Ga naar inhoud

[OPGELOST] opstart windows xp home te lang


Gast peterje

Aanbevolen berichten

is het mogelijk om aan te geven waar ik die overbodige programma,s kan vinden , en wat de namen zijn , zodat ik ze gewoon uit kan schakelen , en verwijderen , zodat ik er maar een overhoud
Aaron heeft je een beetje op een verkeerd spoor gezet. In je log zijn slechts sporen te vinden van 2 antivirusprogramma's. Nu het duidelijk is dat Avast het programma is dat je actief als antivirus gebruikt, kunnen de resten van Bitdefender zonder problemen verwijderd worden.

Om de overblijfselen op te ruimen mag je volgende vetgedrukte map (en de volledige inhoud ervan) verwijderen met Windows Verkenner:

C:\Program Files\Common Files\BitDefender

De rest van je beveiling - AVG Anti-Spyware als spywarescanner en de Windows Firewall - lijkt me OK, al zou ik - persoonlijk - als firewall toch eerder de Windows aan de kant schuiven en vervangen door een (gratis) versie van ZoneAlarm of Comodo (die een meer complete bescherming bieden dan de standaardfirewall van Windows). Maar dat is uiteraard jouw persoonlijke keuze ... en je huidige bescherming is niet slecht voor een "digibeet", hoor :)

Als deze twijfel van de baan is, kan je misschien eens kijken of je aan de uitvoering van mijn vorig advies - Combofix en HiJackThis - toekomt ?

Link naar reactie
Delen op andere sites

  • Reacties 22
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Gast peterje

hallo .

ik heb alles gedaan wat u zei , hierbij het logje van ,combofix , ik kon alleen de optie ,023 boonty games niet vinden , om aan te vinken , dat zal mogelijk komen omdat ik hem in ,service heb uitgeschakeld , als u meer instruktieshebt hoor ik hret graag ,

en alvast weer bedankt voor de moeite.

peterje .

Combix 08-05-01.3 - sjape 2008-05-08 8:01:10.1 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.179 [GMT 2:00]

Gestart vanuit: C:\Documents and Settings\sjape\Bureaublad\combofix\ComboFix.exe

* Nieuw herstelpunt werd aangemaakt

WAARSCHUWING - DE RECOVERY CONSOLE IS NIET OP DIT SYSTEEM GEINSTALLEERD !!

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\Documents and Settings\sjape\Application Data\inst.exe

.

(((((((((((((((((((( Bestanden Gemaakt van 2008-04-08 to 2008-05-08 ))))))))))))))))))))))))))))))

.

2008-05-08 08:01 . 2008-05-08 08:01 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG

2008-05-07 07:46 . 2008-05-07 07:44 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys

2008-05-07 07:44 . 2008-05-07 07:47 <DIR> d-------- C:\Documents and Settings\sjape\.housecall6.6

2008-05-07 07:38 . 2008-05-07 07:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx

2008-05-06 19:53 . 2008-05-06 19:53 <DIR> d-------- C:\Program Files\KC Softwares

2008-05-06 08:09 . 2008-05-06 08:09 0 --ah----- C:\Documents and Settings\sjape\ntuser.dat_TU_58485.LOG

2008-05-06 08:09 . 2008-05-06 08:09 0 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT_TU_33992.LOG

2008-05-06 08:09 . 2008-05-06 08:09 0 --ah----- C:\Documents and Settings\LocalService\ntuser.dat_TU_68708.LOG

2008-05-01 20:02 . 2008-05-01 20:02 0 --ah----- C:\Documents and Settings\sjape\ntuser.dat_TU_72192.LOG

2008-05-01 20:02 . 2008-05-01 20:02 0 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT_TU_93879.LOG

2008-05-01 20:02 . 2008-05-01 20:02 0 --ah----- C:\Documents and Settings\LocalService\ntuser.dat_TU_23271.LOG

2008-05-01 19:55 . 2008-05-01 19:55 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe

2008-05-01 19:55 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll

2008-05-01 19:54 . 2008-05-01 19:55 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008

2008-05-01 19:54 . 2008-05-01 19:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software

2008-05-01 19:53 . 2008-05-01 19:53 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard

2008-05-01 17:05 . 2008-05-07 19:10 <DIR> dr-h----- C:\Documents and Settings\sjape\Onlangs geopend

2008-05-01 10:39 . 2008-05-01 10:39 <DIR> d-------- C:\My Download Files

2008-05-01 10:38 . 2008-05-01 10:38 774,144 --a------ C:\Program Files\RngInterstitial.dll

2008-05-01 10:37 . 2008-05-01 10:37 <DIR> d-------- C:\Program Files\Real

2008-05-01 10:37 . 2008-05-01 10:42 <DIR> d-------- C:\Program Files\Common Files\Real

2008-05-01 09:16 . 2008-05-01 09:22 <DIR> d-------- C:\Program Files\Registry Easy

2008-05-01 09:10 . 2008-05-01 09:10 <DIR> d-------- C:\Documents and Settings\sjape\Application Data\ErrorSmart

2008-05-01 09:04 . 2008-05-01 09:04 54,156 --ah----- C:\WINDOWS\QTFont.qfn

2008-05-01 09:04 . 2008-05-01 09:04 1,409 --a------ C:\WINDOWS\QTFont.for

2008-04-29 19:12 . 2000-12-08 21:59 122,880 --a------ C:\WINDOWS\UnGins.exe

2008-04-29 19:10 . 2008-04-29 19:10 <DIR> d-------- C:\Archivos de programa

2008-04-29 18:38 . 2008-04-29 18:38 <DIR> d-------- C:\Program Files\Hmonitor

2008-04-29 17:13 . 2007-03-02 17:55 198,144 --------- C:\WINDOWS\system32\_psisdecd.dll

2008-04-29 13:15 . 2007-03-02 17:55 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll

2008-04-29 13:14 . 2007-03-02 17:55 89,088 --------- C:\WINDOWS\system32\atl71.dll

2008-04-27 07:32 . 2008-04-27 07:32 <DIR> d-------- C:\Program Files\GiPo@Utilities

2008-04-27 07:32 . 2008-04-27 07:37 <DIR> d-------- C:\Program Files\Common Files\Gibinsoft Shared

2008-04-26 09:09 . 2008-04-26 09:09 <DIR> d-------- C:\Program Files\WinASO

2008-04-25 19:25 . 2008-04-25 19:25 <DIR> d-------- C:\Documents and Settings\sjape\Application Data\GameHouse

2008-04-25 19:25 . 2008-04-25 19:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9

2008-04-24 17:22 . 2008-04-24 17:22 <DIR> d-------- C:\Documents and Settings\sjape\Application Data\Uniblue

2008-04-21 18:56 . 2008-04-21 18:56 <DIR> d-------- C:\65ac826298ff83a11f9a95087618

2008-04-21 18:55 . 2008-04-21 18:55 <DIR> d-------- C:\Program Files\MagicBall

2008-04-21 18:55 . 2008-04-21 18:55 <DIR> d-------- C:\Program Files\Lexmark 730 Series

2008-04-21 18:55 . 2008-05-07 19:06 <DIR> d-------- C:\Documents and Settings\sjape\Application Data\DNA

2008-04-21 18:55 . 2008-04-21 18:55 <DIR> d-------- C:\Documents and Settings\sjape\Application Data\BitDefender

2008-04-21 18:55 . 2008-04-21 18:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender

2008-04-21 18:54 . 2008-04-21 18:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion

2008-04-21 08:21 . 2008-04-21 08:22 <DIR> d-------- C:\Program Files\Movie DVD Maker

2008-04-21 08:03 . 2008-04-21 18:53 <DIR> d-------- C:\Program Files\SpywareBlaster

2008-04-19 20:25 . 2008-04-19 20:25 <DIR> d-------- C:\Documents and Settings\sjape\Application Data\Zen of Sudoku

2008-04-19 19:47 . 2008-05-06 08:09 229,376 --a------ C:\Documents and Settings\LocalService\ntuser.dat_BAK_68708

2008-04-19 19:47 . 2008-05-01 20:02 229,376 --a------ C:\Documents and Settings\LocalService\ntuser.dat_BAK_23271

2008-04-19 19:38 . 2007-11-27 16:46 77,824 --a------ C:\WINDOWS\system32\xcomm.dll

2008-04-19 11:41 . 2008-04-19 11:41 12,673 --a------ C:\WINDOWS\system32\LexFiles.ulf

2008-04-19 11:40 . 2006-05-03 16:15 1,158 -ra------ C:\WINDOWS\system32\lxcf.loc

2008-04-19 11:39 . 2008-04-21 18:55 <DIR> d-------- C:\Program Files\Lexmark 730 Series(2)

2008-04-18 20:25 . 2008-04-21 18:55 <DIR> d-------- C:\f1696ee07c7e5466291b

2008-04-18 20:19 . 2008-04-21 18:55 <DIR> d--h----- C:\Documents and Settings\sjape\Onlangs geopend(2)

2008-04-18 07:41 . 2008-04-21 18:56 <DIR> d-------- C:\Documents and Settings\sjape\.SunDownloadManager

2008-04-16 10:23 . 2008-05-01 20:02 6,291,456 --a------ C:\Documents and Settings\sjape\ntuser.dat_BAK_72192

2008-04-16 10:23 . 2008-05-06 08:09 6,291,456 --a------ C:\Documents and Settings\sjape\ntuser.dat_BAK_58485

2008-04-15 13:23 . 2008-04-15 13:23 85,520 --a------ C:\WINDOWS\system32\drivers\bdfndisf.sys

2008-04-15 09:17 . 2008-04-15 13:37 121 --a------ C:\WINDOWS\bdagent.INI

2008-04-14 23:20 . 2008-04-14 23:20 0 --a------ C:\sla.sys

2008-04-14 20:07 . 2008-04-15 20:06 <DIR> d-------- C:\Program Files\SPYWAREfighter

2008-04-14 19:07 . 2008-04-15 07:01 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy

2008-04-14 19:07 . 2008-04-14 20:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

2008-04-10 08:55 . 2008-04-10 08:55 <DIR> d-------- C:\Program Files\RogueRemover FREE

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-05-07 17:38 --------- d-----w C:\Documents and Settings\sjape\Application Data\OpenOffice.org2

2008-05-07 17:14 --------- d-----w C:\Program Files\EsetOnlineScanner

2008-05-07 05:37 --------- d-----w C:\Program Files\Hitman Pro

2008-05-06 05:58 --------- d-----w C:\Documents and Settings\sjape\Application Data\BitTorrent

2008-05-03 18:02 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP

2008-05-03 17:50 --------- d-----w C:\Program Files\7 Wonders

2008-05-02 17:18 --------- d-----w C:\Program Files\Alawar

2008-05-02 17:15 --------- d-----w C:\Program Files\Google

2008-05-02 06:09 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-05-01 17:02 --------- d-----w C:\Program Files\Lx_cats

2008-05-01 14:00 --------- d-----w C:\Documents and Settings\sjape\Application Data\Ahead

2008-05-01 08:28 --------- d-----w C:\Program Files\PopCap Games

2008-05-01 08:25 --------- d-----w C:\Program Files\GameHouse

2008-04-30 17:08 --------- d-----w C:\Program Files\Common Files\Adobe

2008-04-29 17:55 --------- d-----w C:\Documents and Settings\sjape\Application Data\Desktopicon

2008-04-29 15:13 --------- d-----w C:\Program Files\Cyberlink

2008-04-29 15:13 --------- d-----w C:\Documents and Settings\sjape\Application Data\CyberLink

2008-04-29 15:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink

2008-04-27 07:23 --------- d-----w C:\Program Files\Magic Ball 2

2008-04-26 06:20 --------- d-----w C:\Program Files\Unlocker

2008-04-26 06:18 --------- d-----w C:\Program Files\Windows Media Connect 2

2008-04-25 17:25 --------- d-----w C:\Program Files\Microsoft Silverlight

2008-04-25 17:25 --------- d-----w C:\Program Files\Magic Ball 2 New Worlds

2008-04-21 16:55 --------- d-----w C:\Program Files\Slingo Quest

2008-04-21 16:55 --------- d-----w C:\Program Files\DNA

2008-04-21 16:54 --------- d-----w C:\Program Files\Yahoo!

2008-04-21 16:53 --------- d-----w C:\Program Files\AppieSoft

2008-04-21 06:03 --------- d-----w C:\Program Files\Lavasoft

2008-04-18 16:48 --------- d-----w C:\Program Files\Java

2008-04-15 17:12 3,888 ----a-w C:\WINDOWS\system32\drivers\NTHANDLE.SYS

2008-03-25 19:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab

2008-03-22 21:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\rionix

2008-03-22 18:19 --------- d-----w C:\Documents and Settings\sjape\Application Data\NASA

2008-03-21 19:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\BOONTY

2008-03-21 13:52 12,464 ----a-w C:\WINDOWS\system32\drivers\CdaC15BA.SYS

2008-03-20 15:46 --------- d-----w C:\Program Files\UPHClean

2008-03-20 12:45 --------- d-----w C:\Program Files\Innovative Solutions

2008-03-20 08:10 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys

2008-03-18 06:33 --------- d-----w C:\Program Files\Common Files\Ahead

2008-03-17 15:33 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition

2008-03-17 11:29 --------- d-----w C:\Program Files\Microsoft Bootvis

2008-03-17 11:21 --------- d-----w C:\Program Files\Driver Sweeper

2008-03-16 12:04 --------- d-----w C:\Documents and Settings\sjape\Application Data\vlc

2008-03-16 12:03 --------- d-----w C:\Program Files\VideoLAN

2008-03-15 16:35 --------- d-----w C:\Program Files\Common Files\Fellowes

2008-03-15 16:33 2,423 ----a-w C:\WINDOWS\NewRecorder.reg

2008-03-15 16:33 1,816,779 ----a-w C:\WINDOWS\Recorder.reg

2008-03-15 16:33 --------- d-----w C:\Program Files\Pinnacle

2008-03-13 19:18 --------- d-----w C:\Program Files\Gamenext

2008-03-13 19:16 --------- d-----w C:\Program Files\Common Files\Scanner

2008-03-13 19:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\BigFishGamesCache

2008-03-13 19:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\7Wonders2

2008-03-13 19:04 0 ----a-w C:\Program Files\temp01

2008-03-13 11:52 --------- d-----w C:\Program Files\Wise Registry Cleaner 3

2008-03-12 18:45 --------- d-----w C:\Program Files\BitTorrent

2008-03-11 12:02 --------- d-----w C:\Program Files\Wise Disk Cleaner

2008-03-09 10:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Alawar Stargaze

2008-03-09 08:18 --------- d-----w C:\Documents and Settings\sjape\Application Data\SpinTop

2008-03-05 19:24 47,360 ----a-w C:\Documents and Settings\sjape\Application Data\pcouffin.sys

2008-03-04 12:24 844,017 ----a-w C:\Program Files\BitTorrent-6.0.zip

2008-03-01 13:05 826,368 ----a-w C:\WINDOWS\system32\wininet.dll

2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll

2008-02-20 05:39 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll

2008-02-11 07:39 253,952 ----a-w C:\WINDOWS\system32\OnlineScannerDLLA.dll

2008-02-11 07:39 237,568 ----a-w C:\WINDOWS\system32\OnlineScannerDLLW.dll

2008-02-08 11:53 110,592 ----a-w C:\WINDOWS\system32\OnlineScannerLang.dll

.

------- Sigcheck -------

2008-03-06 13:37 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\dllcache\TCPIP.SYS

2008-03-06 13:37 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\drivers\tcpip.sys

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe]

"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 16:03 16125440 C:\WINDOWS\RTHDCPL.exe]

"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]

"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]

"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]

"LXCFCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 19:47 73728]

"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 14:00 160256]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.I420"= vdrcodec.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Service Manager.lnk]

backup=C:\WINDOWS\pss\Service Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^sjape^Menu Start^Programma's^Opstarten^OpenOffice.org 2.3 .lnk]

backup=C:\WINDOWS\pss\OpenOffice.org 2.3 .lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]

--a------ 2007-06-11 11:25 6731312 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]

--a------ 2007-03-09 12:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]

--a------ 2008-04-11 07:25 288576 C:\Program Files\DNA\btdna.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

--a------ 2004-08-04 14:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]

--a------ 2006-02-07 09:36 77824 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]

--a------ 2006-02-07 09:40 118784 C:\WINDOWS\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]

--a------ 2006-02-07 09:39 94208 C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

--------- 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2001-07-09 12:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]

--a------ 2007-10-23 23:18 443968 C:\Program Files\Picasa2\PicasaMediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]

--a------ 2006-05-16 19:04 2879488 C:\WINDOWS\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

--a------ 2008-01-13 12:09 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zSPGuard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"gusvc"=3 (0x3)

"WMPNetworkSvc"=2 (0x2)

"WLSetupSvc"=3 (0x3)

"MDM"=2 (0x2)

"lxcf_device"=3 (0x3)

"IDriverT"=3 (0x3)

"avast! Mail Scanner"=3 (0x3)

"XCOMM"=2 (0x2)

"TuneUp.Defrag"=3 (0x3)

"LIVESRV"=2 (0x2)

"Boonty Games"=3 (0x3)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe"

"InstantTray"=C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe

"IW_Drop_Icon"=C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc

"Hitman Pro SurfRight Helper"="C:\Program Files\Hitman Pro\srhelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"PinnacleDriverCheck"=C:\WINDOWS\system32\PSDrvCheck.exe

"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime

"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Program Files\\DNA\\btdna.exe"=

"C:\\Program Files\\BitTorrent\\bittorrent.exe"=

"C:\\Program Files\\Yahoo! Games\\Zuma Deluxe\\Zuma.exe"=

R0 VOBID;VOBID;C:\WINDOWS\system32\DRIVERS\vobid.sys [2003-08-01 15:47]

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]

R1 vobiw;vobiw;C:\WINDOWS\system32\drivers\vobiw.sys [2004-07-06 18:06]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]

R2 UxTuneUp;TuneUp Thema-uitbreiding;C:\WINDOWS\System32\svchost.exe [2004-08-04 14:00]

R3 cdrdrv;Cdrdrv;C:\WINDOWS\system32\Drivers\Cdrdrv.sys [2004-08-03 12:10]

S4 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" []

S4 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-01 19:55]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bdx REG_MULTI_SZ scan

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

*Newly Created Service* - CATCHME

.

Inhoud van de 'Gedeelde Taken' map

"2008-05-08 06:00:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"

- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe

"2008-05-08 06:00:00 C:\WINDOWS\Tasks\Easy Onderhoud.job"

- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe

.

**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-05-08 08:02:44

Windows 5.1.2600 Service Pack 2 NTFS

scannen van verborgen processen ...

scannen van verborgen autostart items ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

LXCFCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scannen van verborgen bestanden ...

Scan succesvol afgerond

verborgen bestanden: 0

**************************************************************************

.

Voltooingstijd: 2008-05-08 8:03:23

ComboFix-quarantined-files.txt 2008-05-08 06:03:20

Pre-Run: 42,121,510,912 bytes beschikbaar

Post-Run: 42,152,611,840 bytes beschikbaar

269 --- E O F --- 2008-05-07 21:32:39

Link naar reactie
Delen op andere sites

Gast peterje

ik was nog vergeten de log van hijack this erbij te doen , bij deze .

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 8:09:59, on 8-5-2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\RTHDCPL.EXE

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Cyberlink\Shared files\RichVideo.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\UPHClean\uphclean.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\WINDOWS\system32\notepad.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Startpagina.nl - alles op een rijtje!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites - Add to Windows Live Favorites

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab

O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Magic%20Ball%202%20New%20Worlds/Images/stg_drm.ocx

O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab

O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1198053969015

O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Magic%20Ball%202%20New%20Worlds/Images/armhelper.ocx

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe

--

End of file - 6983 bytes

Link naar reactie
Delen op andere sites

ik heb alles gedaan wat u zei ... ik kon alleen de optie 023 boonty games niet vinden , om aan te vinken , dat zal mogelijk komen omdat ik hem in ,service heb uitgeschakeld , als u meer instruktieshebt hoor ik hret graag
Nu al een antwoordje op deze vraag. Indien je de service hebt uitgeschakeld en de map C:\Program Files\Common Files\BOONTY Shared hebt verwijderd (zoals ik je had aangeraden), is het logisch dat je dat niet meer kan uitvinken in HiJackThis. Dan is deze optie volledig verwijderd van je PC. Je kan dat trouwens controleren in je nieuwe log van HJT : de 023-lijn van Boonty Games is verdwenen. Ook de resten van je Bitdefender zijn inmiddels opgeruimd, valt me nu al op. En zo hoort het :)

P.S. : de rest van je logs ga ik straks even uitvoerig bekijken.

Link naar reactie
Delen op andere sites

Open een kladblokbestand.

Kopieer en plak daarin de onderstaande vetgedrukte tekst.

Folder::

C:\Documents and Settings\sjape\Application Data\ErrorSmart

C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9

C:\Documents and Settings\LocalService\ntuser.dat_BAK_68708

C:\Documents and Settings\LocalService\ntuser.dat_BAK_23271

C:\Documents and Settings\sjape\ntuser.dat_BAK_72192

C:\Documents and Settings\sjape\ntuser.dat_BAK_58485

C:\Documents and Settings\All Users\Application Data\BOONTY

Sla dit bestand op je bureaublad op als CFScript.txt.

Sleep CFScript.txt in ComboFix.exe

Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.

Post na herstart de inhoud van de Combofix.txt in je volgende bericht

Zou je ook eens kunnen vertellen wat er in volgende vetgedrukte mappen zit ?

C:\Archivos de programa

C:\65ac826298ff83a11f9a95087618

C:\f1696ee07c7e5466291b

In je taken bij C:\WINDOWS\Tasks zitten o.a. 1-Click Maintenance.job en Easy Onderhoud.job. Zijn dat zaken die je daar zelf geprogrammeerd hebt ? En worden die ook permanent uitgevoerd ?

Link naar reactie
Delen op andere sites

Gast peterje

hallo.

de drie vetgedrukte dingen zijn gewoon rommel die er af kan , ik wist niet waar ze voor dienden dus was ik bang om ze te verwijderen .

in c windows task , ook rommel , erafgegooit , zo zal er nog wel meer op mijn pc rondzwerven

ik ga uw advies voor dat kladblok bestand opvolgen , dat stuur ik nog op ,

ik vind het wel vreemd dat ik nu alle adviezen per email doorkrijg , (UITSTEKEND HOOR ) maar als ik op de site kijk staan uw nieuwe adviezen daar niet bij , nog de opgestuurde logjes.

verder bedankt , peterje

Link naar reactie
Delen op andere sites

Gast peterje

hallo.

hier het nieuwe logje waar u om vroeg , van combofix .

ComboFix 08-05-01.3 - sjape 2008-05-08 19:48:15.2 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.198 [GMT 2:00]

Gestart vanuit: C:\Documents and Settings\sjape\Bureaublad\combofix\ComboFix.exe

Command switches used :: C:\Documents and Settings\sjape\Mijn documenten\CFScript.txt

* Nieuw herstelpunt werd aangemaakt

WAARSCHUWING - DE RECOVERY CONSOLE IS NIET OP DIT SYSTEEM GEINSTALLEERD !!

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\Documents and Settings\All Users\Application Data\BOONTY

C:\Documents and Settings\All Users\Application Data\BOONTY\Licenses\B4543000.dat

C:\Documents and Settings\All Users\Application Data\BOONTY\Licenses\B4ADD000.dat

C:\Documents and Settings\All Users\Application Data\BOONTY\Licenses\B4C9A000.dat

C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9

C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9\profile.ini

C:\Documents and Settings\LocalService\ntuser.dat_BAK_23271\

C:\Documents and Settings\LocalService\ntuser.dat_BAK_68708\

C:\Documents and Settings\sjape\Application Data\ErrorSmart

C:\Documents and Settings\sjape\Application Data\ErrorSmart\Log\2008 May 01 - 09_10_56 AM_500.log

C:\Documents and Settings\sjape\Application Data\ErrorSmart\Registry Backups\2008-05-01_09-11-59.reg

C:\Documents and Settings\sjape\ntuser.dat_BAK_58485\

C:\Documents and Settings\sjape\ntuser.dat_BAK_72192\

.

(((((((((((((((((((( Bestanden Gemaakt van 2008-04-08 to 2008-05-08 ))))))))))))))))))))))))))))))

.

2008-05-08 08:01 . 2008-05-08 08:01 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG

2008-05-07 07:46 . 2008-05-07 07:44 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys

2008-05-07 07:44 . 2008-05-07 07:47 <DIR> d-------- C:\Documents and Settings\sjape\.housecall6.6

2008-05-07 07:38 . 2008-05-07 07:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx

2008-05-06 19:53 . 2008-05-06 19:53 <DIR> d-------- C:\Program Files\KC Softwares

2008-05-06 08:09 . 2008-05-06 08:09 0 --ah----- C:\Documents and Settings\sjape\ntuser.dat_TU_58485.LOG

2008-05-06 08:09 . 2008-05-06 08:09 0 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT_TU_33992.LOG

2008-05-06 08:09 . 2008-05-06 08:09 0 --ah----- C:\Documents and Settings\LocalService\ntuser.dat_TU_68708.LOG

2008-05-01 20:02 . 2008-05-01 20:02 0 --ah----- C:\Documents and Settings\sjape\ntuser.dat_TU_72192.LOG

2008-05-01 20:02 . 2008-05-01 20:02 0 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT_TU_93879.LOG

2008-05-01 20:02 . 2008-05-01 20:02 0 --ah----- C:\Documents and Settings\LocalService\ntuser.dat_TU_23271.LOG

2008-05-01 19:55 . 2008-05-01 19:55 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe

2008-05-01 19:55 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll

2008-05-01 19:54 . 2008-05-01 19:55 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008

2008-05-01 19:54 . 2008-05-01 19:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software

2008-05-01 19:53 . 2008-05-01 19:53 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard

2008-05-01 17:05 . 2008-05-08 19:43 <DIR> dr-h----- C:\Documents and Settings\sjape\Onlangs geopend

2008-05-01 10:39 . 2008-05-01 10:39 <DIR> d-------- C:\My Download Files

2008-05-01 10:38 . 2008-05-01 10:38 774,144 --a------ C:\Program Files\RngInterstitial.dll

2008-05-01 10:37 . 2008-05-01 10:37 <DIR> d-------- C:\Program Files\Real

2008-05-01 10:37 . 2008-05-01 10:42 <DIR> d-------- C:\Program Files\Common Files\Real

2008-05-01 09:16 . 2008-05-01 09:22 <DIR> d-------- C:\Program Files\Registry Easy

2008-05-01 09:04 . 2008-05-01 09:04 54,156 --ah----- C:\WINDOWS\QTFont.qfn

2008-05-01 09:04 . 2008-05-01 09:04 1,409 --a------ C:\WINDOWS\QTFont.for

2008-04-29 19:12 . 2000-12-08 21:59 122,880 --a------ C:\WINDOWS\UnGins.exe

2008-04-29 19:10 . 2008-04-29 19:10 <DIR> d-------- C:\Archivos de programa

2008-04-29 18:38 . 2008-04-29 18:38 <DIR> d-------- C:\Program Files\Hmonitor

2008-04-29 17:13 . 2007-03-02 17:55 198,144 --------- C:\WINDOWS\system32\_psisdecd.dll

2008-04-29 13:15 . 2007-03-02 17:55 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll

2008-04-29 13:14 . 2007-03-02 17:55 89,088 --------- C:\WINDOWS\system32\atl71.dll

2008-04-27 07:32 . 2008-04-27 07:32 <DIR> d-------- C:\Program Files\GiPo@Utilities

2008-04-27 07:32 . 2008-04-27 07:37 <DIR> d-------- C:\Program Files\Common Files\Gibinsoft Shared

2008-04-26 09:09 . 2008-04-26 09:09 <DIR> d-------- C:\Program Files\WinASO

2008-04-25 19:25 . 2008-04-25 19:25 <DIR> d-------- C:\Documents and Settings\sjape\Application Data\GameHouse

2008-04-24 17:22 . 2008-04-24 17:22 <DIR> d-------- C:\Documents and Settings\sjape\Application Data\Uniblue

2008-04-21 18:56 . 2008-04-21 18:56 <DIR> d-------- C:\65ac826298ff83a11f9a95087618

2008-04-21 18:55 . 2008-04-21 18:55 <DIR> d-------- C:\Program Files\MagicBall

2008-04-21 18:55 . 2008-04-21 18:55 <DIR> d-------- C:\Program Files\Lexmark 730 Series

2008-04-21 18:55 . 2008-05-07 19:06 <DIR> d-------- C:\Documents and Settings\sjape\Application Data\DNA

2008-04-21 18:55 . 2008-04-21 18:55 <DIR> d-------- C:\Documents and Settings\sjape\Application Data\BitDefender

2008-04-21 18:55 . 2008-04-21 18:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender

2008-04-21 18:54 . 2008-04-21 18:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion

2008-04-21 08:21 . 2008-04-21 08:22 <DIR> d-------- C:\Program Files\Movie DVD Maker

2008-04-21 08:03 . 2008-04-21 18:53 <DIR> d-------- C:\Program Files\SpywareBlaster

2008-04-19 20:25 . 2008-04-19 20:25 <DIR> d-------- C:\Documents and Settings\sjape\Application Data\Zen of Sudoku

2008-04-19 19:47 . 2008-05-06 08:09 229,376 --a------ C:\Documents and Settings\LocalService\ntuser.dat_BAK_68708

2008-04-19 19:47 . 2008-05-01 20:02 229,376 --a------ C:\Documents and Settings\LocalService\ntuser.dat_BAK_23271

2008-04-19 19:38 . 2007-11-27 16:46 77,824 --a------ C:\WINDOWS\system32\xcomm.dll

2008-04-19 11:41 . 2008-04-19 11:41 12,673 --a------ C:\WINDOWS\system32\LexFiles.ulf

2008-04-19 11:40 . 2006-05-03 16:15 1,158 -ra------ C:\WINDOWS\system32\lxcf.loc

2008-04-19 11:39 . 2008-04-21 18:55 <DIR> d-------- C:\Program Files\Lexmark 730 Series(2)

2008-04-18 20:25 . 2008-04-21 18:55 <DIR> d-------- C:\f1696ee07c7e5466291b

2008-04-18 20:19 . 2008-04-21 18:55 <DIR> d--h----- C:\Documents and Settings\sjape\Onlangs geopend(2)

2008-04-18 07:41 . 2008-04-21 18:56 <DIR> d-------- C:\Documents and Settings\sjape\.SunDownloadManager

2008-04-16 10:23 . 2008-05-01 20:02 6,291,456 --a------ C:\Documents and Settings\sjape\ntuser.dat_BAK_72192

2008-04-16 10:23 . 2008-05-06 08:09 6,291,456 --a------ C:\Documents and Settings\sjape\ntuser.dat_BAK_58485

2008-04-15 13:23 . 2008-04-15 13:23 85,520 --a------ C:\WINDOWS\system32\drivers\bdfndisf.sys

2008-04-15 09:17 . 2008-04-15 13:37 121 --a------ C:\WINDOWS\bdagent.INI

2008-04-14 23:20 . 2008-04-14 23:20 0 --a------ C:\sla.sys

2008-04-14 20:07 . 2008-04-15 20:06 <DIR> d-------- C:\Program Files\SPYWAREfighter

2008-04-14 19:07 . 2008-04-15 07:01 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy

2008-04-14 19:07 . 2008-04-14 20:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

2008-04-10 08:55 . 2008-04-10 08:55 <DIR> d-------- C:\Program Files\RogueRemover FREE

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-05-08 17:26 --------- d-----w C:\Documents and Settings\sjape\Application Data\OpenOffice.org2

2008-05-07 17:14 --------- d-----w C:\Program Files\EsetOnlineScanner

2008-05-07 05:37 --------- d-----w C:\Program Files\Hitman Pro

2008-05-06 05:58 --------- d-----w C:\Documents and Settings\sjape\Application Data\BitTorrent

2008-05-03 18:02 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP

2008-05-03 17:50 --------- d-----w C:\Program Files\7 Wonders

2008-05-02 17:18 --------- d-----w C:\Program Files\Alawar

2008-05-02 17:15 --------- d-----w C:\Program Files\Google

2008-05-02 06:09 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-05-01 17:02 --------- d-----w C:\Program Files\Lx_cats

2008-05-01 14:00 --------- d-----w C:\Documents and Settings\sjape\Application Data\Ahead

2008-05-01 08:28 --------- d-----w C:\Program Files\PopCap Games

2008-05-01 08:25 --------- d-----w C:\Program Files\GameHouse

2008-04-30 17:08 --------- d-----w C:\Program Files\Common Files\Adobe

2008-04-29 17:55 --------- d-----w C:\Documents and Settings\sjape\Application Data\Desktopicon

2008-04-29 15:13 --------- d-----w C:\Program Files\Cyberlink

2008-04-29 15:13 --------- d-----w C:\Documents and Settings\sjape\Application Data\CyberLink

2008-04-29 15:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink

2008-04-27 07:23 --------- d-----w C:\Program Files\Magic Ball 2

2008-04-26 06:20 --------- d-----w C:\Program Files\Unlocker

2008-04-26 06:18 --------- d-----w C:\Program Files\Windows Media Connect 2

2008-04-25 17:25 --------- d-----w C:\Program Files\Microsoft Silverlight

2008-04-25 17:25 --------- d-----w C:\Program Files\Magic Ball 2 New Worlds

2008-04-21 16:55 --------- d-----w C:\Program Files\Slingo Quest

2008-04-21 16:55 --------- d-----w C:\Program Files\DNA

2008-04-21 16:54 --------- d-----w C:\Program Files\Yahoo!

2008-04-21 16:53 --------- d-----w C:\Program Files\AppieSoft

2008-04-21 06:03 --------- d-----w C:\Program Files\Lavasoft

2008-04-18 16:48 --------- d-----w C:\Program Files\Java

2008-04-15 17:12 3,888 ----a-w C:\WINDOWS\system32\drivers\NTHANDLE.SYS

2008-03-25 19:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab

2008-03-22 21:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\rionix

2008-03-22 18:19 --------- d-----w C:\Documents and Settings\sjape\Application Data\NASA

2008-03-21 13:52 12,464 ----a-w C:\WINDOWS\system32\drivers\CdaC15BA.SYS

2008-03-20 15:46 --------- d-----w C:\Program Files\UPHClean

2008-03-20 12:45 --------- d-----w C:\Program Files\Innovative Solutions

2008-03-20 08:10 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys

2008-03-18 06:33 --------- d-----w C:\Program Files\Common Files\Ahead

2008-03-17 15:33 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition

2008-03-17 11:29 --------- d-----w C:\Program Files\Microsoft Bootvis

2008-03-17 11:21 --------- d-----w C:\Program Files\Driver Sweeper

2008-03-16 12:04 --------- d-----w C:\Documents and Settings\sjape\Application Data\vlc

2008-03-16 12:03 --------- d-----w C:\Program Files\VideoLAN

2008-03-15 16:35 --------- d-----w C:\Program Files\Common Files\Fellowes

2008-03-15 16:33 2,423 ----a-w C:\WINDOWS\NewRecorder.reg

2008-03-15 16:33 1,816,779 ----a-w C:\WINDOWS\Recorder.reg

2008-03-15 16:33 --------- d-----w C:\Program Files\Pinnacle

2008-03-13 19:18 --------- d-----w C:\Program Files\Gamenext

2008-03-13 19:16 --------- d-----w C:\Program Files\Common Files\Scanner

2008-03-13 19:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\BigFishGamesCache

2008-03-13 19:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\7Wonders2

2008-03-13 19:04 0 ----a-w C:\Program Files\temp01

2008-03-13 11:52 --------- d-----w C:\Program Files\Wise Registry Cleaner 3

2008-03-12 18:45 --------- d-----w C:\Program Files\BitTorrent

2008-03-11 12:02 --------- d-----w C:\Program Files\Wise Disk Cleaner

2008-03-09 10:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Alawar Stargaze

2008-03-09 08:18 --------- d-----w C:\Documents and Settings\sjape\Application Data\SpinTop

2008-03-05 19:24 47,360 ----a-w C:\Documents and Settings\sjape\Application Data\pcouffin.sys

2008-03-04 12:24 844,017 ----a-w C:\Program Files\BitTorrent-6.0.zip

2008-03-01 13:05 826,368 ----a-w C:\WINDOWS\system32\wininet.dll

2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll

2008-02-20 05:39 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll

2008-02-11 07:39 253,952 ----a-w C:\WINDOWS\system32\OnlineScannerDLLA.dll

2008-02-11 07:39 237,568 ----a-w C:\WINDOWS\system32\OnlineScannerDLLW.dll

2008-02-08 11:53 110,592 ----a-w C:\WINDOWS\system32\OnlineScannerLang.dll

.

------- Sigcheck -------

2008-03-06 13:37 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\dllcache\TCPIP.SYS

2008-03-06 13:37 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\drivers\tcpip.sys

.

((((((((((((((((((((((((((((( snapshot@2008-05-08_ 8.03.13,26 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-05-08 05:05:35 2,048 --s-a-w C:\WINDOWS\bootstat.dat

+ 2008-05-08 16:22:55 2,048 --s-a-w C:\WINDOWS\bootstat.dat

+ 2008-05-08 16:23:08 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_49c.dat

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe]

"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 16:03 16125440 C:\WINDOWS\RTHDCPL.exe]

"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]

"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]

"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]

"LXCFCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 19:47 73728]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.I420"= vdrcodec.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Service Manager.lnk]

backup=C:\WINDOWS\pss\Service Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^sjape^Menu Start^Programma's^Opstarten^OpenOffice.org 2.3 .lnk]

backup=C:\WINDOWS\pss\OpenOffice.org 2.3 .lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]

--a------ 2007-06-11 11:25 6731312 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]

--a------ 2007-03-09 12:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]

--a------ 2008-04-11 07:25 288576 C:\Program Files\DNA\btdna.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

--a------ 2004-08-04 14:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]

--a------ 2006-02-07 09:36 77824 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]

--a------ 2006-02-07 09:40 118784 C:\WINDOWS\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]

--a------ 2006-02-07 09:39 94208 C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

--------- 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2001-07-09 12:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]

--a------ 2007-10-23 23:18 443968 C:\Program Files\Picasa2\PicasaMediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]

--a------ 2006-05-16 19:04 2879488 C:\WINDOWS\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

--a------ 2008-01-13 12:09 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zSPGuard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"gusvc"=3 (0x3)

"WMPNetworkSvc"=2 (0x2)

"WLSetupSvc"=3 (0x3)

"MDM"=2 (0x2)

"lxcf_device"=3 (0x3)

"IDriverT"=3 (0x3)

"avast! Mail Scanner"=3 (0x3)

"XCOMM"=2 (0x2)

"TuneUp.Defrag"=3 (0x3)

"LIVESRV"=2 (0x2)

"Boonty Games"=3 (0x3)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe"

"InstantTray"=C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe

"IW_Drop_Icon"=C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc

"Hitman Pro SurfRight Helper"="C:\Program Files\Hitman Pro\srhelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"PinnacleDriverCheck"=C:\WINDOWS\system32\PSDrvCheck.exe

"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime

"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Program Files\\DNA\\btdna.exe"=

"C:\\Program Files\\BitTorrent\\bittorrent.exe"=

"C:\\Program Files\\Yahoo! Games\\Zuma Deluxe\\Zuma.exe"=

R0 VOBID;VOBID;C:\WINDOWS\system32\DRIVERS\vobid.sys [2003-08-01 15:47]

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]

R1 vobiw;vobiw;C:\WINDOWS\system32\drivers\vobiw.sys [2004-07-06 18:06]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]

R2 UxTuneUp;TuneUp Thema-uitbreiding;C:\WINDOWS\System32\svchost.exe [2004-08-04 14:00]

R3 cdrdrv;Cdrdrv;C:\WINDOWS\system32\Drivers\Cdrdrv.sys [2004-08-03 12:10]

S4 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" []

S4 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-01 19:55]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bdx REG_MULTI_SZ scan

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

.

**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-05-08 19:49:17

Windows 5.1.2600 Service Pack 2 NTFS

scannen van verborgen processen ...

scannen van verborgen autostart items ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

LXCFCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scannen van verborgen bestanden ...

Scan succesvol afgerond

verborgen bestanden: 0

**************************************************************************

.

Voltooingstijd: 2008-05-08 19:49:54

ComboFix-quarantined-files.txt 2008-05-08 17:49:49

ComboFix2.txt 2008-05-08 06:03:24

Pre-Run: 42,129,203,200 bytes beschikbaar

Post-Run: 42,120,921,088 bytes beschikbaar

278 --- E O F --- 2008-05-07 21:32:39

Link naar reactie
Delen op andere sites

Gast peterje

hallo .

de start tijd is nu ongeveer anderhalve minuut , prima toch !! de mogelijke reden dat ik wat rommel op de pc had is dat ik pas een paar jaar een pc heb , en daarvoor er absoluut niet in was geinteresseerd , ik was toen 65 jaar , nu 68 . dan heb je wel dingen die je niet weg durft te gooien ,maar die de boel aardig vertragen .

ik wil u , dan ook hartelijk bedanken voor de hulp , die u belangeloos verstrekt heeft , ik vind het fantastisch dat er mensen zijn die dit doen, mogelijk uit hobby , maar toch doet u het , geweldig !!!

ik hoop dat de zaak nu goed blijft draaien , al heb ik nog wel een ander probleem . waar ik al lang mee bezig ben ,

ik zal het kort uitleggen ,

na een crash windows opn. geinstaleerd .

ik heb service pack 2 ,een ook moviemaker ,(engels ) maar die doet het niet ,nou heb ik getracht servicepack te verwijderen ,en de hele zaak incl. moviemaker er opnieuw op te zetten , (maar dan in het nederlands ), maar wat ik ook doe om het te verwijderen ,inclusief de door microsoft aanbevolen manieren , het gaat niet , ook getracht moviemaker nederlands apart te downloaden , die laat zich niet overschrijven , dus daar zal ik mee moeten leven .wel lastig want het is een makkelijk programma

nogmaals hartelijk dank voor uw fantastische hulp .

groeten ,peter.

Link naar reactie
Delen op andere sites

Ben niet echt thuis in Moviemaker, maar mocht ik in uw geval zijn zou ik eens het volgende proberen (al je dat nog niet mocht gedaan hebben, natuurlijk) :

Verwijder dit programma via Start -> Configuratiescherm -> Software (als het zich daar bevindt) of via een eigen uninstaller (als het die heeft). Neem dan een cleanprogramma dat alle overbodige resten van Moviemaker mee uit je register verwijderd. Mijn suggestie daarvoor is altijd CCleaner.

Doe dit als volgt :

Download CCleaner.

Installeer het en start het op. Klik in de linkse kolom op “Opties”. Selecteer het tabblad ‘Geavanceerd’ en haal het vinkje weg voor “Verwijder alleen tijdelijke bestanden in de Windows systeemmap die ouder zijn dan 48 uur” en sluit hierna het programma.

Start CCleaner op en klik in de linkse kolom op “Cleaner”. Klik achtereenvolgens op ‘Analyseren’ en 'Opschonen'. Klik vervolgens in de linkse kolom op “Register” en klik op ‘Scan naar problemen”. Als er fouten gevonden worden klik je op ”Herstel geselecteerde problemen” en ”OK”. Dan krijg je de vraag om een back-up te maken. Klik op “JA”. Kies dan “Herstel alle geselecteerde fouten”. Sluit hierna CCleaner terug af.

Als je enige ervaring hebt met werken in het register van je computer, kan je daar nog eens manueel naar alle sporen van die Moviemaker zoeken en deze verwijderen.

Indien het programma niet gekoppeld is aan andere toepassingen, zou het dan volledig van je PC moeten verwijderd zijn en zou een nieuwe installatie van de Nederlandse versie mogelijk moeten zijn. Maar we zitten hier met Microsoft/Windows-applicaties ... en dan is dat - helaas - nooit helemaal zeker. Maar het lijkt me het proberen waard, je kan er alvast weinig mis mee doen.

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.