ja ik kan wel een hijackthis logje maken.. is het goed als ik dat straks doe? ik moet nu werken, ben rond 8 thuis.
ik zal alvast het hijackthislogje maken, dan kun je alvast kijken
er is alleen 1 probleem... heb bestand "hosts" word geblokkeerd, hijackthis pakt 'm niet
(Bestands locatie: "C:\windows\system32\drivers\etc\hosts")
[hjt]
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:51:53, on 14-10-2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
c:\windows\system32\taskeng.exe
c:\windows\explorer.exe
c:\program files\windows defender\msascui.exe
c:\windows\rthdvcpl.exe
c:\acer\empowering technology\edatasecurity\edsloader.exe
c:\program files\itunes\ituneshelper.exe
c:\program files\canon\myprinter\bjmyprt.exe
c:\program files\scansoft\omnipagese4\opwarese4.exe
c:\program files\java\jre1.6.0_07\bin\jusched.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\windows media player\wmpnscfg.exe
c:\program files\nero\nero 7\incd\nbhgui.exe
c:\program files\nero\nero 7\incd\incd.exe
c:\windows\system32\rundll32.exe
c:\program files\common files\ahead\lib\nmbgmonitor.exe
c:\windows\ehome\ehtray.exe
c:\program files\acer arcade live\acer homemedia connect\kernel\dms\pcmmediasharing.exe
c:\windows\ehome\ehmsas.exe
c:\program files\common files\ahead\lib\nmindexstoresvr.exe
c:\program files\eset\nod32kui.exe
c:\program files\internet explorer\ieuser.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\trend micro\hijackthis\hijackthis.exe
c:\windows\system32\searchfilterhost.exe
r1 - hkcu\software\microsoft\internet explorer\main,search page =
[noparse]http://go.microsoft.com/fwlink/?linkid=54896[/noparse]
r0 - hkcu\software\microsoft\internet explorer\main,start page =
[noparse]http://www.google.nl/[/noparse]
r1 - hklm\software\microsoft\internet explorer\main,default_page_url =
[noparse]http://nl.intl.acer.yahoo.com[/noparse]
r1 - hklm\software\microsoft\internet explorer\main,default_search_url =
[noparse]http://go.microsoft.com/fwlink/?linkid=54896[/noparse]
r1 - hklm\software\microsoft\internet explorer\main,search page =
[noparse]http://go.microsoft.com/fwlink/?linkid=54896[/noparse]
r0 - hklm\software\microsoft\internet explorer\main,start page =
r0 - hklm\software\microsoft\internet explorer\search,searchassistant =
r0 - hklm\software\microsoft\internet explorer\search,customizesearch =
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = *.local
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername =
o1 - hosts: ::1 localhost
o2 - bho: yahoo! toolbar helper -
{02478d38-c3f9-4efb-9b51-7695eca05670} -
c:\program files\yahoo!\companion\installs\cpn\yt.dll
o2 - bho: adobe pdf reader link helper -
{06849e9f-c8d7-4d59-b87d-784b7d6be0b3} -
c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
o2 - bho: skype add-on (mastermind) -
{22bf413b-c6d2-4d91-82a9-a0f997ba588c} -
c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
o2 - bho: realplayer download and record plugin for internet explorer -
{3049c3e9-b461-4bc5-8870-4c09146192ca} -
c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: ssvhelper class -
{761497bb-d6f0-462c-b6eb-d4daf1d92d43} -
c:\program files\java\jre1.6.0_07\bin\ssv.dll
o2 - bho: (no name) -
{7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
o2 - bho: showbarobj class -
{83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} -
c:\windows\system32\activetoolband.dll
o2 - bho: windows live aanmelden - help -
{9030d464-4c02-4abf-8ecc-5164760863c6} -
