Partyflock
 
Forumonderwerp · 710662
7447x bekeken

Onderwerp is gesloten!

Dit gebeurt meestal omdat een of meerdere personen het beleid hebben overtreden.
Het kan natuurlijk ook zijn dat er al een actieve discussie over hetzelfde onderwerp was.
Dit soort situaties zijn te voorkomen door op de hoogte te blijven van het beleid.

Waarschuw beheerder
Ik zie weer mensen die last hebben van spyware en denk laat ik maar een groot topic openen dan hoef er niet elke keer weer hetzelfde.. ok:

[SPYWARE: wat is het en wat doet het?]

Spyware zijn kleine programma's (DLLs/executables) die tijdens de installatie van sommige stukken software ongevraagd worden meegeïnstalleerd (ook al staat het meestal wel vermeld in de readme/EULA). Ook kunnen dit soort programma's op je PC komen als je tijdens het surfen op "bepaalde" sites te snel op "OK" klikt, of de beveiligingsinstellingen van Internet Explorer 🇮🇪 te laag hebt staan.

Eenmaal geïnstalleerd verzamelt het programma gegevens (naar welke websites je surft bijvoorbeeld) en zend die via internet naar de softwarefabrikant. Naast de privacyproblemen die je hiermee hebt, gebeurt het vaak dat er om de haverklap reclame in beeld komt, je Internet Explorer vastloopt of erg traag wordt. Ook wil het regelmatig voorkomen dat je een extra "zoekbalk" in beeld krijgt:

[img cacheid=0007335700136d0410e9667f1a00689ff5]http://members.lycos.nl/tinarulez/hpbimg/sp1.gif[/img]

Daarnaast kan het er voor zorgen dat je bij niet gevonden internetpagina's wordt omgeleid naar de webpagina van de spyware makers.

De meeste spyware is te verwijderen met behulp van: Ad-aware en Spybot Search & Destroy. Deze programma's hebben (netzoals een virusscanner) een update-functie om de nieuwste spyware te herkennen, gebruik deze dan ook vóór je op spyware gaat scannen. Als je niet precies weet wat je wel en niet moet doen, kan je dit topic doorlezen of je vragen stellen.

Ook zijn er online scanners, namelijk PestScan en Spywareinfo's online scanner. Beide werken alleen onder Internet Explorer, zie voor meer info:

http://www.pestscan.com/
http://www.spywareinfo.com/xscan.php

Mochten Ad-aware en Spybot S&D het niet weghalen, dan kan je ook nog het programma HijackThis gebruiken. Pas hier wel mee op! HijackThis ziet niet het verschil tussen wat wel en niet op je pc hoort.

Met deze twee programma's kan je kijken wat er allemaal opgestart wordt als je je PC aan zet, en er zo misschien achterkomen wat je PC heeft geïnfecteerd. HijackThis kan ook een log maken, deze zou je eventueel hier kunnen posten of mailen als je er niet uit komt. Als je niet weet wat een bepaald proces doet, kan je de bestandsnaam even inkloppen op Google. Zo kom je er bijvoorbeeld achter dat smss.exe gewoon thuishoort op je PC.

Voorkomen is beter dan genezen natuurlijk!
Druk daarom nooit overal klakkeloos op "Ja" bij dit soort vensters:

[img cacheid=0001477d0002cfcb57491caf1a00689ff5]http://members.lycos.nl/tinarulez/hpbimg/sp2.gif[/img]

Zelfs als je altijd op "nee" drukt, kan het toch voorkomen dat je geinfecteerd word door spyware. Dit komt meestal door lekken in Internet Explorer, update je windows dan ook regelmatig via:

http://windowsupdate.microsoft.com/


[Hoe de programma's werken?]

Ad-aware
Een simpel programma waarmee de niet al te hardnekige spyware mee verwijderd kan worden.

1.) Downloaden

http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022-10319876.html?tag=lst-0-4

2.) Installeren & Lavasoft Ad-aware opstarten

3.) Web-update uitvoeren (zodat hij ook de nieuwste spyware etc kan detecteren)

[img]http://images.sugababes.nl/sonic/spyware/adawarese1.png[/img]

4.) Scannen via de standaardopties

[img cacheid=0007335800136d0a4b0626bb1a00689ff5]http://members.lycos.nl/tinarulez/hpbimg/sp3.png[/img]

5.) Na het scannen op "next" drukken.

[img cacheid=0007335900136d0bf926faab1a00689ff5]http://members.lycos.nl/tinarulez/hpbimg/sp4.png[/img]

6.) Uitvinken wat je wilt bewaren.
Je kunt dubbelklikken op een gevonden item om te kijken wat het inhoud. Als de beschrijving als "troep" eruit ziet (bijv. malware) dan moet je het gewoon aangevinkt laten staan, zodat het bij de volgende stap wordt verwijdert.

Opmerking:
Het kan zijn dat programma's als Kazaa niet meer werken nadat je je pc hebt "schoongemaakt" met ad-aware. Kazaa is namelijk meestal de grootste veroorzaker van spyware. Advies: gebruik daarom K-lite (de variant van Kazaa zonder spyware).

7.) Verwijderen die hap! (met enter of next/doorgaan)

8.) KLAAR!

(evt. je PC opnieuw starten om de wijzigingen in werking te laten treden)


SpyBot Search and Destroy

1.) Downloaden

http://www.download.com/Spybot-Search-Destroy/3000-8022-10289035.html

2.) Open spybot - Sear & Destroy

3.) Kijk eerst of er updates zijn voor dit programma via de knop "zoek naar updates"

[img]http://images.sugababes.nl/sonic/spyware/spy2.png[/img]

4.) Als er updates zijn selecteer dan alle updates en klik op "download updates"

5.) klik op "check for problems".

[img]http://images.sugababes.nl/sonic/spyware/spy3.png[/img]

En klik dan op "controleer alles" en het scannen begint.

[img]http://images.sugababes.nl/sonic/spyware/spy4.png[/img]

6.) Als hij klaar is druk je op "Fix selected problems" en start je PC opnieuw op.

[img]http://images.sugababes.nl/sonic/spyware/spy5.png[/img]

Opmerking:
Het kan ook zijn dat spybot 1 of meerdere problemen niet kon oplossen, doordat de bestanden in gebruik zijn. Dan wordt er gevraagd om opnieuw op te starten.


[OVERIGE TOOLS om spyware mee te verwijderen]

HijackThis

Een simpele, maar destructieve tool.. Met HijackThis kan je zien wat er allemaal automatisch word opgestart als je computer aanzet..

1.) Downloaden

http://computercops.biz/downloads-file-328.html

2.) Open HijackThis en druk op scan. (Ga niet zomaar dingen lopen verwijderen!)

3.) Klik op save log en post je log hier..

LET OP!:
Nooit zelf zomaar dingen aanvinken! HijackThis ziet namelijk NIET wat goed en slecht is! (wat ernstige consequenties kan hebben)


CWShredder

1.) Downloaden

http://computercops.biz/downloads-file-349.html

2.) Sluit alle openstaande Internet Explorer pagina's

3.) Start CWShredder

4.) Druk op fix (Er zal een venster verschijnen, klik daar gewoon op OK)

5.) Het scannen begint, druk op next en vervolgens exit.

