Vraag & Antwoord

Beveiliging & privacy

Internet traag

12 antwoorden
  • Sinds enkele dagen is mijn Internet traag. Adaware en S&D geven niets bijzonders. Is er iets bijzonders te zien in bijgevoegd log? Dank, Maarten [list:2f5b03f492] Logfile of HijackThis v1.99.1 Scan saved at 21:26:56, on 17-8-2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe C:\Program Files\Analog Devices\SoundMAX\Smtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\tppaldr.exe C:\Program Files\Nuria\Nuria.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~2\SYMANT~2\VPTray.exe C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ATWTUSB.EXE C:\Program Files\SpeedFan\speedfan.exe C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE C:\Program Files\Lavalys\EVEREST Home Edition\everest.bin C:\Program Files\Internet Explorer\iexplore.exe F:\Downloads\Hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [anvshell] anvshell.exe O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe O4 - HKLM\..\Run: [Nuria] C:\Program Files\Nuria\Nuria.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\SYMANT~2\VPTray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Atwtusb] RUNDLL32 FuncKey.DLL,ExtFuncCall AA O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Nuria] C:\Program Files\Nuria\Nuria.exe O4 - Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1092998101859 O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.hema.nl/site/xupload/XUpload.ocx O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe [/list:u:2f5b03f492]
  • Download [url=ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe][b:a65e78bec3][color=blue:a65e78bec3]Dr.Web CureIt[/color:a65e78bec3][/b:a65e78bec3][/url] naar je Bureaublad:[list:a65e78bec3][*:a65e78bec3]Dubbelklik [b:a65e78bec3]drweb-cureit.exe[/b:a65e78bec3] en sta het toe om de express scan te starten. [*:a65e78bec3]Dit zal de bestanden scannen die momenteel in het geheugen geladen zijn en wanneer er iets gevonden wordt, klik de [b:a65e78bec3]Yes to all[/b:a65e78bec3] knop bij de vraag 'cure it?'. Dit is enkel een korte scan. [*:a65e78bec3]Eenmaal de korte scan is beeïndigd, kan je de drives selecteren die je wilt laten scannen. [*:a65e78bec3]Selecteer hier [b:a65e78bec3]alle drives[/b:a65e78bec3]. Een rood bolletje zal dan tevoorschijn komen op de drives die je laat scannen. [*:a65e78bec3]Klik daarna de [b:a65e78bec3]groene pijl[/b:a65e78bec3] rechts om de scan te starten. [*:a65e78bec3]Klik [b:a65e78bec3]Yes to all[/b:a65e78bec3] wanneer er gevraagd wordt om cure of move uit te voeren. [*:a65e78bec3]Wanneer de scan beëindigd is, kijk of je kunt op het icoontje naast de gevonden bestanden klikken: [img:a65e78bec3]http://users.telenet.be/bluepatchy/miekiemoes/images/check.gif[/img:a65e78bec3] [*:a65e78bec3]Indien ja,klik er op en klik vervolgens op het icoontje er juist onder en selecteer [b:a65e78bec3]Move incurable[/b:a65e78bec3] zoals je hier ziet: [img:a65e78bec3]http://users.telenet.be/bluepatchy/miekiemoes/images/move.gif[/img:a65e78bec3] Dit verplaatst gevonden bestanden naar de "%userprofile%\DoctorWeb\quarantaine-map" indien herstel niet mogelijk is. [*:a65e78bec3]Nadat de scan gedaan is, in het menu bovenaan, klik [b:a65e78bec3]File[/b:a65e78bec3] en kies [b:a65e78bec3]Save report List[/b:a65e78bec3]. Bewaar het op je Bureaublad. [*:a65e78bec3]Sluit daarna Dr.Web Cureit. [*:a65e78bec3][b:a65e78bec3]Herstart[/b:a65e78bec3] je computer!! [i:a65e78bec3]Belangrijke stap, want het kan zijn dat Dr.Web Cureit bestanden zal verplaatsen/verwijderen tijdens herstart[/i:a65e78bec3]. [*:a65e78bec3]Na het herstarten, [b:a65e78bec3]kopieer en plak de inhoud van die log die je eerder hebt bewaard in je volgende post[/b:a65e78bec3]. [/list:u:a65e78bec3]
  • Drie dingen gesignaleerd. Hierbij het Log. [list:6247d73f54]regLocal.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups;Probably SCRIPT.Virus;Incurable.Moved.; foto.exe;C:\Documents and Settings\Joyce\My Documents\My Received Files;Joke.Justgame;Incurable.Moved.; [/list:u:6247d73f54] Groet, Maarten PS hebben jullie ervaring met het programma Azureus. Kan dit de bron zijn?
