppen op Google. Zo kom je er bijvoorbeeld achter dat smss.exe gewoon thuishoort op je PC.

Voorkomen is beter dan genezen natuurlijk!
Druk daarom nooit overal klakkeloos op "Ja" bij dit soort vensters:

[img cacheid=0001477d0002cfcb57491caf1a00689ff5]http://members.lycos.nl/tinarulez/hpbimg/sp2.gif[/img]

Zelfs als je altijd op "nee" drukt, kan het toch voorkomen dat je geinfecteerd word door spyware. Dit komt meestal door lekken in Internet Explorer, update je windows dan ook regelmatig via:

http://windowsupdate.microsoft.com/


[Hoe de programma's werken?]

Ad-aware
Een simpel programma waarmee de niet al te hardnekige spyware mee verwijderd kan worden.

1.) Downloaden

http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022-10319876.html?tag=lst-0-4

2.) Installeren & Lavasoft Ad-aware opstarten

3.) Web-update uitvoeren (zodat hij ook de nieuwste spyware etc kan detecteren)

[img]http://images.sugababes.nl/sonic/spyware/adawarese1.png[/img]

4.) Scannen via de standaardopties

[img cacheid=0007335800136d0a4b0626bb1a00689ff5]http://members.lycos.nl/tinarulez/hpbimg/sp3.png[/img]

5.) Na het scannen op "next" drukken.

[img cacheid=0007335900136d0bf926faab1a00689ff5]http://members.lycos.nl/tinarulez/hpbimg/sp4.png[/img]

6.) Uitvinken wat je wilt bewaren.
Je kunt dubbelklikken op een gevonden item om te kijken wat het inhoud. Als de beschrijving als "troep" eruit ziet (bijv. malware) dan moet je het gewoon aangevinkt laten staan, zodat het bij de volgende stap wordt verwijdert.

Opmerking:
Het kan zijn dat programma's als Kazaa niet meer werken nadat je je pc hebt "schoongemaakt" met ad-aware. Kazaa is namelijk meestal de grootste veroorzaker van spyware. Advies: gebruik daarom K-lite (de variant van Kazaa zonder spyware).

7.) Verwijderen die hap! (met enter of next/doorgaan)

8.) KLAAR!

(evt. je PC opnieuw starten om de wijzigingen in werking te laten treden)


SpyBot Search and Destroy

1.) Downloaden

http://www.download.com/Spybot-Search-Destroy/3000-8022-10289035.html

2.) Open spybot - Sear & Destroy

3.) Kijk eerst of er updates zijn voor dit programma via de knop "zoek naar updates"

[img]http://images.sugababes.nl/sonic/spyware/spy2.png[/img]

4.) Als er updates zijn selecteer dan alle updates en klik op "download updates"

5.) klik op "check for problems".

[img]http://images.sugababes.nl/sonic/spyware/spy3.png[/img]

En klik dan op "controleer alles" en het scannen begint.

[img]http://images.sugababes.nl/sonic/spyware/spy4.png[/img]

6.) Als hij klaar is druk je op "Fix selected problems" en start je PC opnieuw op.

[img]http://images.sugababes.nl/sonic/spyware/spy5.png[/img]

Opmerking:
Het kan ook zijn dat spybot 1 of meerdere problemen niet kon oplossen, doordat de bestanden in gebruik zijn. Dan wordt er gevraagd om opnieuw op te starten.


[OVERIGE TOOLS om spyware mee te verwijderen]

HijackThis

Een simpele, maar destructieve tool.. Met HijackThis kan je zien wat er allemaal automatisch word opgestart als je computer aanzet..

1.) Downloaden

http://computercops.biz/downloads-file-328.html

2.) Open HijackThis en druk op scan. (Ga niet zomaar dingen lopen verwijderen!)

3.) Klik op save log en post je log hier..

LET OP!:
Nooit zelf zomaar dingen aanvinken! HijackThis ziet namelijk NIET wat goed en slecht is! (wat ernstige consequenties kan hebben)


CWShredder

1.) Downloaden

http://computercops.biz/downloads-file-349.html

2.) Sluit alle openstaande Internet Explorer pagina's

3.) Start CWShredder

4.) Druk op fix (Er zal een venster verschijnen, klik daar gewoon op OK)

5.) Het scannen begint, druk op next en vervolgens exit.

[HANDIGE LINKS]

Handleiding - simpel en doeltreffend:
http://users.pandora.be/majoorke/Ad%20aware.htm

Handleiding - meer uitleg: [url]http://www.breekpunt.nl/artikel.asp?Artikel=782&art=Yes[/url]

Meer info over spyware:
http://gathering.tweakers.net/forum/list_messages/843971

dus als je het niet lukt drop het hier dan kijken we er wel naar.. O:)

Nieuw handige tool om spyware te verwijderen.. (mede ook door danie)

Hitman Pro:

Wat is Hitman Pro?

Hitman Pro is de ultieme spyware removal tool. Het is een schil voor een aantal gevestigde spyware en adware schoonmaak- en beschermingsprogramma's. De gebruiker hoeft slechts het bedieningsoppervlak van Hitman Pro te bedienen waarna de externe programma's automatisch door Hitman Pro worden aangestuurd. Hitman Pro bevat ook een aantal eenvoudige passieve beschermingsopties waarmee het lastiger wordt om wederom door spyware besmet te raken.
Hitman Pro is daarom een ideale tool voor iedere computergebruiker.

[img cacheid=00132c4500136d1235f85f081a00689ff5]http://www.hitmanpro.nl/gui.gif[/img]

Download het hier:
http://members.home.nl/mloman/setup.exe

O:)
laatste aanpassing door een beheerder
Waarschuw beheerder
jah leuk maar je weet mico$$$oft.. je moet er dalijk voor betalen.. :[
Waarschuw beheerder
ThaOdie---> Daarom lijkt me het slim als iedereen hem nu alvast download.
Ik heb hem wel gedownload maar nog niet geinstalleert.
ik Wacht even de reacties af. Of het wat is;)
 
Waarschuw beheerder
mensen!
neem lekker een andere browser!
ik zie hier allemaal Internet Explorer screenshots.
Gebruik Mozilla Firefox, werkt als een trein...
Geen gezeik, althans, minstens 80% minder...

www.mozilla.org

later!
 