[HANDIGE LINKS]

Handleiding - simpel en doeltreffend:
http://users.pandora.be/majoorke/Ad%20aware.htm

Handleiding - meer uitleg: [url]http://www.breekpunt.nl/artikel.asp?Artikel=782&art=Yes[/url]

Meer info over spyware:
http://gathering.tweakers.net/forum/list_messages/843971

dus als je het niet lukt drop het hier dan kijken we er wel naar.. O:)

Nieuw handige tool om spyware te verwijderen.. (mede ook door danie)

Hitman Pro:

Wat is Hitman Pro?

Hitman Pro is de ultieme spyware removal tool. Het is een schil voor een aantal gevestigde spyware en adware schoonmaak- en beschermingsprogramma's. De gebruiker hoeft slechts het bedieningsoppervlak van Hitman Pro te bedienen waarna de externe programma's automatisch door Hitman Pro worden aangestuurd. Hitman Pro bevat ook een aantal eenvoudige passieve beschermingsopties waarmee het lastiger wordt om wederom door spyware besmet te raken.
Hitman Pro is daarom een ideale tool voor iedere computergebruiker.

[img cacheid=00132c4500136d1235f85f081a00689ff5]http://www.hitmanpro.nl/gui.gif[/img]

Download het hier:
http://members.home.nl/mloman/setup.exe

O:)
laatste aanpassing door een beheerder
 
Waarschuw beheerder
Logfile of HijackThis v1.99.0
Scan saved at 18:47:53, on 15-1-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Smtray.exe
C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\COMPAQ\CPQINET\CPQInet.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\program files\ncase\msbb.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hotbar\bin\Hbinst.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\eFax Messenger Plus 3.3\J2GDllCmd.exe
C:\Program Files\eFax Messenger Plus 3.3\J2GTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\ntvdm.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Miranda\LOCALS~1\Temp\Tijdelijke map 1 voor hijackthis.zip\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.kjwpxfzbesohbzblnol.com/IZ4visGjtS5tOJsvMhfWou8P2UFEvmr4MFwNFiIQqTfzeWZledt0RA0dKpRm99cr.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pfefcbjgsndhvgjxnndam.com/IZ4visGjtS4eb24yEBEP45UJOFA7UXrLUeFdwF24CT0.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {32D13202-D2EB-1B2A-2D9D-4B08ABE22989} - C:\DOCUME~1\Miranda\APPLIC~1\IDOLBU~1\BinSoftware.exe
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [msbb] c:\program files\ncase\msbb.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [Hotbar] C:\Program Files\Hotbar\bin\Hbinst.exe /Upgrade
O4 - HKLM\..\Run: [2junkforstupid] C:\Documents and Settings\All Users\Application Data\bytebat2junk\ping global.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\6.bin\mwsoemon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [deadante] C:\DOCUME~1\Miranda\APPLIC~1\DRIVEO~1\size start draw.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\6.bin\MWSOEMON.EXE
O4 - Global Startup: eFax Live Menu 3.3.lnk = C:\Program Files\eFax Messenger Plus 3.3\J2GDllCmd.exe
O4 - Global Startup: eFax Tray Menu 3.3.lnk = C:\Program Files\eFax Messenger Plus 3.3\J2GTray.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Agenda-herinneringen.lnk = ?
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZN
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {1678F7E1-C422-11D0-AD7D-00400515CAAA} - http://files.cometsystems.com/cometcursor/comet.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/FunBuddyIconsFWBInitialSetup1.0.0.8.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab30149.cab
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.logitech.com/companion/logitech/ver1.3.0.2041/bin/imvid.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Waarschuw beheerder
:/ weer een aantal kut toolbars.. :/ dit kent weg:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.kjwpxfzbesohbzblnol.com/IZ4visGjtS5tOJsvMhfWou8P2UFEvmr4MFwNFiIQqTfzeWZledt0RA0dKpRm99cr.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pfefcbjgsndhvgjxnndam.com/IZ4visGjtS4eb24yEBEP45UJOFA7UXrLUeFdwF24CT0.htm
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O4 - HKLM\..\Run: [msbb] c:\program files\ncase\msbb.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Hotbar] C:\Program Files\Hotbar\bin\Hbinst.exe /Upgrade
O4 - HKLM\..\Run: [2junkforstupid] C:\Documents and Settings\All Users\Application Data\bytebat2junk\ping global.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\6.bin\mwsoemon.exe
O4 - HKCU\..\Run: [deadante] C:\DOCUME~1\Miranda\APPLIC~1\DRIVEO~1\size start draw.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\6.bin\MWSOEMON.EXE
O4 - Global Startup: Microsoft Works Agenda-herinneringen.lnk = ?
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZN
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {1678F7E1-C422-11D0-AD7D-00400515CAAA} - http://files.cometsystems.com/cometcursor/comet.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/FunBuddyIconsFWBInitialSetup1.0.0.8.cab
:yes:
Waarschuw beheerder
donateur
Logfile of HijackThis v1.99.0
Scan saved at 21:17:47, on 15-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\CNYHKey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Browser MOUSE\mouse32a.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Odometer\Odometer.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\DOCUME~1\DENNIS~1\LOCALS~1\Temp\{D72A1C9C-403C-4163-960D-C17780954B6C}\AquariumDesktop.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Home Cinema\PowerCinema\PCM2.exe
C:\Documents and Settings\Dennis van den Broek\Mijn documenten\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://party.snt.utwente.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.partflock.nl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Odometer.lnk = C:\Program Files\Odometer\Odometer.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Gelijkwaardige pagina's - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Koppelingspagina's - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/23b2b94751f7cd2f3306/netzip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100388636078
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: X10 Device Network Service - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe


:/
Waarschuw beheerder
donateur
ff een wilde gok! :D

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)



verder zou ik niet weten! :/
laatste aanpassing
Waarschuw beheerder
+
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [Microsoft Works Update Detection] C:Program FilesCommon FilesMicrosoft SharedWorks SharedWkUFind.exe
deze hoeven niet opgestart te worden.. :/
Waarschuw beheerder
donateur
Nog een x dan! :D

Logfile of HijackThis v1.99.0
Scan saved at 23:45:51, on 15-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\CNYHKey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Browser MOUSE\mouse32a.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Odometer\Odometer.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\DOCUME~1\DENNIS~1\LOCALS~1\Temp\{D72A1C9C-403C-4163-960D-C17780954B6C}\AquariumDesktop.exe
C:\Program Files\Home Cinema\PowerCinema\PCM2.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Dennis van den Broek\Mijn documenten\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://party.snt.utwente.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.partflock.nl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Odometer.lnk = C:\Program Files\Odometer\Odometer.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Gelijkwaardige pagina's - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Koppelingspagina's - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/23b2b94751f7cd2f3306/netzip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100388636078
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: X10 Device Network Service - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
 
Waarschuw beheerder
ogfile of HijackThis v1.99.0
Scan saved at 13:15:48, on 16-1-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\ATI-CPanel\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\DitExp.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Marijn\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.partyflock.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchweb2.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.partyflock.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)
O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Gelijkwaardige pagina's - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Koppelingspagina's - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14325268-79E0-4D2A-89A4-FFFC6E22741E} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_3_EN_XP.cab
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {50AD557E-3426-41FD-AFDD-2AF39BB1C387} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_5_EN_XP.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095108578828
O16 - DPF: {66E79B75-F711-4A88-9C6D-10BCA64F3306} (DriveCamPlayer Class) - http://www.drivecam.com/videos/DriveCamEvent.dll
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/nl/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://195.18.69.102/activex/AxisCamControl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://asp02.photoprintit.de/5/defaults/activex/XUpload.ocx
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O18 - Protocol: bw+0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {7D078752-8978-4DB0-8D43-211798FEA815} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: EPSON Printer Status Agent2 - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner - Network Associates, Inc. - C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe


topicopener.. weet jij nu wat rotzooi is en wat niet?
Waarschuw beheerder
Xes: alleen die R0 waar geen website staat nog..