  • Ik heb geen ervaring met azureus, wil je nog een nieuw HJT logje plaatsen aub.
  • De gevraagde HJT [list:2c24119d88] Logfile of HijackThis v1.99.1 Scan saved at 11:39:01, on 20-8-2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Analog Devices\SoundMAX\Smtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\tppaldr.exe C:\Program Files\Nuria\Nuria.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~2\SYMANT~2\VPTray.exe C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\SpeedFan\speedfan.exe C:\WINDOWS\system32\ATWTUSB.EXE C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe F:\Downloads\Hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [anvshell] anvshell.exe O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe O4 - HKLM\..\Run: [Nuria] C:\Program Files\Nuria\Nuria.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\SYMANT~2\VPTray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Atwtusb] RUNDLL32 FuncKey.DLL,ExtFuncCall AA O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Nuria] C:\Program Files\Nuria\Nuria.exe O4 - Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1092998101859 O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.hema.nl/site/xupload/XUpload.ocx O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe [/list:u:2c24119d88]
  • Probeer onderstaande eens uit te voeren aub. * [u:6c52281051]Clean de Cache and Cookies in [color=blue:6c52281051]IE[/color:6c52281051][/u:6c52281051]:[list:6c52281051][*:6c52281051][b:6c52281051]Sluit[/b:6c52281051] Internet Explorer. [*:6c52281051]Ga naar Configuratiescherm > Internet Opties > tab Algemeen [*:6c52281051]Klik de [b:6c52281051]Cookies verwijderen[/b:6c52281051] knop [*:6c52281051]Klik op de [b:6c52281051]Bestanden verwijderen[/b:6c52281051] knop ernaast [*:6c52281051][b:6c52281051]Vink aan[/b:6c52281051]: Ook alle off line items verwijderen, klik OK[/list:u:6c52281051]* [u:6c52281051]Clean de Cache and Cookies in [color=blue:6c52281051]Firefox[/color:6c52281051][/u:6c52281051] (In geval Firefox geïnstalleerd is):[list:6c52281051][*:6c52281051]Go to Extra > Opties. [*:6c52281051]Klik [b:6c52281051]Privacy[/b:6c52281051] in het menu. [*:6c52281051]Klik op de knop [b:6c52281051]Wissen[/b:6c52281051] (Geschiedenis, Cookies, Cache). [*:6c52281051]Klik OK om het venster opnieuw te sluiten.[/list:u:6c52281051] * [u:6c52281051]Clean [color=blue:6c52281051]andere Temporary files + Prullenbak[/color:6c52281051][/u:6c52281051][list:6c52281051][*:6c52281051]Ga naar Start > Uitvoeren en typ: [b:6c52281051]cleanmgr[/b:6c52281051] en klik ok. [*:6c52281051]Laat het je systeem scannen op bestanden die moeten verwijderd worden [*:6c52281051]Zorg er wel voor dat je daar [b:6c52281051]enkel[/b:6c52281051] maar 'tijdelijke bestanden', 'tijdelijke internetbestanden' en 'prullenbak' staan aangevinkt. [*:6c52281051]Klik daarna op OK.[/list:u:6c52281051] Download [url=http://download.bleepingcomputer.com/sUBs/combofix.exe][b:6c52281051]Combofix[/b:6c52281051][/url] naar je Bureaublad.[list:6c52281051] Dubbelklik [b:6c52281051]Combofix.exe[/b:6c52281051] Volg de instructies, aanvaard de disclaimer door "y" of "Y" te typen. Tijdens het runnen van de fix, [b:6c52281051]NIET[/b:6c52281051] in het venster klikken, want dit zal je pc doen vasthangen.[/list:u:6c52281051] Wanneer de fix voltooid is en na herstart, zal de log [b:6c52281051]combofix.txt[/b:6c52281051] openen. [i:6c52281051]Plaats deze log in je volgende post samen met een nieuw HijackThis log.[/i:6c52281051] NOTA: Indien je virusscanner reageert met een melding van een scriptuitvoering, mag je dit negeren.