Waarschuw beheerder
m'n brooertje heeft het voor elkaar gekregen om spyware in firefox te krijgen... dus niet in IE... dus firefox is niet 100% waterdicht... almoet ik toegeven dat ie beter beveiligd is als IE...

trouwens, een paar pagina's terug staat een torrent van Giant Antispyware... waar die van microsoft op gebaseerd is...
 
Waarschuw beheerder
donateur
100% waterdicht is het natuurlijk nooit.
Er is nu natuurlijk veel spyware die gebruik maken van fouten in IE. Nu firefox steeds populairder wordt gaan ze zich ook daar op richten.
Maar tot nu toe niet al teveel rotzooi binnen via firefox :respect:
 
Waarschuw beheerder
Zou iemand mij kunnen helpen met de volgende log???

Logfile of HijackThis v1.99.0
Scan saved at 11:49:47, on 8-1-2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\lass32.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\lssrv.exe
C:\WINDOWS\System32\nesse69.exe
C:\WINDOWS\System32\sepate.exe
C:\WINDOWS\System32\winmedplay.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\sepate.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\DACHRI~1\LOCALS~1\Temp\~e5.0001
C:\WINDOWS\System32\msams.exe
C:\WINDOWS\explorer.exe
C:\Program Files\DeskAd Service\DeskAdServ.exe
C:\Program Files\DeskAd Service\DeskAdKeep.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINDOWS\roxekgpf.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\WINDOWS\System32\sepate.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Temp\salm.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\sepate.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Optimizer\actalert.exe
C:\PROGRA~1\COMMON~1\tsa\tsl.exe
C:\WINDOWS\System32\smsss.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\AUTOEXECC.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Da Chris\Local Settings\Temp\Tijdelijke map 1 voor hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 59.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 59.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Microsoftkeysds] lass32.exe
O4 - HKLM\..\Run: [Windows Compliant] uqcdnk.exe
O4 - HKLM\..\Run: [start extracting] spoolvs.exe
O4 - HKLM\..\Run: [MS Manager32 Startup] manager32.exe
O4 - HKLM\..\Run: [Sygate Personal Firewall] mcafeeupdate.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [start uploading] smsss.exe
O4 - HKLM\..\Run: [Microsoft Services] lssrv.exe
O4 - HKLM\..\Run: [Microsoft is Gay] nesse69.exe
O4 - HKLM\..\Run: [Sepate Security Firewall] sepate.exe
O4 - HKLM\..\Run: [Microsofts MediaScope] winmedplay.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Windows Media Player] msams.exe
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvdfm32.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DeskAd Service] C:\Program Files\DeskAd Service\DeskAdServ.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [WPvAfoB] C:\WINDOWS\roxekgpf.exe
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [ezevgrex] C:\WINDOWS\ezevgrex.exe
O4 - HKLM\..\Run: [Tsl] C:\PROGRA~1\COMMON~1\tsa\tsl.exe
O4 - HKLM\..\RunServices: [Microsoftkeysds] lass32.exe
O4 - HKLM\..\RunServices: [Windows Compliant] uqcdnk.exe
O4 - HKLM\..\RunServices: [start extracting] spoolvs.exe
O4 - HKLM\..\RunServices: [MS Manager32 Startup] manager32.exe
O4 - HKLM\..\RunServices: [Sygate Personal Firewall] mcafeeupdate.exe
O4 - HKLM\..\RunServices: [start uploading] smsss.exe
O4 - HKLM\..\RunServices: [Microsoft Services] lssrv.exe
O4 - HKLM\..\RunServices: [Microsoft is Gay] nesse69.exe
O4 - HKLM\..\RunServices: [Sepate Security Firewall] sepate.exe
O4 - HKLM\..\RunServices: [Microsofts MediaScope] winmedplay.exe
O4 - HKLM\..\RunServices: [Windows Media Player] msams.exe
O4 - HKLM\..\RunOnce: [Microsoftkeysds] lass32.exe
O4 - HKCU\..\Run: [Microsoftkeysds] lass32.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Da Chris\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [start uploading] smsss.exe
O4 - HKCU\..\Run: [Sepate Security Firewall] sepate.exe
O4 - HKCU\..\Run: [Windows Media Player] msams.exe
O4 - HKCU\..\RunServices: [start uploading] smsss.exe
O4 - HKCU\..\RunOnce: [Microsoftkeysds] lass32.exe
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AFEDF1A4-02DF-4937-B2D2-46955ACD2BF8}: NameServer = 62.58.50.5 62.58.50.6
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

alvast bedankt
Waarschuw beheerder
vink dit aan.. ;)

O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 59.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 59.dll
O4 - HKLM\..\Run: [Microsoft is Gay] nesse69.exe
O4 - HKLM\..\Run: [Sepate Security Firewall] sepate.exe
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvdfm32.exe
O4 - HKLM\..\Run: [DeskAd Service] C:\Program Files\DeskAd Service\DeskAdServ.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [WPvAfoB] C:\WINDOWS\roxekgpf.exe
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [ezevgrex] C:\WINDOWS\ezevgrex.exe
O4 - HKLM\..\Run: [Tsl] C:\PROGRA~1\COMMON~1\tsa\tsl.exe
O4 - HKLM\..\RunServices: [Microsoft is Gay] nesse69.exe
O4 - HKLM\..\RunServices: [Sepate Security Firewall] sepate.exe
tyfus wat heb jij veel troep zeg.. meschien handig om hitman pro te scannen daarna Giant Antispyware.. want heb hebt een troep.. post daarna je schone log te hercontrole.. ;)