ELEGAL:
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://searchweb2.com/searchbar.html
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)
O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [MessengerPlus3] "C:Program FilesMessenger Plus! 3MsgPlus.exe"
O4 - HKCU..Run: [MessengerPlus3] "C:Program FilesMessenger Plus! 3MsgPlus.exe" /WinStart
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O16 - DPF: {66E79B75-F711-4A88-9C6D-10BCA64F3306} (DriveCamPlayer Class) - http://www.drivecam.com/videos/DriveCamEvent.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://195.18.69.102/activex/AxisCamControl.cab
dat was het even voor nu dat ken allemaal weg.. ;)
 
Waarschuw beheerder
OK. thanx! (Y) heb ze ge(fixed) -deleted.
dit was het enige wat weg kan?
Waarschuw beheerder
Plaats een nieuwe log
Waarschuw beheerder
donateur
ken ie niet beter zn oude post editen? wordt beetje zooitje anders met al die lappen tekst achter elkaar
Waarschuw beheerder
alles kan.. ;)

maar je kan ook gewoon vanaf R1/RO beginnen.. :9
Waarschuw beheerder
euhhhhh Odie.. ik heb een klein probleempje..... :D




Logfile of HijackThis v1.98.2
Scan saved at 23:06:16, on 16-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\HHVcdV5Sys\VC5SecS.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\WINDOWS\anvshell.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\DitExp.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\windows\fdbutes.exe
C:\windows\fdbutes.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\devil\Bureaublad\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://yoursearcher.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://yoursearcher.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yoursearcher.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://yoursearcher.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://yoursearcher.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINDOWS\webdir.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [Anvshell] anvshell.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [FDIFx3B] C:\WINDOWS\jpbwg.exe
O4 - HKLM\..\Run: [¢‰¸K0¨4W
}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\jpbwg.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [qlyqiwi] c:\windows\ropfaga.exe
O4 - HKCU\..\Run: [edpwxvf] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [bidtddt] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [gcnalcj] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [dhchbwu] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [bfxptgt] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [hpdsnrg] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [urvhgki] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [kpfkioa] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [ejwvwjx] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [soijjbt] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [tmtgnes] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [ogmwdkr] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [yffxfwx] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [clvmcum] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [orhlfjh] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [ssowgtc] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [synpukh] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [whabmsx] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [juynuhk] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [onolesi] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [tdlnebn] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [arnbgfe] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [bfwhmci] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [hvwclih] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [wdtdpdd] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [beomnme] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [wbcspsb] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [tjefbrt] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [xnexjnm] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [pxoxgmr] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [ajrtnlr] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [toivbqu] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [jdwppoo] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [eqmlqba] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [nxftehg] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [luuhrqy] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [yvuvffe] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [rrbbddn] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [wlqekhp] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [peqcaox] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [nltrjot] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [hlwpksd] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [hwrkaaa] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [nmqqgnc] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [tinelei] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [jfrascr] c:\windows\girrsrf.exe
O4 - HKCU\..\Run: [bgfncep] c:\windows\jaiuduu.exe
O4 - HKCU\..\Run: [pccugkh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [auaxnuw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dvfvjyj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wwpmvek] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [yqtkhsk] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [pliyimo] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [utvyeha] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nukyyjs] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gmdsxky] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [cpyyawd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [hnbksma] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [lxrsnjq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wicfgiv] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [uiemerj] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hdmoyrf] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [elkaouq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [rybwjou] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [snnjuvj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jkdahol] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [bohnaui] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xmcwfiw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [beolnge] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ivwildn] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dkptkvq] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [syhjdxt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [pwixxoh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xexrfjg] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [svhhnjh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [jwgilub] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wckuaaj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [gqgmuak] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ftlpjhw] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nuwvfql] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ahkyqpg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [xfmxqxt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [jnhobur] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [kmwwsav] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [vuaicis] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [pkqyhrw] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [glsbtbp] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ngpdxoa] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [edhddja] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [maxonsl] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [qkinwnr] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nqyuoli] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ckvoksp] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wfeebsa] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xbktujx] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [srsnmld] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [rifnxkc] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [igsqnkd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jocrasn] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xyldhpb] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [anjuahw] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qwymuch] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hnwdhtr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [uslmyis] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [yiiylka] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [lovmvtf] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hmtxuch] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [leowgpo] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bxhssee] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [yfljmlv] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [mglfose] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [jhyfcml] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ucxftki] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [lejuxkg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [smrdmfu] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [utelsyp] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [vukahfi] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [lvcxiqh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [eswvxqt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bonbyec] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [qvsjhfo] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [cvrcvtw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ckwcgtn] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ameakeh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [khgorik] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ifttrgw] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ibuedix] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [kkdlyqa] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [vgbqtjj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [urueuwm] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [niyebye] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [roqdtkh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [udeejxw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [cuohwbk] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [avhuxqb] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xcqqfgl] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [muqkqut] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ruhvluc] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dunnkby] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [sxcgfby] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [fbkgahr] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qosjbpb] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [nfxqitm] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [rgsuqet] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [uraikjv] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gaiwvew] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [bdhkqnt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [atfnjtj] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [nwanvlg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dmmxyip] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [fklmywf] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [wqtxxxg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gowrion] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [cakbbvb] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ibtxudy] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [xccjaao] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ifpjdcb] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ffbpkfs] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [meirobv] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [dmsewag] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qsjrjmx] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bmkhqmw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bokakvu] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [oesrdom] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hlsweis] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [rgdgqst] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [sxpgwlb] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [oxquiaa] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [unnrkjt] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qgrfbvr] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [irbpbdl] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ysefyoe] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xayvmhu] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [yoxbkaj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [asvujdr] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [dmltnyi] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [elicsrh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hopupgj] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hovymwc] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [iagucag] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ahnscme] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gjqdeyb] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [alnmfnd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [gihridq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [oycxqlk] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [wtkaadr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [xuavwgd] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [mtmgxjt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [eqcturn] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [unwadlr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dagrqhe] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [pumhfba] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [mnitjoy] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [vsqvwto] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gyxryvd] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [xlorhmg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [sfghqso] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [mntwoir] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [glwsfwr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dohmeuc] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [vnrkkdd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [tkhwnxv] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [krpmlro] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [twnyluy] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [fcioutm] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jwkqvjd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ogrkfft] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nljdoep] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nduhrus] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [fdyohjs] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nwqdwyh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ynsuiyi] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [yjyepqp] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [vhxgwox] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bwrpgwf] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ncrkaak] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qjtyjuh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [htumbmk] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [rhtavks] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [arlmrnh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [voilleh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gpjjmng] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [athnpju] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [tokunua] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [geipxhr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [cxhtttk] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [davirno] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [sllwnxd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ivebupd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jhymgpq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jwteoqc] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [qauvekh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [twonqar] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [tosxxfg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ueqcuvh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ulyhfxi] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [jtyoggk] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [fjqqvxv] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [knpfcrf] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [uqhjlnq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [vuxgjem] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [whwsglt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ehrfoul] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [lcvnoyd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [slyhwls] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [gclbomm] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [pbrqfcn] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wptxwkl] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [kfmwagx] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [biuycid] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [kbvhiud] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [mogefqe] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [twkpbqr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [mwqccwo] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ybxsdte] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [picmhsg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ssorjqo] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vgeltrc] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lgwdoxv] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tkobqbe] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rvnlsjn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [adcdbkk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rwggoww] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [fvrfcid] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bsivmah] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [erxefmt] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rkamyrx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [otfqqof] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [moatgdp] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [mdovddl] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [iiwjqog] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [fnbjkdy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [iknktno] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [peamtrn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [eprmqjw] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [njupuag] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [tvgiphk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lkxagma] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ruqybvq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lgytptg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nuhbfeu] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [fyohkfy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [qsnhwni] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [cwvlcbj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vocuvjo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [nbfsjmg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nosjgsr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vukrgkd] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hiyyuxo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [lnryupi] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [gtsllgv] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [umonkrs] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [vqbysrm] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [nxtivsx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xbowitn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [twchdjf] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [uretrys] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ysnbkfm] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ksjsmrt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [dvyiuyn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jvmpyad] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qnuvplp] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [yasaflr] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bhojgsa] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [erejgyw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [udmsfwa] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nqhaadm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vgnaooa] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [liojrcs] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uagruva] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [xqtiolm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [mmwnqdb] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ifsxytc] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tqkboos] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [owglekq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [itxhggj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lnmtxbq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pcmrtot] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pixmsme] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [kgyqiwg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ewsjegy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [onenfxi] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rdcksma] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jpsylwj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rsuhkvm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [dygfcya] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [fttmcsk] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wkxriko] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wwhxqus] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bjstcrf] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hwxavir] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lkdcywh] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nfcygnf] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ppnxrfx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uvhlbub] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ytlpttt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [nkvvmtg] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qvgqprq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [owafblq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jxscfcq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [yyfcbkw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uwfxfxo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [dqafsep] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [iowjbsb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xhcpexq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [igrfmdn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [unexjix] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xeknrom] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pqcpdut] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [dqfxbpa] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [oqmamqn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hlmwrfl] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hociovw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wdjikbv] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lmbvrkj] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ophumcy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [hwdbphh] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xjiukjy] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [brensux] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [engfbmq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ttrnhmk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [djlnqvr] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [vmprdud] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uuxjfgm] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [rthycnk] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qevpobx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [srihcuc] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [tfxiage] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [aigvvdk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [xaarqkf] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [hfmtpyq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [sxefofr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [xdtdjxl] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ufijloc] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pptxlwx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ylxbgbt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ejjkhnp] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [iffcshd] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [inqisdc] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [cppxswa] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [tkhxysr] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [evviwoh] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [egjgqdl] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [kgijwbb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [elrwtrr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [kigljlw] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ovnrfsh] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ioukhnb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hulubdy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [voigepi] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [saocyja] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [motecud] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [flcbkif] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wxakubo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [trlmyxg] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [jwooayj] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hdtbcax] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [yjmcikc] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tuuskrp] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [scypclm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rmfcqwa] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uqnqrqc] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nexatiy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tpidgju] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [scgwwxg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [urfjrof] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [gcbbwbo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [vvgpwlv] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qadejvq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [momconm] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [aujmkuy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jrhubwl] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [wsalesy] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pvwphai] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [vhxsdsi] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tirkdei] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [irofjnk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [iieqvsb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ixgwwpc] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bpcwpnq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [yyxravs] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [oxwcrwb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pnfaubd] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ahjvlix] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [aklqtsi] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hikryyr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jpgqixw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bjqekaj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jjkryeq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [emjnyvx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xmamald] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ytadpny] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [sdoerge] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [iddlecr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vpsxkww] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ymtcuic] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qetabsy] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [fbiubrg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [fygoocv] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [akxvgdn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rjahtbq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [pwpadiw] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [iciqrqr] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [mowgboo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [tbtynok] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hlgqmpf] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [eiyivkp] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [olxvrtu] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bqxshul] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bccddjo] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jdostyr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jhraopn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [cbwoflb] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [krdngvb] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [haabgpt] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [btdppue] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [qluwyqs] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vbursut] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nsojuko] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uyfdxpa] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bfwfxas] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xuqyafq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hmcyalr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [gvjdwbs] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [psquibj] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qxmqnwh] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tpfpayt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [jveknsg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [pbguist] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ldnpjej] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [coobped] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [dvhqryn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bcstjwd] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [qatsjmm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [gggoagt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [leggdcw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [gnfnwml] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [mrcgpjn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [otttwjg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [wllwodw] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [qnfvfnj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [pcrpecp] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [mxljcab] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [umobwhl] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [dwtbjrf] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [iokfycg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vjhleoq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [kewwwol] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pjrxbjk] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ucysepy] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [fdpbrce] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wctiaqj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [sltcyqi] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rehqvja] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [caebarx] c:\windows\muwvgdh.exe
O4 - HKCU\..\Run: [lrlliab] c:\windows\fdbutes.exe
O4 - HKCU\..\Run: [oajkhnq] c:\windows\kacbsju.exe
O4 - HKCU\..\Run: [ifuugil] c:\windows\fdbutes.exe
O4 - HKCU\..\Run: [edyqrjh] c:\windows\kacbsju.exe
O4 - HKCU\..\Run: [rtbeheq] c:\windows\fdbutes.exe
O4 - HKCU\..\Run: [rgciavg] c:\windows\grfrfmr.exe
O4 - HKCU\..\Run: [qnlmend] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [nvflgnn] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [rfalasv] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cbcadiv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [drfcqme] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cnrldmq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [olpxpqg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [tyqbyot] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [diiadvt] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [iejhnny] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ioyysof] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [taclrbg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ylvdenf] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sdgtpgu] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wnouldl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [bgtnnws] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xutcucy] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [hjhpisl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ttttqyc] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [iwccrqm] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ewsxgrd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [yyjyyqq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [fosrrhf] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [crlndwh] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xdvinlb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [jelhklq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [oieohtr] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pnfcggx] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [yrlkjsp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ublijsd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xknotxg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [mvxorlu] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ohxfnnr] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [icacyiv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mlhobtw] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xdwnymy] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [njdodmh] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ffnrvoh] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [hsshdtp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [jisfrhq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [amqygvv] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [aopgfsk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [qkovbdy] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [kanmgel] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [nenlfij] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [vkgpwts] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xdavmaq] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [hfgyogv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [tjbrkrg] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [qpdjadr] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [vwfbavq] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [runmebw] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [sxwwunp] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pwbaqdl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [uvcmgbd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [chhgihc] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [qoyagrd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [etkywje] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ftyipej] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [docklfh] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xtpiqir] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [soqblwg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [pbfudxn] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [mmidjya] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [eqlqstx] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [bqbuvuk] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [vsutvhs] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wdagxvn] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [fpwautp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [nsngymm] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [erpagrp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [gxdekjx] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ribqnog] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [icyjsnm] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ygintwi] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [prtkqqi] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [fyovibk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ptiocmw] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xfgojvr] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ubmlwbc] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dcjttfb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [lwayjfg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [tyvjgbq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [nelhuwj] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [pcwswgs] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wxothom] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sqhvnrs] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [lmfiuby] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [vpspdpj] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [icsqpll] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [vrgvcxo] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [hgeokne] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [qtvobtt] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [bstgaqx] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [osvimhn] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dkmvwvy] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [bsnybwi] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xeievhp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [dnrynii] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [umqwvcx] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [rtfdprk] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [hbgttow] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [gkwrehd] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [gcanbmf] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [eqpgulo] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mvkehki] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [gtfldwn] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [klmulba] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [cjkguav] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [pbhcnsx] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [vjqbklm] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [kembeqs] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [slbweuf] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [llkspgl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xudyrjv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [vkbfpvv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xcwlwwh] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mtivple] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [iqmjwgc] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ablhewj] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wefggbg] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [txwgncg] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ovdfxuu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [vfewrlo] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mhokolx] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mjyyfmb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [glrujnw] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [qvqwhqn] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dtdwspj] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [rjwxqte] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [eqxyqly] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [uqnxehk] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [grrbjev] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [fxklxjs] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [mjjbceu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [hfduvwl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ifxlbcp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [dresilf] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [kimokgu] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [kkjunfy] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [qiwgyip] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [txqepre] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [eoxrcbf] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ohqkrqe] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [jdlbgjb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [nlnawta] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ptjwcbe] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [trqnrvp] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [tbcbpdi] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [bxclemj] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dxkvvmh] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [glikmuy] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sfmhwuu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [qekegpr] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [eoattfr] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ybbbdru] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pmcmuie] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ggkjujk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [bqecjyu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pdraxkk] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [rmlaomq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cmnsmim] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xquicmv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [asbrmib] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [neetrdk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [klqcpkq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [iutciqi] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [nkgagml] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ledlymt] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [lmgjpvi] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [cxvarab] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [byjfaps] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xidxbfd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sfnsjfs] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mtecixp] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [psnncxd] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [aalyvom] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [uttqjad] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [fybndfv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pjxgrss] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [caynpkm] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [rnaaois] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [btuoceb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [bniisil] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dolmodr] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ntuampg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xjsutqa] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [tnfdotc] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [chanqjk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sbedhpg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cwmocma] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wixhtoc] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cjcfldu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xcjtcjp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [iagcygi] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dvkeuco] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pfgjido] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pbpxhao] c:\windows\nlntunk.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab



Er kan wel iets van weg neem ik aan?? Help me! Alles loopt vast :( :( :(
(en krijg die yoursearcher maar niet weg)
(en ik krijg die irritante winmin medling niet weg bij et afsluiten..)

Je bent een held ;)
laatste aanpassing
Waarschuw beheerder
donateur
You must be kiddin' :jaja:
Waarschuw beheerder
Misschien is leeggooien niet helemaal de slechtste optie... *zucht*
Waarschuw beheerder
Er staat zo te zien idd een bult shit in je log, geen wonder dat de boel vastloopt. Start de computer ook langzaam op?
Iig wat heb je allemaal al geprobeerd (virusscanners, spyware scanners, in de veilige modus)?

Ben bang dat het goed mis is (dikke virusbesmetting of zelfs gehacked :S) en dat zoals je al zegt ws formatteren en opnieuw installeren de beste optie is.
laatste aanpassing
Waarschuw beheerder
is ffies kijken.. ;)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://yoursearcher.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://yoursearcher.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yoursearcher.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://yoursearcher.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://yoursearcher.com/index.htm
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [FDIFx3B] C:\WINDOWS\jpbwg.exe
O4 - HKLM\..\Run: [¢‰¸K0¨4W
}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\jpbwg.exe
O4 - HKCU\..\Run: [qlyqiwi] c:\windows\ropfaga.exe
O4 - HKCU\..\Run: [edpwxvf] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [bidtddt] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [gcnalcj] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [dhchbwu] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [bfxptgt] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [hpdsnrg] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [urvhgki] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [kpfkioa] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [ejwvwjx] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [soijjbt] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [tmtgnes] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [ogmwdkr] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [yffxfwx] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [clvmcum] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [orhlfjh] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [ssowgtc] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [synpukh] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [whabmsx] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [juynuhk] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [onolesi] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [tdlnebn] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [arnbgfe] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [bfwhmci] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [hvwclih] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [wdtdpdd] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [beomnme] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [wbcspsb] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [tjefbrt] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [xnexjnm] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [pxoxgmr] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [ajrtnlr] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [toivbqu] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [jdwppoo] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [eqmlqba] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [nxftehg] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [luuhrqy] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [yvuvffe] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [rrbbddn] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [wlqekhp] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [peqcaox] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [nltrjot] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [hlwpksd] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [hwrkaaa] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [nmqqgnc] c:\windows\dikqnwp.exe
O4 - HKCU\..\Run: [tinelei] c:\windows\fqxqogd.exe
O4 - HKCU\..\Run: [jfrascr] c:\windows\girrsrf.exe
O4 - HKCU\..\Run: [bgfncep] c:\windows\jaiuduu.exe
O4 - HKCU\..\Run: [pccugkh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [auaxnuw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dvfvjyj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wwpmvek] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [yqtkhsk] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [pliyimo] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [utvyeha] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nukyyjs] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gmdsxky] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [cpyyawd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [hnbksma] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [lxrsnjq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wicfgiv] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [uiemerj] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hdmoyrf] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [elkaouq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [rybwjou] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [snnjuvj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jkdahol] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [bohnaui] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xmcwfiw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [beolnge] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ivwildn] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dkptkvq] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [syhjdxt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [pwixxoh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xexrfjg] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [svhhnjh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [jwgilub] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wckuaaj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [gqgmuak] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ftlpjhw] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nuwvfql] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ahkyqpg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [xfmxqxt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [jnhobur] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [kmwwsav] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [vuaicis] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [pkqyhrw] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [glsbtbp] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ngpdxoa] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [edhddja] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [maxonsl] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [qkinwnr] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nqyuoli] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ckvoksp] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wfeebsa] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xbktujx] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [srsnmld] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [rifnxkc] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [igsqnkd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jocrasn] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xyldhpb] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [anjuahw] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qwymuch] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hnwdhtr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [uslmyis] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [yiiylka] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [lovmvtf] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hmtxuch] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [leowgpo] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bxhssee] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [yfljmlv] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [mglfose] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [jhyfcml] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ucxftki] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [lejuxkg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [smrdmfu] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [utelsyp] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [vukahfi] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [lvcxiqh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [eswvxqt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bonbyec] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [qvsjhfo] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [cvrcvtw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ckwcgtn] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ameakeh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [khgorik] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ifttrgw] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ibuedix] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [kkdlyqa] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [vgbqtjj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [urueuwm] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [niyebye] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [roqdtkh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [udeejxw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [cuohwbk] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [avhuxqb] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xcqqfgl] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [muqkqut] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ruhvluc] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dunnkby] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [sxcgfby] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [fbkgahr] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qosjbpb] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [nfxqitm] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [rgsuqet] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [uraikjv] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gaiwvew] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [bdhkqnt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [atfnjtj] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [nwanvlg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dmmxyip] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [fklmywf] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [wqtxxxg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gowrion] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [cakbbvb] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ibtxudy] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [xccjaao] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ifpjdcb] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ffbpkfs] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [meirobv] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [dmsewag] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qsjrjmx] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bmkhqmw] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bokakvu] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [oesrdom] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hlsweis] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [rgdgqst] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [sxpgwlb] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [oxquiaa] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [unnrkjt] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qgrfbvr] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [irbpbdl] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ysefyoe] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [xayvmhu] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [yoxbkaj] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [asvujdr] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [dmltnyi] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [elicsrh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hopupgj] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [hovymwc] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [iagucag] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ahnscme] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gjqdeyb] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [alnmfnd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [gihridq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [oycxqlk] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [wtkaadr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [xuavwgd] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [mtmgxjt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [eqcturn] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [unwadlr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dagrqhe] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [pumhfba] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [mnitjoy] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [vsqvwto] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gyxryvd] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [xlorhmg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [sfghqso] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [mntwoir] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [glwsfwr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [dohmeuc] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [vnrkkdd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [tkhwnxv] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [krpmlro] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [twnyluy] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [fcioutm] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jwkqvjd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ogrkfft] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nljdoep] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nduhrus] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [fdyohjs] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [nwqdwyh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ynsuiyi] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [yjyepqp] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [vhxgwox] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [bwrpgwf] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ncrkaak] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [qjtyjuh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [htumbmk] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [rhtavks] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [arlmrnh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [voilleh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [gpjjmng] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [athnpju] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [tokunua] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [geipxhr] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [cxhtttk] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [davirno] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [sllwnxd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ivebupd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jhymgpq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [jwteoqc] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [qauvekh] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [twonqar] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [tosxxfg] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ueqcuvh] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [ulyhfxi] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [jtyoggk] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [fjqqvxv] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [knpfcrf] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [uqhjlnq] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [vuxgjem] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [whwsglt] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [ehrfoul] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [lcvnoyd] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [slyhwls] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [gclbomm] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [pbrqfcn] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [wptxwkl] c:\windows\jtbwdij.exe
O4 - HKCU\..\Run: [kfmwagx] c:\windows\yucstij.exe
O4 - HKCU\..\Run: [biuycid] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [kbvhiud] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [mogefqe] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [twkpbqr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [mwqccwo] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ybxsdte] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [picmhsg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ssorjqo] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vgeltrc] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lgwdoxv] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tkobqbe] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rvnlsjn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [adcdbkk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rwggoww] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [fvrfcid] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bsivmah] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [erxefmt] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rkamyrx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [otfqqof] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [moatgdp] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [mdovddl] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [iiwjqog] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [fnbjkdy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [iknktno] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [peamtrn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [eprmqjw] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [njupuag] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [tvgiphk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lkxagma] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ruqybvq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lgytptg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nuhbfeu] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [fyohkfy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [qsnhwni] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [cwvlcbj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vocuvjo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [nbfsjmg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nosjgsr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vukrgkd] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hiyyuxo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [lnryupi] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [gtsllgv] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [umonkrs] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [vqbysrm] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [nxtivsx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xbowitn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [twchdjf] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [uretrys] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ysnbkfm] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ksjsmrt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [dvyiuyn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jvmpyad] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qnuvplp] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [yasaflr] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bhojgsa] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [erejgyw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [udmsfwa] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nqhaadm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vgnaooa] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [liojrcs] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uagruva] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [xqtiolm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [mmwnqdb] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ifsxytc] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tqkboos] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [owglekq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [itxhggj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lnmtxbq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pcmrtot] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pixmsme] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [kgyqiwg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ewsjegy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [onenfxi] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rdcksma] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jpsylwj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rsuhkvm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [dygfcya] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [fttmcsk] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wkxriko] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wwhxqus] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bjstcrf] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hwxavir] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lkdcywh] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nfcygnf] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ppnxrfx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uvhlbub] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ytlpttt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [nkvvmtg] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qvgqprq