Archief - Vista: Verkenner werkt niet meer/rundll32 crash

Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.

ugh

Legacy Member
Mijn verkenner (explorer) crasht sinds een paar uur elke keer, en dan moet ik 'opnieuw starten' klikken en na 4 seconden crasht hij weer.
Dit gaat gekoppeld met de melding rundll32 crash.

Mijn pc stond zo'n 30uur aan (screensaver wel), en geen nieuw programma geinstalleerd of gedownload sinds paar dagen geleden (toen het wel werkte))

Ik heb alle nutteloze programmas gedesinstalleerd.
En na wat googlen ben ik op een (tijdelijke) oplossing gekomen. Als ik in configuratiescherm -mapopties -weergave ga, en dan het vakje 'altijd pictogrammen weegeven, nooit miniatuurweergaven' aanvink.
Dan krijg ik de error niet meer.

Maar het lijkt me dat dit een bepaald probleempje oplost maar niet de onderliggende oorzaak. Ik heb ad-aware al eens laten scannen, evenals antivir, maar die vonden niets.

Dus hier heb ik een hijackthis logje toegevoegd, hopelijk dat jullie me hiermee kunnen helpen.
(Ik zou die miniatuurweergave wel willen gebruiken en wil mogelijke problemen in de toekomst ook vermijden)

Code:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:03:48, on 26/12/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\mIRC\mirc.exe
C:\Users\ugh\Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2088433
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-785287101-1414556579-2312349739-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'postgres')
O4 - Global Startup: UltraMon.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Play Poker - {00000000-0000-0000-0000-000000000000} - C:\MicroGaming\Poker\PokerShareMPP\MPPoker.exe (HKCU)
O9 - Extra button: Absolute Poker - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Users\ugh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Users\ugh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O13 - Gopher Prefix: 
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} (VodClient Control Class) - http://www.vexcast.com/download/vexcast.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: B-Service - Unknown owner - C:\Users\ugh\AppData\Roaming\Mikogo\B-Service.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 5292 bytes

Juisterr

Legacy Member
Klik met de rechtermuis op het programma Hijackthis en kies voor "Uitvoeren als Administrator"
Kies voor 'Do a system scan only'
Selecteer alleen de items die hieronder zijn genoemd:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

Sluit alle vensters behalve Hijackthis
Klik op 'Fix checked' om de items te verwijderen.

Start hijackthis opnieuw en maak een nieuw HijackThis logje, let wel op want
je moet HijackThis als Administrator uitvoeren en dan de nieuwe log posten.
Indien je het niet als administrator uitvoert, wordt de oude log niet overschreven.

Het lijkt me niet waarschijnlijk dat dit het probleem oplossen zal.

ugh

Legacy Member
Code:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:10:31, on 27/12/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\ugh\Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2088433
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-785287101-1414556579-2312349739-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'postgres')
O4 - Global Startup: UltraMon.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Play Poker - {00000000-0000-0000-0000-000000000000} - C:\MicroGaming\Poker\PokerShareMPP\MPPoker.exe (HKCU)
O9 - Extra button: Absolute Poker - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Users\ugh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Users\ugh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O13 - Gopher Prefix: 
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} (VodClient Control Class) - http://www.vexcast.com/download/vexcast.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: B-Service - Unknown owner - C:\Users\ugh\AppData\Roaming\Mikogo\B-Service.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 5177 bytes

ik krijg dit precies niet weg:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

lukt niet door op fix checked te klikken.

edit: nog niet opgelost, zodra ik terug miniatuurweergave toelaat krijg ik instant rundll32 en explorer crash

Juisterr

Legacy Member
Download Combofix naar je Bureaublad en gebruik het volgens deze handleiding.

OPMERKING: indien je, tijdens of na het downloaden van Combofix of tijdens het gebruik van Combofix een melding krijgt van je Antivirus- of een andere realtime scanner, schakel dan deze scanner uit en download Combofix opnieuw.
Sommige scanners zien bepaalde componenten die Combofix gebruikt als verdacht en gaan deze blokkeren of verwijderen!
  • Dubbelklik op Combofix.exe om het te starten.
  • Indien je Combofix al eerder hebt gebruikt, kan je een waarschuwing krijgen dat een update beschikbaar is. Sta toe dat ComboFix wordt geupdate.
  • Klik op OK in het "NirCmd" venstertje.
  • Klik na afloop terug op Ja om het scannen op malware te starten.
  • Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.
  • Wanneer de fix voltooid is en na herstart, zal de log Combofix.txt openen.
Post dit logje in je volgende antwoord

ugh

Legacy Member
ComboFix 10-01-02.05 - ugh 03/01/2010 17:52:55.2.2 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.32.1033.18.2046.816 [GMT 1:00]
Gestart vanuit: c:\users\ugh\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-1993962763-1409082233-839522115-1004

.
(((((((((((((((((((( Bestanden Gemaakt van 2009-12-03 to 2010-01-03 ))))))))))))))))))))))))))))))
.