en meschien handig om Service Pack 2 te installeren..??
"Platform: Windows XP (WinNT 5.01.2600)"
Waarschuw beheerder
donateur
link naar hitman pro doet het niet :(
Waarschuw beheerder
http://www.hitmanpro.nl/
Waarschuw beheerder
donateur
dank u :respect:
Waarschuw beheerder
donateur
Logfile of HijackThis v1.99.0
Scan saved at 10:08:16, on 11-1-05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MESSENGER PLUS! 3\MSGPLUS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\CREATIVE\NEWS\NEWSUPD.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\LOGITECH\ITOUCH\ITOUCH.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
D:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOTDD01.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOHMR08.EXE
C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOEVM08.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOSTS08.EXE
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\WINDOWS\TEMP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R3 - URLSearchHook: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NewsUpd] C:\Program Files\Creative\News\NewsUpd.EXE /q
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [ueyuatoqycr] C:\WINDOWS\SYSTEM\avzqlghy.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] LOGI_MWX.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Spyware Doctor] "D:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - Startup: hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: Messenger Addon - {FB5F1911-F110-11d2-BB9E-00C04F795683} - http://messenger.ipfox.com (file missing)
O9 - Extra 'Tools' menuitem: &Messenger Addon - {FB5F1911-F110-11d2-BB9E-00C04F795683} - http://messenger.ipfox.com (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Search - {00000000-0000-0000-0000-000000000000} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O18 - Filter: text/html - {00000000-0000-0000-0000-000000000000} - (no file)
Waarschuw beheerder
vink dit an:
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://minisearch.startnow.com/
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WINDOWSabout.htm
R3 - URLSearchHook: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)
O4 - HKLM..Run: [ueyuatoqycr] C:WINDOWSSYSTEMavzqlghy.exe
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OBrealsched.exe" -osboot
O9 - Extra button: Search - {00000000-0000-0000-0000-000000000000} - C:WINDOWSSYSTEMSHDOCVW.DLL
O9 - Extra button: Messenger Addon - {FB5F1911-F110-11d2-BB9E-00C04F795683} - http://messenger.ipfox.com (file missing)
O9 - Extra 'Tools' menuitem: &Messenger Addon - {FB5F1911-F110-11d2-BB9E-00C04F795683} - http://messenger.ipfox.com (file missing)
O18 - Filter: text/html - {00000000-0000-0000-0000-000000000000} - (no file)
O:)
Waarschuw beheerder
Wat een enorme logs iedere keer......


Heb nergens last van.... O:)

:P
Artiest Razer
Waarschuw beheerder
ken nooit es kwaad als ik ook es wat post :)

Logfile of HijackThis v1.99.0
Scan saved at 14:18:47, on 11-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ISS\BlackICE\blackd.exe
C:\Program Files\ISS\BlackICE\rapapp.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NetLimiter\NetLimiter.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\System32\rmctrl.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\ISS\BlackICE\blackice.exe
C:\DOCUME~1\Razer\LOCALS~1\Temp\Rar$EX00.656\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BlackICE PC Protection.lnk = C:\Program Files\ISS\BlackICE\blackice.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103664102203
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://webcam5.hrz.tu-darmstadt.de/activex/AMC.cab
O23 - Service: Adobe LM Service - Unknown - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\BlackICE\blackd.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\BlackICE\rapapp.exe
laatste aanpassing
Waarschuw beheerder
welke provider heb je?


Ik zou deze met msconfig uitschakelen die hoefen niet automatisch mee optestarten.

O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
laatste aanpassing
Waarschuw beheerder
planet internet
Waarschuw beheerder
die hebben toch geen datalimiet
Waarschuw beheerder
hebben geen limiet nee, maar deel mijn connectie met mijn ouders
Dus ze moeten ook nog normaal kunnen internetten
Waarschuw beheerder
anders is het zo sneu ;) dan maar netlimiter :D ( ook handig met dc++ ff op 30 zetten :D kun je ook nog normaal internetten :D
Waarschuw beheerder
ik heb dit lijstje

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\nl\msnappau.exe
C:\WINDOWS\System32\mssw32.exe
C:\WINDOWS\System32\wuaruclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Documents and Settings\Eigenaar\Application Data\thre.exe
C:\WINDOWS\System32\t?skmgr.exe
C:\WINDOWS\System32\mssw32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\dbfa8cdf949383a5b6aae114970c30a2\update\update.exe
C:\Documents and Settings\Eigenaar\Local Settings\Temp\Tijdelijke map 1 voor hijackthis[1].zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: (no name) - {40B98214-36AD-1F07-AE0C-6C944F9D88C7} - C:\WINDOWS\System32\zym.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\nl\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\nl\msntb.dll
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\nl\msnappau.exe"
O4 - HKLM\..\Run: [Microsoft Windows W32 Services] mssw32.exe
O4 - HKLM\..\Run: [*windows update] wuaruclt.exe
O4 - HKLM\..\RunServices: [Microsoft Windows W32 Services] mssw32.exe
O4 - HKLM\..\RunServices: [*windows update] wuaruclt.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Adru] C:\Documents and Settings\Eigenaar\Application Data\thre.exe
O4 - HKCU\..\Run: [Wemyvt] C:\WINDOWS\System32\t?skmgr.exe
O4 - HKCU\..\Run: [Microsoft Windows W32 Services] mssw32.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [*windows update] wuaruclt.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
Waarschuw beheerder
Post je volledige log [img cacheid=00070c6b001641ae747fd9dd1a008793fa]http://pinoypride.yehey.com/forums/images/smilies/rolleyes.gif[/img]
Waarschuw beheerder
Logfile of HijackThis v1.99.0
Scan saved at 21:25:07, on 12-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\nl\msnappau.exe
C:\WINDOWS\System32\mssw32.exe
C:\WINDOWS\System32\wuaruclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Documents and Settings\Eigenaar\Application Data\thre.exe
C:\WINDOWS\System32\t?skmgr.exe
C:\WINDOWS\System32\mssw32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\dbfa8cdf949383a5b6aae114970c30a2\update\update.exe
C:\Documents and Settings\Eigenaar\Local Settings\Temp\Tijdelijke map 1 voor hijackthis[1].zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: (no name) - {40B98214-36AD-1F07-AE0C-6C944F9D88C7} - C:\WINDOWS\System32\zym.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\nl\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\nl\msntb.dll
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\nl\msnappau.exe"
O4 - HKLM\..\Run: [Microsoft Windows W32 Services] mssw32.exe
O4 - HKLM\..\Run: [*windows update] wuaruclt.exe
O4 - HKLM\..\RunServices: [Microsoft Windows W32 Services] mssw32.exe
O4 - HKLM\..\RunServices: [*windows update] wuaruclt.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Adru] C:\Documents and Settings\Eigenaar\Application Data\thre.exe
O4 - HKCU\..\Run: [Wemyvt] C:\WINDOWS\System32\t?skmgr.exe
O4 - HKCU\..\Run: [Microsoft Windows W32 Services] mssw32.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [*windows update] wuaruclt.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
Waarschuw beheerder
Je hebt msn 6.2 geinstalleerd met toolbar bewust of onbewust.