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [owafblq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jxscfcq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [yyfcbkw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uwfxfxo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [dqafsep] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [iowjbsb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xhcpexq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [igrfmdn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [unexjix] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xeknrom] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pqcpdut] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [dqfxbpa] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [oqmamqn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hlmwrfl] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hociovw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wdjikbv] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [lmbvrkj] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ophumcy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [hwdbphh] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xjiukjy] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [brensux] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [engfbmq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ttrnhmk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [djlnqvr] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [vmprdud] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uuxjfgm] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [rthycnk] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qevpobx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [srihcuc] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [tfxiage] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [aigvvdk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [xaarqkf] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [hfmtpyq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [sxefofr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [xdtdjxl] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ufijloc] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pptxlwx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ylxbgbt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ejjkhnp] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [iffcshd] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [inqisdc] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [cppxswa] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [tkhxysr] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [evviwoh] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [egjgqdl] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [kgijwbb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [elrwtrr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [kigljlw] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ovnrfsh] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ioukhnb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hulubdy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [voigepi] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [saocyja] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [motecud] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [flcbkif] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wxakubo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [trlmyxg] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [jwooayj] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hdtbcax] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [yjmcikc] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tuuskrp] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [scypclm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rmfcqwa] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uqnqrqc] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nexatiy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tpidgju] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [scgwwxg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [urfjrof] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [gcbbwbo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [vvgpwlv] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qadejvq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [momconm] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [aujmkuy] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jrhubwl] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [wsalesy] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pvwphai] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [vhxsdsi] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tirkdei] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [irofjnk] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [iieqvsb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ixgwwpc] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bpcwpnq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [yyxravs] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [oxwcrwb] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pnfaubd] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ahjvlix] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [aklqtsi] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hikryyr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jpgqixw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bjqekaj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jjkryeq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [emjnyvx] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xmamald] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ytadpny] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [sdoerge] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [iddlecr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vpsxkww] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ymtcuic] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qetabsy] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [fbiubrg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [fygoocv] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [akxvgdn] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rjahtbq] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [pwpadiw] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [iciqrqr] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [mowgboo] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [tbtynok] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hlgqmpf] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [eiyivkp] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [olxvrtu] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bqxshul] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bccddjo] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jdostyr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [jhraopn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [cbwoflb] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [krdngvb] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [haabgpt] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [btdppue] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [qluwyqs] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vbursut] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [nsojuko] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [uyfdxpa] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bfwfxas] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [xuqyafq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [hmcyalr] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [gvjdwbs] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [psquibj] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [qxmqnwh] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [tpfpayt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [jveknsg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [pbguist] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [ldnpjej] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [coobped] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [dvhqryn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [bcstjwd] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [qatsjmm] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [gggoagt] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [leggdcw] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [gnfnwml] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [mrcgpjn] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [otttwjg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [wllwodw] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [qnfvfnj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [pcrpecp] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [mxljcab] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [umobwhl] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [dwtbjrf] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [iokfycg] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [vjhleoq] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [kewwwol] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [pjrxbjk] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [ucysepy] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [fdpbrce] c:\windows\atelcge.exe
O4 - HKCU\..\Run: [wctiaqj] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [sltcyqi] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [rehqvja] c:\windows\nvvakln.exe
O4 - HKCU\..\Run: [caebarx] c:\windows\muwvgdh.exe
O4 - HKCU\..\Run: [lrlliab] c:\windows\fdbutes.exe
O4 - HKCU\..\Run: [oajkhnq] c:\windows\kacbsju.exe
O4 - HKCU\..\Run: [ifuugil] c:\windows\fdbutes.exe
O4 - HKCU\..\Run: [edyqrjh] c:\windows\kacbsju.exe
O4 - HKCU\..\Run: [rtbeheq] c:\windows\fdbutes.exe
O4 - HKCU\..\Run: [rgciavg] c:\windows\grfrfmr.exe
O4 - HKCU\..\Run: [qnlmend] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [nvflgnn] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [rfalasv] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cbcadiv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [drfcqme] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cnrldmq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [olpxpqg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [tyqbyot] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [diiadvt] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [iejhnny] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ioyysof] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [taclrbg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ylvdenf] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sdgtpgu] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wnouldl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [bgtnnws] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xutcucy] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [hjhpisl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ttttqyc] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [iwccrqm] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ewsxgrd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [yyjyyqq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [fosrrhf] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [crlndwh] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xdvinlb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [jelhklq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [oieohtr] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pnfcggx] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [yrlkjsp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ublijsd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xknotxg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [mvxorlu] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ohxfnnr] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [icacyiv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mlhobtw] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xdwnymy] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [njdodmh] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ffnrvoh] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [hsshdtp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [jisfrhq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [amqygvv] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [aopgfsk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [qkovbdy] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [kanmgel] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [nenlfij] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [vkgpwts] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xdavmaq] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [hfgyogv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [tjbrkrg] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [qpdjadr] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [vwfbavq] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [runmebw] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [sxwwunp] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pwbaqdl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [uvcmgbd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [chhgihc] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [qoyagrd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [etkywje] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ftyipej] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [docklfh] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xtpiqir] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [soqblwg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [pbfudxn] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [mmidjya] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [eqlqstx] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [bqbuvuk] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [vsutvhs] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wdagxvn] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [fpwautp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [nsngymm] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [erpagrp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [gxdekjx] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ribqnog] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [icyjsnm] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ygintwi] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [prtkqqi] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [fyovibk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ptiocmw] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xfgojvr] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ubmlwbc] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dcjttfb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [lwayjfg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [tyvjgbq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [nelhuwj] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [pcwswgs] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wxothom] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sqhvnrs] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [lmfiuby] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [vpspdpj] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [icsqpll] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [vrgvcxo] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [hgeokne] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [qtvobtt] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [bstgaqx] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [osvimhn] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dkmvwvy] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [bsnybwi] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xeievhp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [dnrynii] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [umqwvcx] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [rtfdprk] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [hbgttow] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [gkwrehd] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [gcanbmf] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [eqpgulo] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mvkehki] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [gtfldwn] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [klmulba] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [cjkguav] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [pbhcnsx] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [vjqbklm] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [kembeqs] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [slbweuf] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [llkspgl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xudyrjv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [vkbfpvv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xcwlwwh] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mtivple] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [iqmjwgc] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ablhewj] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wefggbg] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [txwgncg] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ovdfxuu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [vfewrlo] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mhokolx] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mjyyfmb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [glrujnw] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [qvqwhqn] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dtdwspj] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [rjwxqte] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [eqxyqly] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [uqnxehk] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [grrbjev] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [fxklxjs] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [mjjbceu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [hfduvwl] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ifxlbcp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [dresilf] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [kimokgu] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [kkjunfy] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [qiwgyip] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [txqepre] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [eoxrcbf] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ohqkrqe] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [jdlbgjb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [nlnawta] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ptjwcbe] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [trqnrvp] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [tbcbpdi] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [bxclemj] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dxkvvmh] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [glikmuy] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sfmhwuu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [qekegpr] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [eoattfr] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ybbbdru] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pmcmuie] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ggkjujk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [bqecjyu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pdraxkk] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [rmlaomq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cmnsmim] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xquicmv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [asbrmib] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [neetrdk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [klqcpkq] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [iutciqi] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [nkgagml] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [ledlymt] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [lmgjpvi] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [cxvarab] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [byjfaps] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xidxbfd] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sfnsjfs] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [mtecixp] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [psnncxd] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [aalyvom] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [uttqjad] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [fybndfv] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pjxgrss] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [caynpkm] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [rnaaois] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [btuoceb] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [bniisil] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dolmodr] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [ntuampg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [xjsutqa] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [tnfdotc] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [chanqjk] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [sbedhpg] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cwmocma] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [wixhtoc] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [cjcfldu] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [xcjtcjp] c:\windows\faqfinj.exe
O4 - HKCU\..\Run: [iagcygi] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [dvkeuco] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pfgjido] c:\windows\shdiswv.exe
O4 - HKCU\..\Run: [pbpxhao] c:\windows\nlntunk.exe
soooooow.. en hle lijst.. :yes:

nou al die 04 dingen moet je in veilige modus verwijderen.. behalve de Quicktime player.. :/
(veilige modus opstarten gaat als je de pc net aanzet op del of F8 drukken dan krijg je een keuze menu en dan kies je veilige modus zonder intrenet.. :yes: )

als je dr tijd voor hebt anders jah.. dan een schone windows installatie.. :9
Waarschuw beheerder
Tijd moet er maar gemaakt worden! ;) Als ik bij mn werk vandaan ben race ik naar huus om eraan te beginnen. I let ya know.

Thanx iig!

-meteosas , ik laat regelmatig een scannertje lopen, maar never in veilige modus, misschien toch es doen..
Waarschuw beheerder
donateur
Je wil toch niet zeggen dat die log niet gefaked is? 8)
Waarschuw beheerder
Die log was absoluut niet gefaked ERiQ! ;) :(

Dankzij Danie & Odie is hier mn nieuwe log :

Logfile of HijackThis v1.98.2
Scan saved at 18:46:48, on 17-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\HHVcdV5Sys\VC5SecS.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\WINDOWS\anvshell.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\DitExp.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\devil\Bureaublad\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINDOWS\webdir.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [Anvshell] anvshell.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab



Enige probleem wat er nu nog loopt is dat de vensters van internet met grote vertraging opkomen (bij openen nieuw venster). Enige idee wat dat zou kunnen zijn?

Thanx!!!!
Waarschuw beheerder
donateur
Download en run CWShredder eens?

Ik vind je process: C:\Program Files\HHVcdV5Sys\VC5SecS.exe ook nogal verdacht, maar ik zie niet waar die gestart wordt.. Misschien weet odie 't :)
Waarschuw beheerder
WTF! heheh, er zat inderdaad nog een coolwebsearch .dll file verstopt, weggehaald en internet doet et weer prima ;)

Thanx ERiQ
Waarschuw beheerder
donateur
You're welcome :jaja:
Waarschuw beheerder
Plaats nu nog eens je log en nu eens versie 1.99
Waarschuw beheerder
voilá

Logfile of HijackThis v1.99.0
Scan saved at 23:52:14, on 17-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\HHVcdV5Sys\VC5SecS.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\WINDOWS\anvshell.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\DitExp.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\FTDv3\FTDv3.exe
C:\Program Files\WinMX\WinMX.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\devil\Bureaublad\yProxy.exe
C:\WINDOWS\explorer.exe
c:\program files\quintessential player\qcdplayer.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\nbpro\nbpro.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\devil\Bureaublad\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [Anvshell] anvshell.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: ASUS Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Virtual CD v5 Security service - H+H Software GmbH - C:\Program Files\HHVcdV5Sys\VC5SecS.exe
Waarschuw beheerder
Mijn logfile is veel kleiner dit komt omdat je nog veel services hebt opstaan. Die niet open hoeven te staan ik zou je adviseren met msconfig alleen het noodzakelijke te laten opstarten.