c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: google toolbar helper -
{aa58ed58-01dd-4d91-8333-cf10577473f7} -
c:\program files\google\googletoolbar1.dll
o3 - toolbar: acer edatasecurity management -
{5cbe3b7c-1e47-477e-a7dd-396db0476e29} -
c:\windows\system32\edstoolbar.dll
o3 - toolbar: yahoo! toolbar -
{ef99bd32-c1fb-11d2-892f-0090271d4f88} -
c:\program files\yahoo!\companion\installs\cpn\yt.dll
o3 - toolbar: &google -
{2318c2b1-4965-11d4-9b18-009027a5cd4f} -
c:\program files\google\googletoolbar1.dll
o3 - toolbar: bs.player controlbar -
{2c688203-7eb3-4327-9995-1cb417ba23f9} -
c:\program files\bs.player controlbar\bstoolbar.dll
o4 - hklm\..\run:
[windows defender] %programfiles%\windows defender\msascui.exe -hide
o4 - hklm\..\run:
[rthdvcpl] rthdvcpl.exe
o4 - hklm\..\run:
[edatasecurity loader] c:\acer\empowering technology\edatasecurity\edsloader.exe
o4 - hklm\..\run:
[skytel] skytel.exe
o4 - hklm\..\run:
[warreg_popup] c:\acer\wr_popup\warreg_popup.exe
o4 - hklm\..\run:
[quicktime task] c:\program files\quicktime\qttask.exe -atboottime
o4 - hklm\..\run:
[ituneshelper] c:\program files\itunes\ituneshelper.exe
o4 - hklm\..\run:
[canonsolutionmenu] c:\program files\canon\solutionmenu\cnslmain.exe /logon
o4 - hklm\..\run:
[canonmyprinter] c:\program files\canon\myprinter\bjmyprt.exe /logon
o4 - hklm\..\run:
[ssbkgdupdate] c:\program files\common files\scansoft shared\ssbkgdupdate\ssbkgdupdate.exe -embedding -boot
o4 - hklm\..\run:
[opwarese4] c:\program files\scansoft\omnipagese4\opwarese4.exe
o4 - hklm\..\run:
[sunjavaupdatesched] c:\program files\java\jre1.6.0_07\bin\jusched.exe
o4 - hklm\..\run:
[tkbellexe] c:\program files\common files\real\update_ob\realsched.exe -osboot
o4 - hklm\..\run:
[pc suite for smartphones] c:\program files\sony ericsson\mobile4\application launcher\application launcher.exe /startoptions
o4 - hklm\..\run:
[msconfig] c:\windows\system32\msconfig.exe /auto
o4 - hklm\..\run:
[nerofiltercheck] c:\program files\common files\ahead\lib\nerocheck.exe
o4 - hklm\..\run:
[securdisc] c:\program files\nero\nero 7\incd\nbhgui.exe
o4 - hklm\..\run:
[incd] c:\program files\nero\nero 7\incd\incd.exe
o4 - hklm\..\run:
[nod32kui] c:\program files\eset\nod32kui.exe /waitservice
o4 - hklm\..\run:
[nvcpldaemon] rundll32.exe
c:\windows\system32\nvcpl.dll,nvstartup
o4 - hklm\..\run:
[nvmediacenter] rundll32.exe
c:\windows\system32\nvmctray.dll,nvtaskbarinit
o4 - hkcu\..\run:
[bgmonitor_{79662e04-7c6c-4d9f-84c7-88d8a56b10aa}] c:\program files\common files\ahead\lib\nmbgmonitor.exe
o4 - hkcu\..\run:
[ehtray.exe] c:\windows\ehome\ehtray.exe
o4 - hkcu\..\run:
[wmpnscfg] c:\program files\windows media player\wmpnscfg.exe
o4 - hkus\s-1-5-19\..\run:
[sidebar] %programfiles%\windows sidebar\sidebar.exe /detectmem (user 'local service')
o4 - hkus\s-1-5-19\..\run:
[windowswelcomecenter] rundll32.exe oobefldr.dll,showwelcomecenter (user 'local service')
o4 - hkus\s-1-5-20\..\run:
[sidebar] %programfiles%\windows sidebar\sidebar.exe /detectmem (user 'network service')
o4 - hkus\s-1-5-18\..\run:
[acer tour reminder] c:\acer\acertour\reminder.exe (user 'systeem')
o4 - hkus\.default\..\run:
[acer tour reminder] c:\acer\acertour\reminder.exe (user 'default user')
o4 - global startup: adobe gamma loader.lnk =
c:\program files\common files\adobe\calibration\adobe gamma loader.exe
o4 - global startup: adobe reader snelle start.lnk =
c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
o4 - global startup: pcm media sharing.lnk =
