Ga naar inhoud

exdude

Lid
  • Items

    12
  • Registratiedatum

  • Laatst bezocht

Berichten die geplaatst zijn door exdude

  1. Ik kan niets meer wijzigen aan de accountinstelling van Outlook 2007.

    Ik kan de accountinstellingen zelfs niet meer openen.

    Bij het openen krijg ik onderstaande foutmelding

    "Fout in de bewerking omdat er een probleem is met het register of installatie. Start Outlook opnieuw en probeer het nogmaals. Als het probleem zich blijft voordoen, installeert u Outlook opnieuw."

    Herinstallatie heeft niet geholpen.

    Ik heb al geprobeerd om een nieuw profiel aan te maken in Vista.

    Start - configuratiescherm - gebruikersaccounts - e-mail - profielen weergeven - toevoegen.

    Maar ik krijg dan opnieuw een foutmelding.

    "Er is een fout opgetreden bij het openen van het systeemregister"

    Iemand een idee wat het probleem kan zijn?

    Alvast bedankt.

    PC = Windows vista home premium sp 2 32bit; Intel Core2Duo T5750 2,00GHZ; 4 GB Ram

  2. Ik heb net een ultieme poging gedaan en het blijkt te werken!

    1. Kopieer de map met al uw e-mails

    C:\Users\jepcnaam\AppData\Roaming\Thunderbird\Profiles\jeprofielnaam\Mail\Local Folders

    2. Verwijder Thunderbird van je pc

    3. Verwijder de hele Thunderbird map

    C:\Users\jepcnaam\AppData\Roaming\Thunderbird\

    4. Installeer Thunderbird opnieuw

    5. Start Thunderbird op en vul je accountgegevens in.

    6. Sluit Thunderbird af en ga opnieuw naar

    C:\Users\jepcnaam\AppData\Roaming\Thunderbird\Profiles\jeprofielnaam\Mail\Local Folders

    7. Vervang deze nieuwe map door het kopie van je oude

    8. Probleem opgelost.

  3. Bedankt voor je antwoord.

    Ik heb eens alles uitgeschakeld en opnieuw opgestart. De tijdswinst was te verwaarlozen.

    Maar ik ben al tevreden dat mijn pc weer op volle snelheid werkt.

    bedankt voor je hulp!

    edit: ik heb eens die "HP digital imaging monitor" verwijderd en plots is het probleem van de baan :stupid:

    PC start beduidend sneller op :-)

  4. Al een heel stuk beter.

    Maar het is wel nog steeds niet perfect.

    De PC start op en dan kom ik op mijn bureaublad terecht.

    Dan zie ik het venster van mij antivirus (nod32 - opstartscherm).

    Dit gaat allemaal zoals het hoort en redelijk snel.

    Op het moment dat mijn antivirus zichzelf minimaliseert zou ik in staat moeten zijn om mijn pc normaal te gebruiken ?

    Wel dit is niet zo. De eerste 30s loopt mijn pc slomer dan normaal.

    Als ik bv. Firefox open heb ik het gevoel dat mijn pc elk moment zou kunnen vastlopen.

    De tijd dat hij slomer loopt lijkt rechtstreeks verbonden aan: (iets raars :-))

    Direct bij het opstarten verschijnen rechts onder 3 icoontjes: 'antivirus', 'be-id(software van mijn paspoortlezer)' en 'volume'.

    Na 30s verschijnen plots ook het icoontjes van mijn 'lan-verbinding' en 'HP digital imaging monitor'.

    En vanaf dan lijkt mijn pc aan volle kracht te werken.

    Moet ik gewoon geduld hebben of is er toch iets mis ?

    Blijkbaar loopt ook nog ergens Ashampoo antivirus. Hoe krijg ik die weg ?

    AV: Ashampoo AntiVirus *On-access scanning enabled* (Updated) {87430BA8-187A-42D6-A8FE-8E00DF291089}
  5. Hier volgt de log.

    Die Ashampoo AntiVirus is iets raar. Ik heb die helemaal niet meer (al meer dan een jaar) op mijn pc geïnstalleerd staan.

    ComboFix 09-08-10.06 - Eigenaar 13/08/2009 22:38.2.2 - NTFSx86

    Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.2047.1446 [GMT 2:00]

    Gestart vanuit: c:\documents and settings\Eigenaar\Bureaublad\pc test\ComboFix.exe

    AV: Ashampoo AntiVirus *On-access scanning enabled* (Updated) {87430BA8-187A-42D6-A8FE-8E00DF291089}

    AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

    .