Logfile of HijackThis v1.99.0
Scan saved at 0:06:04, on 18-1-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Opera 8 Beta\Opera.exe
C:\WINDOWS\Explorer.EXE
D:\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:14000
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Gelijkwaardige pagina's - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Koppelingspagina's - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: NOD32 Kernel Service - Unknown - C:\Program Files\Eset\nod32krn.exe
O23 - Service: RadClock - Unknown - C:\WINDOWS\system32\RadClock.exe
O23 - Service: Sygate Personal Firewall Pro - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
laatste aanpassing
Waarschuw beheerder
Bij tabje opstarten disablen neem ik aan waar je op doelt?
Waarschuw beheerder
start>uitvoeren>msconfig>opstarten

start>uitvoeren>services.msc
start>uitvoeren>gpedit.msc
 
Waarschuw beheerder
Logfile of HijackThis v1.99.0
Scan saved at 13:51:57, on 18-1-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
D:\My Proggies\D-Tools\daemon.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Secway\SimpLite-MSN 2.1\SimpLite-MSN.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\AnalogX\Proxy\proxy.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\boundll.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\maurice\LOCALS~1\Temp\Rar$EX00.250\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.partyflock.nl/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [SpyBlocker] C:\Program Files\Modem Spy\maurice\spyblocker.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\My Proggies\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [ICQ Lite] D:\My Proggies\ICQ2002a\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [WinVNC] "D:\My Proggies\RealVNC\WinVNC\winvnc.exe" -servicehelper
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [Simp] C:\Program Files\Secway\SimpLite-MSN 2.1\SimpLite-MSN.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\RunOnce: [ICQ Lite] D:\My Proggies\ICQ2002a\ICQLite\ICQLite.exe -trayboot
O4 - Startup: boundll.bat.lnk = C:\WINDOWS\boundll.bat
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - D:\MYPROG~1\ICQ2002a\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\MYPROG~1\ICQ2002a\ICQ\ICQ.exe
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ 4.0 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\My Proggies\ICQ2002a\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\My Proggies\ICQ2002a\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://ppupdates.ca.com/downloads/scanner/axscanner.cab
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://studio.airpeace.nl/activex/AMC.cab
O18 - Protocol hijack: mhtml -
O23 - Service: Adobe LM Service - Unknown - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) - Unknown - %ProgramFiles%\WinPcap\rpcapd.exe (file missing)
O23 - Service: Sygate Personal Firewall - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: VNC Server - RealVNC Ltd. - D:\My Proggies\RealVNC\WinVNC\winvnc.exe


wat kan er hier weg?
laatste aanpassing
Waarschuw beheerder
devil1973:
vrij van troep..

danie:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

ELEGAL:
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = about:blank
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)
O4 - HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O18 - Protocol hijack: mhtml -
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) - Unknown - %ProgramFiles%WinPcaprpcapd.exe (file missing)
 
Waarschuw beheerder
thanx man (y)
 
Waarschuw beheerder
Logfile of HijackThis v1.99.0
Scan saved at 23:46:08, on 18-1-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
D:\My Proggies\RealVNC\WinVNC\winvnc.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\System32\svchost.exe
D:\My Proggies\D-Tools\daemon.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Secway\SimpLite-MSN 2.1\SimpLite-MSN.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\boundll.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\maurice\LOCALS~1\Temp\Rar$EX00.344\HijackThis.exe
C:\PROGRA~1\mcafee.com\agent\mcupdate.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.partyflock.nl/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [SpyBlocker] C:\Program Files\Modem Spy\maurice\spyblocker.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\My Proggies\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [ICQ Lite] D:\My Proggies\ICQ2002a\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [WinVNC] "D:\My Proggies\RealVNC\WinVNC\winvnc.exe" -servicehelper
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [Simp] C:\Program Files\Secway\SimpLite-MSN 2.1\SimpLite-MSN.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\RunOnce: [ICQ Lite] D:\My Proggies\ICQ2002a\ICQLite\ICQLite.exe -trayboot
O4 - Startup: boundll.bat.lnk = C:\WINDOWS\boundll.bat
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - D:\MYPROG~1\ICQ2002a\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\MYPROG~1\ICQ2002a\ICQ\ICQ.exe
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ 4.0 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\My Proggies\ICQ2002a\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\My Proggies\ICQ2002a\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://ppupdates.ca.com/downloads/scanner/axscanner.cab
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://studio.airpeace.nl/activex/AMC.cab
O23 - Service: Adobe LM Service - Unknown - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: VNC Server - RealVNC Ltd. - D:\My Proggies\RealVNC\WinVNC\winvnc.exe


dus hij is helemaal clean nu? :D
Trouwens.. die hitman pro executable doet het nie :(
laatste aanpassing
 
Waarschuw beheerder
Logfile of HijackThis v1.99.0
Scan saved at 22:20:45, on 19-1-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Teunes van de Beek\Bureaublad\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.paradigit.nl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.paradigit.nl
O18 - Protocol: bw+0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Macromedia Licensing Service - Unknown - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SoundMAX Agent Service - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 
Waarschuw beheerder
:-| bedoel je odie?
Waarschuw beheerder
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.paradigit.nl
O18 - Protocol: bw+0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {5A8DC54B-78B8-44A2-B0FA-DB962FF1E26C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll


weg ermee

[img cacheid=0013307000115d40d68a165d1a008a1fcd]http://members.chello.nl/~h.brom1/Msn%20Plus.JPG[/img]
Waarschuw beheerder
donateur
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray


Die hoeven niet weg hoor, is absoluut niks gevaarlijks. De eerste 3 lines zijn voor je nvidia kaartje, de andere 2 voor je geluidskaart.
Waarschuw beheerder
Maakt je pc wel sneller.
Waarschuw beheerder
donateur
Dat is zo, maar dit topic gaat vooral over de "schadelijke programmatuur" :)
Waarschuw beheerder
helemaal waar.. ;)

maar soms wordt het misbruikt en dan staat er nrwiz bijv.. ziet je niet zo snel.. maar dat is dan een spyware..
Waarschuw beheerder
Logfile of HijackThis v1.99.0
Scan saved at 0:01:56, on 20-1-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure\Common\FSMA32.EXE
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure\Common\FSMB32.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\F-Secure\Common\FCH32.EXE
C:\Program Files\F-Secure\Common\FAMEH32.EXE
C:\Program Files\F-Secure\Common\FSM32.EXE
C:\Program Files\F-Secure\Common\FNRB32.EXE
C:\WINDOWS\system32\gsicon.exe
C:\WINDOWS\system32\dslagent.exe
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
C:\Program Files\F-Secure\Common\FIH32.EXE
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\devldr32.exe
C:\Download\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1601.0\nl\msntb.dll
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1101038886737
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC517FE7-9448-4047-9BE2-6AA5D2898EA3}: NameServer = 194.134.5.5 194.134.0.97
O17 - HKLM\System\CCS\Services\Tcpip\..\{C26A519E-FDA5-41D1-9256-6E853D328B5C}: NameServer = 192.168.100.1
O23 - Service: F-Secure Automatic Update - Unknown - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: F-Secure Gatekeeper Handler Starter - Unknown - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
O23 - Service: fsbwsys - Unknown - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


Schoon logje he of niet
laatste aanpassing
Waarschuw beheerder
:no:

O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm

TYF DAP WEG!! gebruik FlashGet.. ;)

DAP zit vol met spyware.. :yes:
 
Waarschuw beheerder
ik heb het in me registery, wat betekend dat het elke keer terugkomt als ik me comp opnieuw opstart. haalt hitman dat ook weg?