Je hebt sp2 nog niet geinstalleerd als je dat ooit nog van plan bent kun je beter een Geslipstreamde cd maken.

Moeilijk http://gathering.tweakers.net/forum/list_messages/948707

Makelijk http://www.neowin.net/forum/index.php?showtopic=223562


Maar het belangrijkste is nog je hebt geen virruscanner geinstalleerd en en firewall.


Dus ik zie nu een virus op je pc staan die kun je wel weghalen maar hij komt net zo hard weer terug.


Dus wat ga je doen En geslipstreamde cd maken en XP sp2 vers installeren

of er een firewall en virruscanner op zetten.
Waarschuw beheerder
weet iemand wat over de Windows AntiSpyware van MS (Beta)?
Waarschuw beheerder
O2 - BHO: (no name) - {40B98214-36AD-1F07-AE0C-6C944F9D88C7} - C:\WINDOWS\System32\zym.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\nl\msntb.dll
3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\nl\msntb.dll
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\nl\msnappau.exe"
O4 - HKLM\..\Run: [*windows update] wuaruclt.exe
O4 - HKLM\..\RunServices: [*windows update] wuaruclt.exe
4 - HKCU\..\Run: [Adru] C:\Documents and Settings\Eigenaar\Application Data\thre.exe
O4 - HKCU\..\Run: [Wemyvt] C:\WINDOWS\System32\t?skmgr.exe
O4 - HKCU\..\Run: [*windows update] wuaruclt.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O:) weg ermee.. :yes:
 
Waarschuw beheerder
donateur
Hier is mijn Hijack This Logfile:
-----------------------------------------------------------

Logfile of HijackThis v1.99.0
Scan saved at 14:55:28, on 14-1-2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Altiris\eXpress\NS Client\AeXNSClient.exe
C:\Program Files\Altiris\eXpress\NS Client\AeXNSClientTransport.exe
C:\WINNT\SYSTEM32\DWRCS.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINNT\System32\NMSSvc.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Altiris\eXpress\NS Client\AeXSWDUsr.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINNT\system32\ICO.EXE
C:\WINNT\system32\RUNDLL32.EXE
C:\WINNT\system32\Pelmiced.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE
C:\Program Files\Microsoft Firewall Client\ISATRAY.EXE
C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\WISPTIS.EXE
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Jasper\LOCALS~1\Temp\Rar$EX00.094\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = HCME_IIS:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.*;127.0.0.1;*.hcme-nl.com;sun-oracle.*;*.hitachi-kenki.co.jp;
R3 - URLSearchHook: (no name) - {CE000994-A58C-4441-8938-744CD72AB27F} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.reg
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Client Access Help Update] "C:\Program Files\IBM\Client Access\cwbinhlp.exe"
O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGIN
O4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"
O4 - HKLM\..\Run: [AeXSWDUsr] "C:\Program Files\Altiris\eXpress\NS Client\AeXSWDUsr.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Client Access PC5250 Sound] "C:\Program Files\IBM\Client Access\Emulator\pcssnd.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKLM\..\RunOnce: [InnoSetupRegFile.0000000001] C:\WINNT\is-QQ04E.exe /REG
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE"
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Firewall Client Connectivity Monitor.LNK = C:\Program Files\Microsoft Firewall Client\ISATRAY.EXE
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O23 - Service: Altiris eXpress NS Client - Altiris - C:\Program Files\Altiris\eXpress\NS Client\AeXNSClient.exe
O23 - Service: Altiris eXpress NS Client Transport - Altiris - C:\Program Files\Altiris\eXpress\NS Client\AeXNSClientTransport.exe
O23 - Service: iSeries Access for Windows Remote Command - IBM Corporation - C:\WINNT\CWBRXD.EXE
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare Mini Remote Control - DameWare Development LLC - C:\WINNT\SYSTEM32\DWRCS.EXE
O23 - Service: McAfee Framework Service - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NMS Service - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: VNC Server - AT&T Research Labs Cambridge - C:\Program Files\ORL\VNC\WinVNC.exe
Waarschuw beheerder
vinkie ditie wegie:

R3 - URLSearchHook: (no name) - {CE000994-A58C-4441-8938-744CD72AB27F} - (no file)
O4 - HKLM\..\Run: [tourpath] regedit /s c:\winnt\tour.reg
O4 - HKLM\..\RunOnce: [InnoSetupRegFile.0000000001] C:\WINNT\is-QQ04E.exe /REG
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
uninstall DAP zit veel :[ spyware in.. en gebruik FlashGet.. ;)
 