    /wow section - STAGE 41

    (((((((((((((((((((( Bestanden Gemaakt van 2009-07-13 to 2009-08-13 ))))))))))))))))))))))))))))))

    .

    2009-08-13 17:41 . 2009-08-13 17:41 -------- d-----w- c:\documents and settings\Eigenaar\Application Data\Malwarebytes

    2009-08-13 17:41 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

    2009-08-13 17:41 . 2009-08-13 17:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

    2009-08-13 17:41 . 2009-08-13 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

    2009-08-13 17:41 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys

    2009-08-12 16:08 . 2001-08-17 19:51 14848 -c--a-w- c:\windows\system32\dllcache\asc3550.sys

    2009-08-12 16:07 . 2001-08-17 20:07 101888 -c--a-w- c:\windows\system32\dllcache\adpu160m.sys

    2009-08-12 15:49 . 2009-08-12 15:49 -------- d-----w- c:\program files\Trend Micro

    2009-08-12 15:48 . 2009-07-10 13:31 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll

    2009-08-08 22:13 . 2009-08-08 22:13 -------- d-----w- c:\program files\DirectVobSub

    2009-08-05 09:01 . 2009-08-05 09:01 205312 -c----w- c:\windows\system32\dllcache\mswebdvd.dll

    2009-08-04 20:11 . 2009-08-04 20:11 -------- d-----w- c:\program files\Medieval Software

    2009-07-28 18:52 . 2009-08-01 15:54 -------- d-----w- c:\documents and settings\Eigenaar\Application Data\vlc

    2009-07-27 23:54 . 2009-07-27 23:54 -------- d-----w- c:\program files\TVAnts

    2009-07-27 23:36 . 2009-07-27 23:46 -------- d-----w- c:\program files\SopCast

    2009-07-27 23:26 . 2009-07-27 23:26 -------- d-----w- c:\documents and settings\Eigenaar\Application Data\StreamTorrent

    2009-07-27 23:26 . 2009-07-27 23:26 -------- d-----w- c:\documents and settings\All Users\Application Data\PPLiveVA

    2009-07-27 23:17 . 2009-07-27 23:17 -------- d-----w- c:\documents and settings\Eigenaar\Local Settings\Application Data\TVU Networks

    2009-07-27 23:17 . 2009-07-27 23:17 -------- d-----w- c:\documents and settings\All Users\Application Data\TVU Networks

    2009-07-27 23:17 . 2009-07-27 23:17 -------- d-----w- c:\documents and settings\Eigenaar\LocalLow

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2009-08-13 17:49 . 2007-06-22 23:48 -------- d-----w- c:\program files\Gabest

    2009-08-12 15:53 . 2007-06-22 22:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

    2009-08-05 09:01 . 2004-08-03 23:03 205312 ----a-w- c:\windows\system32\mswebdvd.dll

    2009-08-02 10:25 . 2007-07-25 16:05 -------- d-----w- c:\documents and settings\Eigenaar\Application Data\CoreFTP

    2009-08-02 10:17 . 2008-10-30 19:34 -------- d-----w- c:\documents and settings\Eigenaar\Application Data\LimeWire

    2009-07-31 14:13 . 2008-06-27 12:56 -------- d-----w- c:\program files\Microsoft Silverlight

    2009-07-23 22:30 . 2008-01-01 19:01 -------- d-----w- c:\program files\Steam

    2009-07-17 19:04 . 2004-08-03 23:03 58880 ----a-w- c:\windows\system32\atl.dll

    2009-07-13 21:43 . 2004-08-03 23:03 286208 ----a-w- c:\windows\system32\wmpdxm.dll

    2009-07-08 16:49 . 2008-02-17 11:28 -------- d-----w- c:\program files\Common Files\Adobe

    2009-07-06 22:48 . 2007-06-29 15:44 -------- d-----w- c:\program files\mIRC

    2009-07-03 17:00 . 2004-08-03 23:03 915456 ----a-w- c:\windows\system32\wininet.dll

    2009-06-25 08:27 . 2004-08-03 23:03 54272 ----a-w- c:\windows\system32\wdigest.dll

    2009-06-25 08:27 . 2004-08-03 23:03 56832 ----a-w- c:\windows\system32\secur32.dll

    2009-06-25 08:27 . 2004-08-03 23:03 147456 ----a-w- c:\windows\system32\schannel.dll

    2009-06-25 08:27 . 2004-08-03 23:03 136192 ----a-w- c:\windows\system32\msv1_0.dll

    2009-06-25 08:27 . 2004-08-03 23:03 735232 ----a-w- c:\windows\system32\lsasrv.dll

    2009-06-25 08:27 . 2004-08-03 23:03 301568 ----a-w- c:\windows\system32\kerberos.dll

    2009-06-24 11:18 . 2004-08-03 20:59 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys

    2009-06-16 14:40 . 2004-08-03 23:03 119808 ----a-w- c:\windows\system32\t2embed.dll

    2009-06-16 14:40 . 2001-09-07 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll

    2009-06-15 10:45 . 2004-08-03 23:03 82432 ----a-w- c:\windows\system32\tlntsess.exe

    2009-06-15 10:45 . 2004-08-03 23:03 79872 ----a-w- c:\windows\system32\telnet.exe

    2009-06-10 14:16 . 2004-08-03 23:03 85504 ----a-w- c:\windows\system32\avifil32.dll

    2009-06-10 09:45 . 2007-06-22 23:53 68768 ----a-w- c:\documents and settings\Eigenaar\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

    2009-06-10 07:22 . 2007-06-22 22:24 2066432 ----a-w- c:\windows\system32\mstscax.dll

    2009-06-10 06:16 . 2004-08-03 23:03 132096 ----a-w- c:\windows\system32\wkssvc.dll

    2009-06-03 19:11 . 2004-08-03 23:03 1295360 ----a-w- c:\windows\system32\quartz.dll

    2009-05-19 12:17 . 2009-05-19 12:09 168466 ----a-w- c:\windows\hpoins28.dat

    2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll

    2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "SW20"="c:\windows\system32\sw20.exe" [2006-09-07 208896]

    "SW24"="c:\windows\system32\sw24.exe" [2006-09-07 69632]

    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]

    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]

    "beid"="c:\program files\Belgium Identity Card\beid35gui.exe" [2009-02-02 2035712]

    "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-04-09 2029640]

    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]

    "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]

    "USB Storage Toolbox"="c:\program files\USB Disk Win98 Driver\Res.EXE" [2005-09-14 65536]

    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-10 385024]

    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

    "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-09-17 1657376]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\

    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^ScanPanel.lnk]

    backup=c:\windows\pss\ScanPanel.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Eigenaar^Menu Start^Programma's^Opstarten^OneNote 2007 Schermopname en Snel starten.lnk]

    backup=c:\windows\pss\OneNote 2007 Schermopname en Snel starten.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]

    "AntiVirusOverride"=dword:00000001

    "FirewallOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

    "%windir%\\system32\\sessmgr.exe"=

    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=

    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    "c:\\Program Files\\mIRC\\mirc.exe"=

    "c:\\Program Files\\LimeWire\\LimeWire.exe"=

    "c:\\Program Files\\Steam\\steamapps\\mrsanta007@hotmail.com\\counter-strike\\hl.exe"=

    "c:\\Program Files\\Steam\\steamapps\\mrsanta007@hotmail.com\\half-life\\hl.exe"=

    "c:\\Program Files\\Steam\\steamapps\\mrsanta007@hotmail.com\\half-life 2 deathmatch\\hl2.exe"=

    "g:\\Game\\PES 2009\\pes2009.exe"=

    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=

    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=

    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=

    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

    "c:\\Program Files\\TVAnts\\Tvants.exe"=

    R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [9/04/2009 15:18 107256]

    R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [9/04/2009 15:21 94360]

    R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [9/04/2009 15:19 731840]

    R3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\drivers\a38usb.sys [12/03/2009 18:48 33536]

    S3 HwIOctl;HwIOctl;\??\c:\program files\Setup Files\MS-7235 v3.50\HwIOctl.sys --> c:\program files\Setup Files\MS-7235 v3.50\HwIOctl.sys [?]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]

    "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

    .

    Inhoud van de 'Gedeelde Taken' map

    2009-08-08 c:\windows\Tasks\OGADaily.job

    - c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]

    2009-08-13 c:\windows\Tasks\OGALogon.job

    - c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]

    .

    .

    ------- Bijkomende Scan -------

    .

    uStart Page = hxxp://google.be/

    IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

    Trusted Zone: com.tw\www.msi

    Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll

    DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab

    FF - ProfilePath - c:\documents and settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\m81rdlto.default\

    FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/ig?hl=nl

    FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll

    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll

    FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll

    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);

    c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);

    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");

    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);

    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

    Rootkit scan 2009-08-13 22:42

    Windows 5.1.2600 Service Pack 3 NTFS

    scannen van verborgen processen ...

    scannen van verborgen autostart items ...

    scannen van verborgen bestanden ...

    c:\documents and settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\m81rdlto.default\places.sqlite-journal 0 bytes

    Scan succesvol afgerond

    verborgen bestanden: 1

    **************************************************************************

    .

    --------------------- DLLs Geladen Onder Lopende Processen ---------------------

    - - - - - - - > 'explorer.exe'(2976)

    c:\windows\system32\webcheck.dll

    c:\windows\system32\WPDShServiceObj.dll

    c:\windows\system32\PortableDeviceTypes.dll

    c:\windows\system32\PortableDeviceApi.dll

    c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll

    c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.NLD

    c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    c:\program files\Microsoft Office\Office12\1043\GrooveIntlResource.dll

    .

    Voltooingstijd: 2009-08-13 22:43

    ComboFix-quarantined-files.txt 2009-08-13 20:43

    ComboFix2.txt 2009-08-12 22:17

    Pre-Run: 25.773.625.344 bytes beschikbaar

    Post-Run: 25.809.530.880 bytes beschikbaar

    223 --- E O F --- 2009-07-31 07:24

  6. Al bedankt voor je hulp.

    Na je instructies kreeg ik volgende logs:

    Malwarebytes' Anti-Malware 1.40

    Database versie: 2615

    Windows 5.1.2600 Service Pack 3

    13/08/2009 19:46:39

    mbam-log-2009-08-13 (19-46-39).txt

    Scan type: Snelle Scan

    Objecten gescand: 93393

    Verstreken tijd: 4 minute(s), 3 second(s)

    Geheugenprocessen geïnfecteerd: 0

    Geheugenmodulen geïnfecteerd: 0

    Registersleutels geïnfecteerd: 1

    Registerwaarden geïnfecteerd: 0

    Registerdata bestanden geïnfecteerd: 0

    Mappen geïnfecteerd: 2

    Bestanden geïnfecteerd: 0

    Geheugenprocessen geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Geheugenmodulen geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Registersleutels geïnfecteerd:

    HKEY_LOCAL_MACHINE\SOFTWARE\Purchased Products (Rogue.Multiple) -> Quarantined and deleted successfully.

    Registerwaarden geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Registerdata bestanden geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Mappen geïnfecteerd:

    C:\Documents and Settings\All Users\Application Data\SalesMon (Rogue.Multiple) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SalesMon\Data (Rogue.Multiple) -> Quarantined and deleted successfully.

    Bestanden geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 19:48:14, on 13/08/2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\RUNDLL32.EXE

    C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    C:\Program Files\Belgium Identity Card\beid35gui.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    C:\Program Files\USB Disk Win98 Driver\Res.EXE

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O4 - HKLM\..\Run: [sW20] C:\WINDOWS\system32\sw20.exe

    O4 - HKLM\..\Run: [sW24] C:\WINDOWS\system32\sw24.exe

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [beid] "C:\Program Files\Belgium Identity Card\beid35gui.exe" /startup

    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe

    O4 - HKLM\..\Run: [uSB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: HP Slim selecteren - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O15 - Trusted Zone: http://www.msi.com.tw

    O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.new2.foto.com/ImageUploader5.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1182559828906

    O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --

    End of file - 6722 bytes

  7. Mijn PC doet de laatste tijd erg raar tijdens het opstarten.

    Ik krijg geen foutmeldingen, maar het duurt erg lang.

    Na het opstarten lijkt hij gewoon normaal te werken ...

    Wil iemand mijn log eens nakijken ?

    Alles wat niet vitaal is voor de werking van mijn pc, mag er uit :-)

    dank bij voorbaat

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 17:49:27, on 12/08/2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\RUNDLL32.EXE

    C:\Program Files\Belgium Identity Card\beid35gui.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    C:\Program Files\USB Disk Win98 Driver\Res.EXE

    C:\WINDOWS\system32\ctfmon.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe

    C:\Program Files\Windows Live\Messenger\usnsvc.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\WINDOWS\SoftwareDistribution\Download\470f70ff15111cee4dd521c300e4736a\update\update.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O4 - HKLM\..\Run: [sW20] C:\WINDOWS\system32\sw20.exe

    O4 - HKLM\..\Run: [sW24] C:\WINDOWS\system32\sw24.exe

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [beid] "C:\Program Files\Belgium Identity Card\beid35gui.exe" /startup

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe

    O4 - HKLM\..\Run: [uSB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')

    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: HP Slim selecteren - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O15 - Trusted Zone: http://www.msi.com.tw

    O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.new2.foto.com/ImageUploader5.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1182559828906

    O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --

    End of file - 7044 bytes

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.