  • Gevraagde instructie succesvol uitgevoerd. Bij Combofix kreeg ik meteen een log zonder reboot. Heb voor de zekerheid nogmaals een restart gedaan. Hierbij het Combolog en een HJlog. EDIT Ik zie nog wel wat resten staan van mijn oude zonelab firewall. Deze heb ik verwijderd omdat ik Symantec heb geïnstalleerd. Kan ik die verwijderen? EDIT Maarten Combo [list:d6f216adb1] buikhuisen - 06-08-20 21:14:40,98 ComboFix 06.08.18 - Running from: F:\Downloads\Hijackthis ((((((((((((((((((((((((((((((( Files Created from 2006-07-20 to 2006-08-20 )))))))))))))))))))))))))))))))))) 2006-08-13 15:15 93 C:\WINDOWS\Info.Com 2006-08-13 15:15 53,728 C:\WINDOWS\rmfile.exe 2006-08-13 15:15 43,664 C:\WINDOWS\addrun.exe 2006-08-13 15:08 917,504 C:\WINDOWS\system32\TblRes.dll 2006-08-13 15:08 77,824 C:\WINDOWS\system32\wintab32.dll 2006-08-13 15:08 73,728 C:\WINDOWS\RmTablet.exe 2006-08-13 15:08 61,440 C:\WINDOWS\system32\tblmouse.exe 2006-08-13 15:08 57,344 C:\WINDOWS\system32\TBLFUNC.DLL 2006-08-13 15:08 57,344 C:\WINDOWS\system32\Funckey.dll 2006-08-13 15:08 40,960 C:\WINDOWS\system32\tbltinst.dll 2006-08-13 15:08 36,864 C:\WINDOWS\system32\utblfilt.dll 2006-08-13 15:08 188,416 C:\WINDOWS\system32\atwtusb.exe (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-08-20 21:00 -------- d-------- C:\Program Files\Common Files\Symantec Shared 2006-08-20 20:34 -------- d-------- C:\Program Files\SpeedFan 2006-08-14 18:00 -------- d-------- C:\Program Files\Azureus 2006-08-13 21:40 -------- d-------- C:\Program Files\PENSOFT 2006-08-13 15:15 93 --a------ C:\WINDOWS\Info.Com 2006-08-13 15:15 53728 --a------ C:\WINDOWS\rmfile.exe 2006-08-13 15:15 43664 --a------ C:\WINDOWS\addrun.exe 2006-08-13 12:43 -------- d-------- C:\Program Files\Internet Explorer 2006-07-27 15:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll 2006-07-21 10:24 72704 --a------ C:\WINDOWS\system32\hlink.dll 2006-07-16 13:50 -------- d---s---- C:\Documents and Settings\buikhuisen\Application Data\Microsoft 2006-07-16 12:10 -------- d--h----- C:\Program Files\InstallShield Installation Information 2006-07-16 12:09 -------- d-------- C:\Program Files\QuickTime 2006-07-09 12:36 -------- d-------- C:\Program Files\Java 2006-07-09 12:35 -------- d-a------ C:\Program Files\Common Files 2006-07-09 12:35 -------- d-------- C:\Program Files\Common Files\Java 2006-06-30 18:04 -------- d-------- C:\Program Files\Canon 2006-06-30 09:07 -------- d-------- C:\Program Files\Nuria 2006-06-30 09:00 -------- d-------- C:\Program Files\Symantec_Client_Security 2006-06-30 08:56 -------- d-------- C:\Program Files\Symantec 2006-06-30 08:55 -------- d-------- C:\Program Files\Symantec Client Security 2006-06-30 08:55 -------- d-------- C:\Program Files\Common Files\Microsoft Shared 2006-05-28 17:08 25992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Smapp"="C:\\Program Files\\Analog Devices\\SoundMAX\\Smtray.exe" "NeroCheck"="C:\\WINDOWS\\System32\\NeroCheck.exe" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "anvshell"="anvshell.exe" "iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe" "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "TPP Auto Loader"="C:\\WINDOWS\\tppaldr.exe" "Nuria"="C:\\Program Files\\Nuria\\Nuria.exe" "nwiz"="nwiz.exe /install" "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "vptray"="C:\\PROGRA~1\\SYMANT~2\\SYMANT~2\\VPTray.exe" "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_07\\bin\\jusched.exe" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "Atwtusb"="RUNDLL32 FuncKey.DLL,ExtFuncCall AA" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "Nuria"="C:\\Program Files\\Nuria\\Nuria.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000004 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\ 00,00,01,00,00,00 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce] "RunNarrator"="Narrator.exe" [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce] "RunNarrator"="Narrator.exe" [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" ~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ backup-20060528-103235-174 O20 - Winlogon Notify: winpdc32 - winpdc32.dll (file missing) backup-20060528-103235-845 O16 - DPF: {00000000-0000-0000-0000-100000000003} - http://code.jcash.biz/l/ddb5c5ccea4ef98dda0b765d4a93712e_13.exe backup-20060528-103235-961 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = backup-20050217-205908-259 O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite K++\kpp.exe" "C:\Program Files\Kazaa Lite K++\KazaaLite.kpp" /SYSTRAY backup-20050215-221654-898 O2 - BHO: (no name) - {7C0D0F1A-AA1F-4F43-94EC-3F88651C8C7F}} - (no file) backup-20050215-220524-837 O4 - HKCU\..\RunServices: [win-xp] winis.exe backup-20050215-220524-442 O4 - HKCU\..\Run: [win-xp] winis.exe backup-20050215-220524-662 O4 - HKLM\..\RunServices: [win-xp] winis.exe backup-20050215-220524-152 O4 - HKLM\..\Run: [win-xp] winis.exe backup-20050215-212922-510 O4 - HKCU\..\RunServices: [win-xp] winis.exe backup-20050215-212922-335 O4 - HKLM\..\RunServices: [win-xp] winis.exe backup-20050215-212922-115 O4 - HKCU\..\Run: [win-xp] winis.exe backup-20050215-212922-418 O4 - HKLM\..\Run: [win-xp] winis.exe backup-20041016-200145-163 O2 - BHO: (no name) - {7C0D0F1A-AA1F-4F43-94EC-3F88651C8C7F}} - (no file) Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\Symantec NetDetect.job Completion time: Sun 20-08-2006 21:15:19.82 ComboFix.txt [/list:u:d6f216adb1] HiJack [list:d6f216adb1] Logfile of HijackThis v1.99.1 Scan saved at 21:18:24, on 20-8-2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Analog Devices\SoundMAX\Smtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\tppaldr.exe C:\Program Files\Nuria\Nuria.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~2\SYMANT~2\VPTray.exe C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\WINDOWS\system32\ATWTUSB.EXE C:\Program Files\SpeedFan\speedfan.exe C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe F:\Downloads\Hijackthis\HijackThis.exe C:\WINDOWS\system32\wuauclt.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [anvshell] anvshell.exe O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe O4 - HKLM\..\Run: [Nuria] C:\Program Files\Nuria\Nuria.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\SYMANT~2\VPTray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Atwtusb] RUNDLL32 FuncKey.DLL,ExtFuncCall AA O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Nuria] C:\Program Files\Nuria\Nuria.exe O4 - Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1092998101859 O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.hema.nl/site/xupload/XUpload.ocx O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe [/list:u:d6f216adb1]
  • Ja dat is goed, je logje is schoon, klachten ook over??
  • Klachten lijken inderdaad voorbij. Hiervoor mijn dank. Nog suggesties voor het verwijderen van de resten van Zone alarm? Groet, Maarten
  • Download [url=http://www.ccleaner.com/]Ccleaner[/url] update hem en doe een scan (aan de linkerkant staan icoons, eerst die met het stoffertje doen, laat hem scannen en doe daarna opschonen, twee keer opschonen) Daaronder staat een icoon met problemen, klik die aan en doe een scan, klik op fouten reparen (indien fouten aanwezig) en maak een backupmapje op je pc. Leeg je temp-mappen ( [color=blue:924693b19e]NB de mappen leegmaken, niet verwijderen[/color:924693b19e] !): C:\Documents and Settings\<Gebruikersnaam>\Local Settings\ [b:924693b19e]Temp [/b:924693b19e] C:\Documents and Settings\gebruikersnaam\Local Settings\[b:924693b19e]Temporary [/b:924693b19e][b:924693b19e]Internet Files[/b:924693b19e] C:\Documents and Settings\gebruikersnaam\Local Settings\[b:924693b19e]Temporary [/b:924693b19e][b:924693b19e]Internet Files\content.ie5[/b:924693b19e] Als deze map niet wordt weergegeven, ga dan naar de map temporary internet files en type er [b:924693b19e]\content.ie5[/b:924693b19e] achter in de adresbalk en klik enter. C:\Windows\[b:924693b19e]Temp[/b:924693b19e]
  • Ok, uitgevoerd. Ik dacht overigens dat CCleaner automatisch je tijdelijke Internetmappen verwijderde. Maar helaas. [quote:a21298be39]het verwijderen van de resten van Zone alarm? [/quote:a21298be39] Nog suggesties? Dank, Maarten
  • [quote:e5f25cfbf5="Maarten60"]Ok, uitgevoerd. Ik dacht overigens dat CCleaner automatisch je tijdelijke Internetmappen verwijderde. Maar helaas. [quote:e5f25cfbf5]het verwijderen van de resten van Zone alarm? [/quote:e5f25cfbf5] Nog suggesties? Dank, Maarten[/quote:e5f25cfbf5] tja dan moet je die functie wel aanvinken natuurlijk. * [u:e5f25cfbf5]Clean de Cache and Cookies in [color=blue:e5f25cfbf5]IE[/color:e5f25cfbf5][/u:e5f25cfbf5]:[list:e5f25cfbf5][*:e5f25cfbf5][b:e5f25cfbf5]Sluit[/b:e5f25cfbf5] Internet Explorer. [*:e5f25cfbf5]Ga naar Configuratiescherm > Internet Opties > tab Algemeen [*:e5f25cfbf5]Klik de [b:e5f25cfbf5]Cookies verwijderen[/b:e5f25cfbf5] knop [*:e5f25cfbf5]Klik op de [b:e5f25cfbf5]Bestanden verwijderen[/b:e5f25cfbf5] knop ernaast [*:e5f25cfbf5][b:e5f25cfbf5]Vink aan[/b:e5f25cfbf5]: Ook alle off line items verwijderen, klik OK[/list:u:e5f25cfbf5]* [u:e5f25cfbf5]Clean de Cache and Cookies in [color=blue:e5f25cfbf5]Firefox[/color:e5f25cfbf5][/u:e5f25cfbf5] (In geval Firefox geïnstalleerd is):[list:e5f25cfbf5][*:e5f25cfbf5]Go to Extra > Opties. [*:e5f25cfbf5]Klik [b:e5f25cfbf5]Privacy[/b:e5f25cfbf5] in het menu. [*:e5f25cfbf5]Klik op de knop [b:e5f25cfbf5]Wissen[/b:e5f25cfbf5] (Geschiedenis, Cookies, Cache). [*:e5f25cfbf5]Klik OK om het venster opnieuw te sluiten.[/list:u:e5f25cfbf5] * [u:e5f25cfbf5]Clean [color=blue:e5f25cfbf5]andere Temporary files + Prullenbak[/color:e5f25cfbf5][/u:e5f25cfbf5][list:e5f25cfbf5][*:e5f25cfbf5]Ga naar Start > Uitvoeren en typ: [b:e5f25cfbf5]cleanmgr[/b:e5f25cfbf5] en klik ok. [*:e5f25cfbf5]Laat het je systeem scannen op bestanden die moeten verwijderd worden [*:e5f25cfbf5]Zorg er wel voor dat je daar [b:e5f25cfbf5]enkel[/b:e5f25cfbf5] maar 'tijdelijke bestanden', 'tijdelijke internetbestanden' en 'prullenbak' staan aangevinkt. [*:e5f25cfbf5]Klik daarna op OK.[/list:u:e5f25cfbf5]

Beantwoord deze vraag

Weet jij het antwoord op deze vraag? Registreer of meld je aan met je account

Dit is een gearchiveerde pagina. Antwoorden is niet meer mogelijk.