Waarschuw beheerder
Logfile of HijackThis v1.99.0
Scan saved at 18:47:53, on 15-1-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Smtray.exe
C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\COMPAQ\CPQINET\CPQInet.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\program files\ncase\msbb.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hotbar\bin\Hbinst.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\eFax Messenger Plus 3.3\J2GDllCmd.exe
C:\Program Files\eFax Messenger Plus 3.3\J2GTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\ntvdm.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Miranda\LOCALS~1\Temp\Tijdelijke map 1 voor hijackthis.zip\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.kjwpxfzbesohbzblnol.com/IZ4visGjtS5tOJsvMhfWou8P2UFEvmr4MFwNFiIQqTfzeWZledt0RA0dKpRm99cr.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pfefcbjgsndhvgjxnndam.com/IZ4visGjtS4eb24yEBEP45UJOFA7UXrLUeFdwF24CT0.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {32D13202-D2EB-1B2A-2D9D-4B08ABE22989} - C:\DOCUME~1\Miranda\APPLIC~1\IDOLBU~1\BinSoftware.exe
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [msbb] c:\program files\ncase\msbb.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [Hotbar] C:\Program Files\Hotbar\bin\Hbinst.exe /Upgrade
O4 - HKLM\..\Run: [2junkforstupid] C:\Documents and Settings\All Users\Application Data\bytebat2junk\ping global.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\6.bin\mwsoemon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [deadante] C:\DOCUME~1\Miranda\APPLIC~1\DRIVEO~1\size start draw.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\6.bin\MWSOEMON.EXE
O4 - Global Startup: eFax Live Menu 3.3.lnk = C:\Program Files\eFax Messenger Plus 3.3\J2GDllCmd.exe
O4 - Global Startup: eFax Tray Menu 3.3.lnk = C:\Program Files\eFax Messenger Plus 3.3\J2GTray.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Agenda-herinneringen.lnk = ?
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZN
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {1678F7E1-C422-11D0-AD7D-00400515CAAA} - http://files.cometsystems.com/cometcursor/comet.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/FunBuddyIconsFWBInitialSetup1.0.0.8.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab30149.cab
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.logitech.com/companion/logitech/ver1.3.0.2041/bin/imvid.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Waarschuw beheerder
:/ weer een aantal kut toolbars.. :/ dit kent weg:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.kjwpxfzbesohbzblnol.com/IZ4visGjtS5tOJsvMhfWou8P2UFEvmr4MFwNFiIQqTfzeWZledt0RA0dKpRm99cr.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pfefcbjgsndhvgjxnndam.com/IZ4visGjtS4eb24yEBEP45UJOFA7UXrLUeFdwF24CT0.htm
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O4 - HKLM\..\Run: [msbb] c:\program files\ncase\msbb.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Hotbar] C:\Program Files\Hotbar\bin\Hbinst.exe /Upgrade
O4 - HKLM\..\Run: [2junkforstupid] C:\Documents and Settings\All Users\Application Data\bytebat2junk\ping global.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\6.bin\mwsoemon.exe
O4 - HKCU\..\Run: [deadante] C:\DOCUME~1\Miranda\APPLIC~1\DRIVEO~1\size start draw.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\6.bin\MWSOEMON.EXE
O4 - Global Startup: Microsoft Works Agenda-herinneringen.lnk = ?
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZN
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {1678F7E1-C422-11D0-AD7D-00400515CAAA} - http://files.cometsystems.com/cometcursor/comet.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/FunBuddyIconsFWBInitialSetup1.0.0.8.cab
:yes:
Waarschuw beheerder
donateur
Logfile of HijackThis v1.99.0
Scan saved at 21:17:47, on 15-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\CNYHKey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Browser MOUSE\mouse32a.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Odometer\Odometer.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\DOCUME~1\DENNIS~1\LOCALS~1\Temp\{D72A1C9C-403C-4163-960D-C17780954B6C}\AquariumDesktop.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Home Cinema\PowerCinema\PCM2.exe
C:\Documents and Settings\Dennis van den Broek\Mijn documenten\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://party.snt.utwente.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.partflock.nl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Odometer.lnk = C:\Program Files\Odometer\Odometer.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Gelijkwaardige pagina's - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Koppelingspagina's - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/23b2b94751f7cd2f3306/netzip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100388636078
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: X10 Device Network Service - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe


:/
Waarschuw beheerder
donateur
ff een wilde gok! :D

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)



verder zou ik niet weten! :/
laatste aanpassing
Waarschuw beheerder
+
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [Microsoft Works Update Detection] C:Program FilesCommon FilesMicrosoft SharedWorks SharedWkUFind.exe
deze hoeven niet opgestart te worden.. :/
Waarschuw beheerder
donateur
Nog een x dan! :D

Logfile of HijackThis v1.99.0
Scan saved at 23:45:51, on 15-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\CNYHKey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Browser MOUSE\mouse32a.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Odometer\Odometer.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\DOCUME~1\DENNIS~1\LOCALS~1\Temp\{D72A1C9C-403C-4163-960D-C17780954B6C}\AquariumDesktop.exe
C:\Program Files\Home Cinema\PowerCinema\PCM2.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Dennis van den Broek\Mijn documenten\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://party.snt.utwente.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.partflock.nl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Odometer.lnk = C:\Program Files\Odometer\Odometer.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Gelijkwaardige pagina's - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Koppelingspagina's - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/23b2b94751f7cd2f3306/netzip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100388636078
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: X10 Device Network Service - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
 
Waarschuw beheerder
ogfile of HijackThis v1.99.0
Scan saved at 13:15:48, on 16-1-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\ATI-CPanel\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\DitExp.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Marijn\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.partyflock.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchweb2.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.partyflock.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)
O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Gelijkwaardige pagina's - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Koppelingspagina's - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14325268-79E0-4D2A-89A4-FFFC6E22741E} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_3_EN_XP.cab
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {50AD557E-3426-41FD-AFDD-2AF39BB1C387} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_5_EN_XP.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095108578828
O16 - DPF: {66E79B75-F711-4A88-9C6D-10BCA64F3306} (DriveCamPlayer Class) - http://www.drivecam.com/videos/DriveCamEvent.dll
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/nl/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://195.18.69.102/activex/AxisCamControl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://asp02.photoprintit.de/5/defaults/activex/XUpload.ocx
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O18 - Protocol: bw+0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: EPSON Printer Status Agent2 - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner - Network Associates, Inc. - C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe


topicopener.. weet jij nu wat rotzooi is en wat niet?
Waarschuw beheerder
Xes: alleen die R0 waar geen website staat nog..