c:\program files\acer arcade live\acer homemedia connect\kernel\dms\pcmmediasharing.exe
o9 - extra button: (no name) -
{08b0e5c0-4fcb-11cf-aaa5-00401c608501} -
c:\progra~1\java\jre16~2.0_0\bin\ssv.dll
o9 - extra 'tools' menuitem: sun java console -
{08b0e5c0-4fcb-11cf-aaa5-00401c608501} -
c:\progra~1\java\jre16~2.0_0\bin\ssv.dll
o9 - extra button: verzenden naar onenote -
{2670000a-7350-4f3c-8081-5663ee0c6c49} -
c:\progra~1\micros~2\office12\onbttnie.dll
o9 - extra 'tools' menuitem: verz&enden naar onenote -
{2670000a-7350-4f3c-8081-5663ee0c6c49} -
c:\progra~1\micros~2\office12\onbttnie.dll
o9 - extra button: skype -
{77bf5300-1474-4ec7-9980-d32b190e9b07} -
c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
o9 - extra button: research -
{92780b25-18cc-41c8-b9be-3c9c571a8263} -
c:\progra~1\micros~2\office12\refiebar.dll
o13 - gopher prefix:
o18 - protocol: skype4com -
{ffc8b962-9b40-4dff-9458-1830c7dd7f5d} -
c:\progra~1\common~1\skype\skype4~1.dll
o23 - service: acer homemedia connect service - cyberlink -
c:\program files\acer arcade live\acer homemedia connect\kernel\dms\clmsserver.exe
o23 - service: eperformance service (acermemusagecheckservice) - unknown owner -
c:\acer\empowering technology\eperformance\memcheck.exe
o23 - service: apple mobile device - apple, inc. -
c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
o23 - service: ati external event utility - ati technologies inc. -
c:\windows\system32\ati2evxx.exe
o23 - service: bonjour-service (bonjour service) - apple inc. -
c:\program files\bonjour\mdnsresponder.exe
o23 - service: symantec lic netconnect service (cltnetcnservice) - unknown owner -
c:\program files\common files\symantec shared\ccsvchst.exe (file missing)
o23 - service: edsservice.exe (edatasecurity service) - hitrsut -
c:\acer\empowering technology\edatasecurity\edsservice.exe
o23 - service: erecovery service (erecoveryservice) - acer inc. -
c:\acer\empowering technology\erecovery\erecoveryservice.exe
o23 - service: flexnet licensing service - macrovision europe ltd. -
c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe
o23 - service: google updater service (gusvc) - google -
c:\program files\google\common\google updater\googleupdaterservice.exe
o23 - service: pixma extended survey program (ijplmsvc) - unknown owner -
c:\program files\canon\ijplm\ijplmsvc.exe
o23 - service: incd helper (incdsrv) - nero ag -
c:\program files\nero\nero 7\incd\incdsrv.exe
o23 - service: ipod-service (ipod service) - apple inc. -
c:\program files\ipod\bin\ipodservice.exe
o23 - service: lightscribeservice direct disc labeling service (lightscribeservice) - hewlett-packard company -
c:\program files\common files\lightscribe\lssrvc.exe
o23 - service: nbservice - nero ag -
c:\program files\nero\nero 7\nero backitup\nbservice.exe
o23 - service: nmindexingservice - nero ag -
c:\program files\common files\ahead\lib\nmindexingservice.exe
o23 - service: nod32 kernel service (nod32krn) - eset -
c:\program files\eset\nod32krn.exe
o23 - service: nvidia display driver service (nvsvc) - nvidia corporation -
c:\windows\system32\nvvsvc.exe
o23 - service: pnkbstra - unknown owner -
c:\windows\system32\pnkbstra.exe
o23 - service: cyberlink richvideo service(crvs) (richvideo) - unknown owner -
c:\program files\cyberlink\shared files\richvideo.exe
o23 - service: steam client service - valve corporation -
c:\program files\common files\steam\steamservice.exe
--
end of file - 10404 bytes
[/hjt]