2010-01-03 17:13 . 2010-01-03 17:14 -------- d-----w- c:\users\ugh\AppData\Local\temp
2010-01-03 17:13 . 2010-01-03 17:13 -------- d-----w- c:\users\postgres\AppData\Local\temp
2010-01-03 17:13 . 2010-01-03 17:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-03 16:40 . 2010-01-03 16:40 -------- d-----w- c:\programdata\Trymedia
2009-12-30 11:00 . 2009-12-30 11:00 -------- d-----w- c:\users\ugh\AppData\Roaming\FastStone
2009-12-30 11:00 . 2009-12-30 11:00 -------- d-----w- c:\program files\FastStone Photo Resizer
2009-12-26 00:00 . 2009-12-26 00:00 -------- d-----w- c:\programdata\TuneUp Software
2009-12-26 00:00 . 2009-12-26 00:00 -------- d-sh--w- c:\programdata\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-12-25 02:49 . 2009-12-25 02:49 8677824 ----a-w- c:\users\ugh\AppData\Roaming\Azureus\tmp\AZU8438693586728655215.tmp\Vuze_4.3.0.6b_win32.exe
2009-12-23 13:27 . 2009-12-25 23:58 -------- d-----w- c:\users\ugh\AppData\Roaming\runic games
2009-12-23 13:23 . 2009-12-25 23:58 -------- d-----w- c:\program files\Runic Games
2009-12-23 01:50 . 2009-12-26 00:55 -------- d-----w- c:\users\ugh\AppData\Local\Unity
2009-12-22 14:37 . 2009-12-26 00:00 -------- d-----w- c:\users\ugh\AppData\Local\TVersity
2009-12-15 22:28 . 2009-12-15 22:28 -------- d-----w- c:\programdata\Boss Media
2009-12-15 22:28 . 2009-12-15 22:28 -------- d-----w- c:\users\ugh\AppData\Local\Boss Media
2009-12-15 22:28 . 2009-12-15 22:29 -------- d-----w- c:\program files\OPoker.com
2009-12-14 16:36 . 2009-12-14 16:36 -------- d-----w- c:\program files\7-Zip
2009-12-14 16:03 . 2009-12-14 21:08 -------- d-----w- c:\program files\Common Files\Steam
2009-12-14 16:03 . 2010-01-03 04:22 -------- d-----w- c:\program files\Steam
2009-12-13 14:01 . 2009-12-13 14:01 -------- d-----w- c:\program files\Alcohol Soft
2009-12-13 11:12 . 2009-12-13 11:12 -------- d-----w- c:\users\ugh\AppData\Roaming\Nero
2009-12-13 11:08 . 2009-12-25 23:57 -------- d-----w- c:\programdata\Nero
2009-12-13 11:08 . 2009-12-25 23:57 -------- d-----w- c:\program files\Common Files\Nero
2009-12-13 10:47 . 2009-12-25 23:57 -------- d-----w- c:\program files\Nero
2009-12-13 10:37 . 2000-06-26 10:45 106496 ----a-w- c:\windows\system32\TwnLib20.dll
2009-12-13 10:37 . 2009-12-13 10:37 -------- d-----w- c:\program files\Common Files\Ahead
2009-12-13 10:37 . 2001-07-09 10:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
2009-12-13 10:37 . 2009-12-13 10:51 -------- d-----w- c:\program files\Ahead
2009-12-11 02:37 . 2009-12-11 02:37 -------- d-----w- c:\program files\CDisplay
2009-12-08 22:58 . 2009-12-25 23:49 -------- d-----w- c:\users\ugh\AppData\Roaming\Skype
2009-12-08 22:57 . 2009-12-08 22:57 -------- d-----w- c:\program files\Common Files\Skype
2009-12-08 22:57 . 2009-12-08 22:58 -------- d-----r- c:\program files\Skype
2009-12-08 22:57 . 2009-12-08 22:57 -------- d-----w- c:\programdata\Skype
2009-12-08 16:14 . 2009-12-08 16:19 -------- d-----w- c:\users\ugh\AppData\Roaming\Synthesia
2009-12-07 14:44 . 2010-01-03 14:29 -------- d-----w- c:\users\ugh\AppData\Local\PokerStars
2009-12-07 14:43 . 2009-12-23 00:59 -------- d-----w- c:\program files\PokerStars

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-03 16:56 . 2009-11-10 17:50 667824 ----a-w- c:\windows\system32\perfh013.dat
2010-01-03 16:56 . 2009-11-10 17:50 127002 ----a-w- c:\windows\system32\perfc013.dat
2010-01-03 16:52 . 2009-10-20 14:08 -------- d-----w- c:\programdata\NVIDIA
2010-01-03 16:52 . 2009-10-20 14:12 126071 ----a-w- c:\programdata\nvModes.dat
2010-01-03 16:49 . 2009-10-20 15:05 -------- d-----w- c:\users\ugh\AppData\Roaming\NoNameScript
2010-01-03 16:49 . 2009-10-20 16:40 -------- d-----w- c:\users\ugh\AppData\Roaming\vlc
2010-01-03 13:38 . 2009-10-20 15:05 -------- d-----w- c:\program files\mIRC
2009-12-29 16:04 . 2009-11-02 12:50 -------- d-----w- c:\users\ugh\AppData\Roaming\foobar2000
2009-12-28 00:01 . 2009-12-26 00:00 -------- d-----w- c:\program files\TuneUp Utilities 2010
2009-12-27 14:21 . 2009-10-31 20:54 -------- d-----w- c:\users\ugh\AppData\Roaming\dvdcss
2009-12-26 00:53 . 2009-12-13 12:24 -------- d-----w- c:\program files\Free Easy Burner
2009-12-26 00:47 . 2009-10-22 13:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-26 00:41 . 2009-10-21 14:34 -------- d-----w- c:\program files\Sports Interactive
2009-12-26 00:00 . 2009-12-26 00:00 -------- d-----w- c:\users\ugh\AppData\Roaming\TuneUp Software
2009-12-25 18:38 . 2009-10-20 17:36 862040 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-12-25 18:38 . 2009-10-20 17:36 206944 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-12-25 18:38 . 2009-10-20 17:36 390288 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-12-25 18:38 . 2009-10-20 17:36 537576 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-12-25 18:38 . 2009-10-20 17:36 370744 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-12-25 18:38 . 2009-10-20 17:36 194104 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2009-12-25 18:37 . 2009-10-27 18:37 6296864 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
2009-12-25 18:37 . 2009-10-20 17:35 933120 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-12-25 18:37 . 2009-10-20 17:35 816272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-12-25 18:37 . 2009-10-20 17:35 822904 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-12-25 18:37 . 2009-10-20 17:35 1643272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-12-25 18:37 . 2009-10-20 17:35 788880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-12-25 18:37 . 2009-10-20 17:35 1181328 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-12-25 02:50 . 2009-10-20 15:23 -------- d-----w- c:\users\ugh\AppData\Roaming\Azureus
2009-12-22 22:44 . 2009-12-22 22:44 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-12-15 23:52 . 2009-10-20 15:01 -------- d-----w- c:\users\ugh\AppData\Roaming\Microgaming
2009-12-15 18:03 . 2009-10-20 14:01 367832 ----a-w- c:\users\ugh\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-08 00:27 . 2009-10-20 17:12 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-03 00:18 . 2009-11-13 17:18 -------- d-----w- c:\program files\Everest Poker
2009-11-30 14:19 . 2009-11-30 14:19 -------- d-----w- c:\program files\Synthesia
2009-11-24 18:37 . 2009-10-20 17:36 163728 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-11-24 18:37 . 2009-10-20 17:35 327000 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-11-24 18:37 . 2009-10-20 17:35 87496 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-11-24 18:37 . 2009-10-20 17:35 641632 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-24 18:10 . 2009-11-24 18:09 -------- d-----w- c:\users\ugh\AppData\Roaming\Mobipocket
2009-11-13 01:04 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-11-12 13:50 . 2009-10-20 15:00 -------- d-----w- c:\programdata\Microsoft Help
2009-11-10 20:03 . 2009-11-10 20:03 -------- d-----w- c:\users\ugh\AppData\Roaming\postgresql
2009-11-10 17:54 . 2009-11-10 17:54 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-10 17:53 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-10 17:53 . 2009-11-10 17:53 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-10 17:50 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-11-10 17:50 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-11-10 17:50 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2009-11-10 17:50 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Journal
2009-11-10 17:50 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-11-10 17:50 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2009-11-10 17:49 . 2009-11-10 17:50 41976 ----a-w- c:\windows\system32\perfd013.dat
2009-11-10 17:49 . 2009-11-10 17:50 336440 ----a-w- c:\windows\system32\perfi013.dat
2009-11-10 17:49 . 2009-11-10 17:50 41976 ----a-w- c:\windows\inf\PERFLIB\0413\perfd.dat
2009-11-10 17:49 . 2009-11-10 17:50 41976 ----a-w- c:\windows\inf\PERFLIB\0413\perfc.dat
2009-11-10 17:49 . 2009-11-10 17:50 336440 ----a-w- c:\windows\inf\PERFLIB\0413\perfi.dat
2009-11-10 17:49 . 2009-11-10 17:50 336440 ----a-w- c:\windows\inf\PERFLIB\0413\perfh.dat
2009-11-08 11:44 . 2009-11-04 13:19 -------- d-----w- c:\users\ugh\AppData\Roaming\ISP Monitor
2009-11-06 20:36 . 2009-11-06 20:36 147456 ----a-w- c:\users\ugh\AppData\Roaming\Absolute Poker\DownLoad\liveupdate.exe
2009-11-06 20:35 . 2009-11-06 20:34 -------- d-----w- c:\users\ugh\AppData\Roaming\Absolute Poker
2009-11-06 18:40 . 2009-11-06 18:40 -------- d-----w- c:\programdata\WindowsSearch
2009-11-04 13:18 . 2009-11-04 13:18 737280 ----a-w- c:\windows\iun6002.exe
2009-11-02 19:42 . 2009-10-21 11:03 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-30 18:44 . 2009-10-27 18:37 212480 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2009-10-30 14:37 . 2009-10-30 14:37 61440 ----a-w- c:\programdata\MGS\cache\t\tikimaskbonusgame.0dc1c149f619ef0a72aacd3abdeb0dfb.dll
2009-10-30 14:37 . 2009-10-30 14:37 57344 ----a-w- c:\programdata\MGS\cache\v\volcanobonusgame.1f5cd5f4b800bd1a6e740e08a3119e10.dll
2009-10-30 14:37 . 2009-10-30 14:37 213089 ----a-w- c:\programdata\MGS\cache\b\bigkahuna.769fd4a48b95c8614a738f1cad88bcd5.dll
2009-10-30 14:37 . 2009-10-30 14:37 430352 ----a-w- c:\programdata\MGS\cache\s\simplepickxofyskillbonus.8d56aeea91f0d0bbdf41c578fbf38496.dll
2009-10-30 14:34 . 2009-10-30 14:34 376832 ----a-w- c:\programdata\MGS\cache\a\atlanticcityblackjack.9baef784fe666fb9d90dc331d0239eed.dll
2009-10-30 14:32 . 2009-10-30 14:32 233744 ----a-w- c:\programdata\MGS\cache\s\simplepickuntilbonus_temp.b6b7e588aedb05fa062fb8447406bca9.dll
2009-10-30 14:32 . 2009-10-30 14:32 495888 ----a-w- c:\programdata\MGS\cache\s\simplepickuntilbonus.aa7eb4e3b4774e5cad0d4f8562ca860d.dll
2009-10-30 14:32 . 2009-10-30 14:32 561424 ----a-w- c:\programdata\MGS\cache\s\simplepickuntilbonus_tggg.ca9a61a09a35dc0843cc68f532694746.dll
2009-10-30 14:32 . 2009-10-30 14:32 1056768 ----a-w- c:\programdata\MGS\cache\s\simplepickuntilbonus_flightzone.1f65e9ffaab494fa7dea6b149ec7a671.dll
2009-10-30 14:32 . 2009-10-30 14:32 290941 ----a-w- c:\programdata\MGS\cache\l\levelupvideopokerxxx.0d52d2ac00db83d9b97c99592ee3aa21.dll
2009-10-30 14:32 . 2009-10-30 14:32 139264 ----a-w- c:\programdata\MGS\cache\l\levelupvideopokerplugin.d3ee60c36507413ca9ab67247eac5288.dll
2009-10-30 14:32 . 2009-10-30 14:32 114688 ----a-w- c:\programdata\MGS\cache\l\levelupvideopokergambleplugin.d65fe35ffb2e6dc1b9ea46def3db39dc.dll
2009-10-30 14:32 . 2009-10-30 14:32 237840 ----a-w- c:\programdata\MGS\cache\p\powerpokersuite1_nl.cebfe8812d984716506c6d9d096a5f48.dll
2009-10-30 14:32 . 2009-10-30 14:32 217360 ----a-w- c:\programdata\MGS\cache\v\videopokersuite1.03dd648f567bef124a1d270ad208752a.dll
2009-10-30 14:32 . 2009-10-30 14:32 200704 ----a-w- c:\programdata\MGS\cache\3\3cardpoker.8e73a522a397f174eb628d05f72f1f40.dll
2009-10-30 14:30 . 2009-10-30 14:30 655360 ----a-w- c:\programdata\MGS\cache\t\transition_flightzone.2d8aa10da872f1ac4a34a2122bf3c4b2.dll
2009-10-30 14:30 . 2009-10-30 14:30 266512 ----a-w- c:\programdata\MGS\cache\t\transition_tggg.399218aff849d2e187d4554dd62a73b6.dll
2009-10-30 14:30 . 2009-10-30 14:30 262416 ----a-w- c:\programdata\MGS\cache\t\transition_temp.c6aaf42b66fa6688c8ea18a671984287.dll
2009-10-30 14:30 . 2009-10-30 14:30 679936 ----a-w- c:\programdata\MGS\cache\t\transition_wealthspa.5a3f4e96415d8b3050681cdd275f3d88.dll
2009-10-30 14:30 . 2009-10-30 14:30 679936 ----a-w- c:\programdata\MGS\cache\t\transition_septgao_09.04686bb06cfe59ecb3f271eb95218422.dll
2009-10-30 14:30 . 2009-10-30 14:30 421888 ----a-w- c:\programdata\MGS\cache\l\lua51host.65f8dee3181dee3bfc68ab23c9f2782b.dll
2009-10-30 14:30 . 2009-10-30 14:30 254224 ----a-w- c:\programdata\MGS\cache\t\transition.26c3e2ce55c7cca8b63e5e8d7b4627e4.dll
2009-10-30 14:30 . 2009-10-30 14:30 225280 ----a-w- c:\programdata\MGS\cache\m\myslot.14d73c530d6c095843c7fbfb86364c4e.dll
2009-10-30 14:30 . 2009-10-30 14:30 679936 ----a-w- c:\programdata\MGS\cache\t\transition_octgao_09.7768fe95f9efff3962c913196fe05f6a.dll
2009-10-30 14:30 . 2009-10-30 14:30 114960 ----a-w- c:\programdata\MGS\cache\t\type_5reelnormal3_4_5.07db0a5618a0565d7bde7a2766c54711.dll
2009-10-30 14:27 . 2009-10-30 14:27 327784 ----a-w- c:\programdata\MGS\cache\m\mpvtabletournamentlobby.fea1be7b63b308e9fdb6e8d4bd356052.dll
2009-10-30 14:27 . 2009-10-30 14:27 303204 ----a-w- c:\programdata\MGS\cache\m\mpvblackjackplugin.49e5f42fbdf0e1e2df5232e5ea419897.dll
2009-10-30 14:27 . 2009-10-30 14:27 311398 ----a-w- c:\programdata\MGS\cache\m\mpvblackjacktourxxx.e4ccb563efd75763602af7373fbd8cec.dll
2009-10-29 17:55 . 2009-10-29 17:55 24576 ----a-w- c:\users\ugh\AppData\Roaming\Mikogo\B-Capture.exe
2009-10-29 17:55 . 2009-10-29 17:55 185640 ----a-w- c:\users\ugh\AppData\Roaming\Mikogo\B-Service.exe
2009-10-29 17:54 . 2009-10-29 17:54 2748416 ----a-w- c:\users\ugh\AppData\Roaming\Mikogo\Mikogo-Host.exe
2009-10-29 17:54 . 2009-10-29 17:54 144688 ----a-w- c:\users\ugh\AppData\Roaming\Mikogo\remover.exe
2009-10-29 17:54 . 2009-10-29 17:54 1249280 ----a-w- c:\users\ugh\AppData\Roaming\Mikogo\SessionPlayer.exe
2009-10-29 09:17 . 2009-11-30 15:41 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-27 18:38 . 2009-10-27 18:38 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-10-27 18:38 . 2009-10-27 18:37 93360 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2009-12-14 1217808]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
UltraMon.lnk - c:\windows\Installer\{CC15A5FC-B6D3-4A2D-8A26-D8F2702A3C00}\IcoUltraMon.ico [2009-10-20 29310]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan.lnk
backup=c:\windows\pss\McAfee Security Scan.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 10:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 02:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
2007-07-17 09:03 868352 ------w- c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mikogo]
2009-10-29 17:54 2748416 ----a-w- c:\users\ugh\AppData\Roaming\Mikogo\Mikogo-Host.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-10-09 12:11 25623336 ----a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-20 15:21 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:21 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:23 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):18,aa,f7,f7,a9,ba,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-785287101-1414556579-2312349739-1000]
"EnableNotificationsRef"=dword:00000001

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [20/10/2009 18:36 64288]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [20/10/2009 18:12 108289]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 12:17 1181328]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [27/09/2009 15:48 240232]
R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [14/09/2008 16:32 10496]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [25/10/2009 18:31 721904]
S2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [13/03/2009 4:50 65536]
S3 B-Service;B-Service;c:\users\ugh\AppData\Roaming\Mikogo\B-Service.exe [29/10/2009 18:55 185640]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [21/01/2008 3:21 21504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
vvdsvc REG_MULTI_SZ vvdsvc
.
Inhoud van de 'Gedeelde Taken' map

2010-01-03 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:37]

2010-01-03 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:37]

2010-01-03 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:37]

2010-01-03 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:37]

2010-01-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:37]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2088433
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\ugh\AppData\Roaming\Mozilla\Firefox\Profiles\pic0qo2i.default\
FF - prefs.js: browser.startup.homepage - Google
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v2.01.01.
- - - - ORPHANS VERWIJDERD - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-AlcoholAutomount - c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe
MSConfigStartUp-SearchSettings - c:\program files\Search Settings\SearchSettings.exe
AddRemove-HijackThis - c:\users\ugh\Desktop\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2010-01-03 18:14
Windows 6.0.6002 Service Pack 2 NTFS

scannen van verborgen processen ...

scannen van verborgen autostart items ...

scannen van verborgen bestanden ...

Scan succesvol afgerond
verborgen bestanden: 0

**************************************************************************
.
Voltooingstijd: 2010-01-03 18:15:23
ComboFix-quarantined-files.txt 2010-01-03 17:15

Pre-Run: 20.475.351.040 bytes beschikbaar
Post-Run: 24.481.927.168 bytes beschikbaar

- - End Of File - - 70C23000884BC13ADD81D3D13E590312

Juisterr

Legacy Member
Klik met de rechtermuis op het programma Hijackthis en kies voor "Uitvoeren als Administrator"
Kies voor 'Do a system scan only'
Selecteer alleen de items die hieronder zijn genoemd:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}

O4 - Global Startup: UltraMon.lnk = ?

Klik op 'Fix checked' om de items te verwijderen.

Start hijackthis opnieuw en maak een nieuw HijackThis logje, let wel op want
je moet HijackThis als Administrator uitvoeren en dan de nieuwe log posten.
Indien je het niet als administrator uitvoert, wordt de oude log niet overschreven.


vertel even hoe het nu gaat

ugh

Legacy Member
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:03:21, on 8/01/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\ugh\AppData\Roaming\Mikogo\Mikogo-Host.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\ugh\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Mikogo] "C:\Users\ugh\AppData\Roaming\Mikogo\Mikogo-Host.exe"
O4 - HKUS\S-1-5-21-785287101-1414556579-2312349739-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'postgres')
O4 - HKUS\S-1-5-21-785287101-1414556579-2312349739-1001\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'postgres')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Play Poker - {00000000-0000-0000-0000-000000000000} - C:\MicroGaming\Poker\PokerShareMPP\MPPoker.exe (HKCU)
O9 - Extra button: Absolute Poker - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Users\ugh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Users\ugh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} (VodClient Control Class) - http://www.vexcast.com/download/vexcast.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: B-Service - Unknown owner - C:\Users\ugh\AppData\Roaming\Mikogo\B-Service.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 4671 bytes


Ik krijg nog steeds dezelfde crash als ik dit niet doe:
En na wat googlen ben ik op een (tijdelijke) oplossing gekomen. Als ik in configuratiescherm -mapopties -weergave ga, en dan het vakje 'altijd pictogrammen weegeven, nooit miniatuurweergaven' aanvink.
Dan krijg ik de error niet meer.

Juisterr

Legacy Member
Update je Windows eerst nu even en kijk dan of het is opgelost.

Vraag als het nog niet is opgelost de vraag even bij de Windows afdeling.
Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.
Terug
Bovenaan