ELEGAL:
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://searchweb2.com/searchbar.html
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)
O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [MessengerPlus3] "C:Program FilesMessenger Plus! 3MsgPlus.exe"
O4 - HKCU..Run: [MessengerPlus3] "C:Program FilesMessenger Plus! 3MsgPlus.exe" /WinStart
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O16 - DPF: {66E79B75-F711-4A88-9C6D-10BCA64F3306} (DriveCamPlayer Class) - http://www.drivecam.com/videos/DriveCamEvent.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://195.18.69.102/activex/AxisCamControl.cab
dat was het even voor nu dat ken allemaal weg.. ;)
 
Waarschuw beheerder
OK. thanx! (Y) heb ze ge(fixed) -deleted.
dit was het enige wat weg kan?
Waarschuw beheerder
Plaats een nieuwe log
Waarschuw beheerder
donateur
ken ie niet beter zn oude post editen? wordt beetje zooitje anders met al die lappen tekst achter elkaar
Waarschuw beheerder
alles kan.. ;)

maar je kan ook gewoon vanaf R1/RO beginnen.. :9
Waarschuw beheerder
euhhhhh Odie.. ik heb een klein probleempje..... :D




Logfile of HijackThis v1.98.2
Scan saved at 23:06:16, on 16-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\HHVcdV5Sys\VC5SecS.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\WINDOWS\anvshell.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\DitExp.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\windows\fdbutes.exe
C:\windows\fdbutes.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\devil\Bureaublad\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://yoursearcher.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://yoursearcher.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yoursearcher.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://yoursearcher.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://yoursearcher.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINDOWS\webdir.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [Anvshell] anvshell.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [FDIFx3B] C:\WINDOWS\jpbwg.exe
O4 - HKLM\..\Run: [¢‰¸K0¨4W
}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\jpbwg.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [qlyqiwi] c:\windows\ropfaga.exe
O4 - HKCU\..\Run: [edpwxvf] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [bidtddt] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [gcnalcj] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [dhchbwu] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [bfxptgt] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [hpdsnrg] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [urvhgki] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [kpfkioa] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [ejwvwjx] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [soijjbt] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [tmtgnes] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [ogmwdkr] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [yffxfwx] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [clvmcum] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [orhlfjh] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [ssowgtc] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [synpukh] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [whabmsx] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [juynuhk] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [onolesi] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [tdlnebn] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [arnbgfe] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [bfwhmci] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [hvwclih] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [wdtdpdd] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [beomnme] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [wbcspsb] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [tjefbrt] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [xnexjnm] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [pxoxgmr] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [ajrtnlr] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [toivbqu] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [jdwppoo] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [eqmlqba] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [nxftehg] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [luuhrqy] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [yvuvffe] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [rrbbddn] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [wlqekhp] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [peqcaox] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [nltrjot] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [hlwpksd] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [hwrkaaa] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [nmqqgnc] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [tinelei] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [jfrascr] c:\windows\girrsrf.exe
O4 - HKCU\..\Run: [bgfncep] c:\windows\jaiuduu.exe
O4 - HKCU\..\Run: [pccugkh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [auaxnuw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dvfvjyj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wwpmvek] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [yqtkhsk] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [pliyimo] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [utvyeha] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nukyyjs] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gmdsxky] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [cpyyawd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [hnbksma] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [lxrsnjq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wicfgiv] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [uiemerj] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hdmoyrf] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [elkaouq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [rybwjou] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [snnjuvj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jkdahol] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [bohnaui] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xmcwfiw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [beolnge] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ivwildn] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dkptkvq] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [syhjdxt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [pwixxoh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xexrfjg] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [svhhnjh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [jwgilub] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wckuaaj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [gqgmuak] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ftlpjhw] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nuwvfql] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ahkyqpg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [xfmxqxt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [jnhobur] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [kmwwsav] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [vuaicis] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [pkqyhrw] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [glsbtbp] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ngpdxoa] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [edhddja] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [maxonsl] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [qkinwnr] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nqyuoli] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ckvoksp] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wfeebsa] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xbktujx] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [srsnmld] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [rifnxkc] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [igsqnkd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jocrasn] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xyldhpb] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [anjuahw] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qwymuch] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hnwdhtr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [uslmyis] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [yiiylka] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [lovmvtf] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hmtxuch] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [leowgpo] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bxhssee] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [yfljmlv] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [mglfose] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [jhyfcml] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ucxftki] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [lejuxkg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [smrdmfu] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [utelsyp] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [vukahfi] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [lvcxiqh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [eswvxqt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bonbyec] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [qvsjhfo] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [cvrcvtw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ckwcgtn] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ameakeh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [khgorik] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ifttrgw] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ibuedix] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [kkdlyqa] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [vgbqtjj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [urueuwm] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [niyebye] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [roqdtkh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [udeejxw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [cuohwbk] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [avhuxqb] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xcqqfgl] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [muqkqut] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ruhvluc] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dunnkby] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [sxcgfby] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [fbkgahr] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qosjbpb] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [nfxqitm] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [rgsuqet] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [uraikjv] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gaiwvew] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [bdhkqnt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [atfnjtj] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [nwanvlg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dmmxyip] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [fklmywf] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [wqtxxxg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gowrion] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [cakbbvb] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ibtxudy] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [xccjaao] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ifpjdcb] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ffbpkfs] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [meirobv] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [dmsewag] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qsjrjmx] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bmkhqmw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bokakvu] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [oesrdom] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hlsweis] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [rgdgqst] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [sxpgwlb] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [oxquiaa] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [unnrkjt] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qgrfbvr] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [irbpbdl] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ysefyoe] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xayvmhu] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [yoxbkaj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [asvujdr] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [dmltnyi] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [elicsrh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hopupgj] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hovymwc] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [iagucag] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ahnscme] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gjqdeyb] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [alnmfnd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [gihridq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [oycxqlk] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [wtkaadr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [xuavwgd] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [mtmgxjt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [eqcturn] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [unwadlr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dagrqhe] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [pumhfba] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [mnitjoy] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [vsqvwto] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gyxryvd] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [xlorhmg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [sfghqso] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [mntwoir] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [glwsfwr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dohmeuc] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [vnrkkdd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [tkhwnxv] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [krpmlro] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [twnyluy] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [fcioutm] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jwkqvjd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ogrkfft] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nljdoep] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nduhrus] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [fdyohjs] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nwqdwyh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ynsuiyi] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [yjyepqp] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [vhxgwox] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bwrpgwf] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ncrkaak] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qjtyjuh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [htumbmk] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [rhtavks] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [arlmrnh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [voilleh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gpjjmng] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [athnpju] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [tokunua] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [geipxhr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [cxhtttk] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [davirno] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [sllwnxd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ivebupd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jhymgpq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jwteoqc] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [qauvekh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [twonqar] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [tosxxfg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ueqcuvh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ulyhfxi] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [jtyoggk] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [fjqqvxv] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [knpfcrf] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [uqhjlnq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [vuxgjem] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [whwsglt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ehrfoul] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [lcvnoyd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [slyhwls] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [gclbomm] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [pbrqfcn] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wptxwkl] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [kfmwagx] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [biuycid] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [kbvhiud] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [mogefqe] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [twkpbqr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [mwqccwo] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ybxsdte] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [picmhsg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ssorjqo] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vgeltrc] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lgwdoxv] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tkobqbe] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rvnlsjn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [adcdbkk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rwggoww] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [fvrfcid] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bsivmah] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [erxefmt] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rkamyrx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [otfqqof] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [moatgdp] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [mdovddl] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [iiwjqog] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [fnbjkdy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [iknktno] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [peamtrn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [eprmqjw] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [njupuag] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [tvgiphk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lkxagma] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ruqybvq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lgytptg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nuhbfeu] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [fyohkfy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [qsnhwni] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [cwvlcbj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vocuvjo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [nbfsjmg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nosjgsr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vukrgkd] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hiyyuxo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [lnryupi] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [gtsllgv] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [umonkrs] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [vqbysrm] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [nxtivsx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xbowitn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [twchdjf] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [uretrys] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ysnbkfm] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ksjsmrt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [dvyiuyn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jvmpyad] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qnuvplp] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [yasaflr] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bhojgsa] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [erejgyw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [udmsfwa] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nqhaadm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vgnaooa] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [liojrcs] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uagruva] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [xqtiolm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [mmwnqdb] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ifsxytc] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tqkboos] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [owglekq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [itxhggj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lnmtxbq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pcmrtot] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pixmsme] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [kgyqiwg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ewsjegy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [onenfxi] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rdcksma] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jpsylwj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rsuhkvm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [dygfcya] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [fttmcsk] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wkxriko] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wwhxqus] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bjstcrf] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hwxavir] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lkdcywh] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nfcygnf] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ppnxrfx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uvhlbub] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ytlpttt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [nkvvmtg] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qvgqprq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [owafblq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jxscfcq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [yyfcbkw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uwfxfxo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [dqafsep] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [iowjbsb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xhcpexq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [igrfmdn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [unexjix] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xeknrom] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pqcpdut] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [dqfxbpa] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [oqmamqn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hlmwrfl] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hociovw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wdjikbv] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lmbvrkj] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ophumcy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [hwdbphh] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xjiukjy] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [brensux] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [engfbmq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ttrnhmk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [djlnqvr] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [vmprdud] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uuxjfgm] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [rthycnk] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qevpobx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [srihcuc] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [tfxiage] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [aigvvdk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [xaarqkf] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [hfmtpyq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [sxefofr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [xdtdjxl] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ufijloc] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pptxlwx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ylxbgbt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ejjkhnp] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [iffcshd] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [inqisdc] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [cppxswa] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [tkhxysr] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [evviwoh] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [egjgqdl] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [kgijwbb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [elrwtrr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [kigljlw] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ovnrfsh] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ioukhnb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hulubdy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [voigepi] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [saocyja] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [motecud] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [flcbkif] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wxakubo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [trlmyxg] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [jwooayj] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hdtbcax] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [yjmcikc] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tuuskrp] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [scypclm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rmfcqwa] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uqnqrqc] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nexatiy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tpidgju] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [scgwwxg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [urfjrof] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [gcbbwbo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [vvgpwlv] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qadejvq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [momconm] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [aujmkuy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jrhubwl] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [wsalesy] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pvwphai] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [vhxsdsi] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tirkdei] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [irofjnk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [iieqvsb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ixgwwpc] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bpcwpnq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [yyxravs] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [oxwcrwb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pnfaubd] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ahjvlix] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [aklqtsi] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hikryyr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jpgqixw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bjqekaj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jjkryeq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [emjnyvx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xmamald] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ytadpny] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [sdoerge] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [iddlecr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vpsxkww] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ymtcuic] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qetabsy] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [fbiubrg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [fygoocv] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [akxvgdn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rjahtbq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [pwpadiw] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [iciqrqr] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [mowgboo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [tbtynok] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hlgqmpf] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [eiyivkp] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [olxvrtu] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bqxshul] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bccddjo] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jdostyr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jhraopn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [cbwoflb] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [krdngvb] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [haabgpt] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [btdppue] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [qluwyqs] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vbursut] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nsojuko] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uyfdxpa] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bfwfxas] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xuqyafq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hmcyalr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [gvjdwbs] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [psquibj] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qxmqnwh] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tpfpayt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [jveknsg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [pbguist] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ldnpjej] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [coobped] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [dvhqryn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bcstjwd] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [qatsjmm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [gggoagt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [leggdcw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [gnfnwml] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [mrcgpjn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [otttwjg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [wllwodw] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [qnfvfnj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [pcrpecp] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [mxljcab] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [umobwhl] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [dwtbjrf] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [iokfycg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vjhleoq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [kewwwol] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pjrxbjk] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ucysepy] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [fdpbrce] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wctiaqj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [sltcyqi] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rehqvja] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [caebarx] c:\windows\muwvgdh.exe
O4 - HKCU\..\Run: [lrlliab] c:\windows\fdbutes.exe
O4 - HKCU\..\Run: [oajkhnq] c:\windows\kacbsju.exe
O4 - HKCU\..\Run: [ifuugil] c:\windows\fdbutes.exe
O4 - HKCU\..\Run: [edyqrjh] c:\windows\kacbsju.exe
O4 - HKCU\..\Run: [rtbeheq] c:\windows\fdbutes.exe
O4 - HKCU\..\Run: [rgciavg] c:\windows\grfrfmr.exe
O4 - HKCU\..\Run: [qnlmend] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [nvflgnn] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [rfalasv] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cbcadiv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [drfcqme] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cnrldmq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [olpxpqg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [tyqbyot] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [diiadvt] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [iejhnny] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ioyysof] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [taclrbg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ylvdenf] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sdgtpgu] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wnouldl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [bgtnnws] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xutcucy] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [hjhpisl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ttttqyc] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [iwccrqm] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ewsxgrd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [yyjyyqq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [fosrrhf] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [crlndwh] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xdvinlb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [jelhklq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [oieohtr] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pnfcggx] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [yrlkjsp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ublijsd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xknotxg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [mvxorlu] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ohxfnnr] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [icacyiv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mlhobtw] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xdwnymy] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [njdodmh] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ffnrvoh] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [hsshdtp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [jisfrhq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [amqygvv] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [aopgfsk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [qkovbdy] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [kanmgel] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [nenlfij] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [vkgpwts] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xdavmaq] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [hfgyogv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [tjbrkrg] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [qpdjadr] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [vwfbavq] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [runmebw] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [sxwwunp] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pwbaqdl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [uvcmgbd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [chhgihc] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [qoyagrd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [etkywje] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ftyipej] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [docklfh] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xtpiqir] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [soqblwg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [pbfudxn] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [mmidjya] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [eqlqstx] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [bqbuvuk] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [vsutvhs] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wdagxvn] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [fpwautp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [nsngymm] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [erpagrp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [gxdekjx] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ribqnog] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [icyjsnm] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ygintwi] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [prtkqqi] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [fyovibk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ptiocmw] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xfgojvr] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ubmlwbc] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dcjttfb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [lwayjfg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [tyvjgbq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [nelhuwj] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [pcwswgs] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wxothom] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sqhvnrs] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [lmfiuby] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [vpspdpj] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [icsqpll] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [vrgvcxo] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [hgeokne] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [qtvobtt] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [bstgaqx] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [osvimhn] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dkmvwvy] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [bsnybwi] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xeievhp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [dnrynii] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [umqwvcx] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [rtfdprk] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [hbgttow] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [gkwrehd] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [gcanbmf] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [eqpgulo] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mvkehki] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [gtfldwn] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [klmulba] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [cjkguav] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [pbhcnsx] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [vjqbklm] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [kembeqs] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [slbweuf] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [llkspgl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xudyrjv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [vkbfpvv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xcwlwwh] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mtivple] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [iqmjwgc] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ablhewj] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wefggbg] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [txwgncg] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ovdfxuu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [vfewrlo] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mhokolx] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mjyyfmb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [glrujnw] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [qvqwhqn] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dtdwspj] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [rjwxqte] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [eqxyqly] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [uqnxehk] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [grrbjev] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [fxklxjs] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [mjjbceu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [hfduvwl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ifxlbcp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [dresilf] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [kimokgu] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [kkjunfy] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [qiwgyip] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [txqepre] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [eoxrcbf] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ohqkrqe] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [jdlbgjb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [nlnawta] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ptjwcbe] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [trqnrvp] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [tbcbpdi] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [bxclemj] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dxkvvmh] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [glikmuy] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sfmhwuu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [qekegpr] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [eoattfr] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ybbbdru] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pmcmuie] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ggkjujk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [bqecjyu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pdraxkk] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [rmlaomq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cmnsmim] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xquicmv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [asbrmib] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [neetrdk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [klqcpkq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [iutciqi] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [nkgagml] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ledlymt] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [lmgjpvi] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [cxvarab] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [byjfaps] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xidxbfd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sfnsjfs] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mtecixp] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [psnncxd] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [aalyvom] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [uttqjad] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [fybndfv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pjxgrss] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [caynpkm] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [rnaaois] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [btuoceb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [bniisil] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dolmodr] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ntuampg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xjsutqa] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [tnfdotc] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [chanqjk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sbedhpg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cwmocma] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wixhtoc] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cjcfldu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xcjtcjp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [iagcygi] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dvkeuco] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pfgjido] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pbpxhao] c:\windows\nlntunk.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab



Er kan wel iets van weg neem ik aan?? Help me! Alles loopt vast :( :( :(
(en krijg die yoursearcher maar niet weg)
(en ik krijg die irritante winmin medling niet weg bij et afsluiten..)

Je bent een held ;)
laatste aanpassing
Waarschuw beheerder
donateur
You must be kiddin' :jaja: