Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 19:42:58, on 26-12-2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Common
Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\Java\jre6\bin\jqs.exe
C:\WINDOWS\SysWOW64\PSIService.exe
C:\WINDOWS\SysWOW64\ctfmon.exe
C:\Program Files (x86)\DNA\btdna.exe
C:\Documents and Settings\Administrator\Local
Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Documents and Settings\Administrator\Local
Settings\Application
Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\Program Files (x86)\Common
Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files (x86)\Adobe\Acrobat
7.0\Reader\reader_sl.exe
C:\Program Files (x86)\ArcSoft\TotalMedia
3.5\TMMonitor.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files (x86)\Marktplaats
Zoekassistent\Marktplaats.exe
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
C:\Program Files (x86)\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files (x86)\Common
Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files (x86)\CyberLink\PowerDVD\PowerDVD.exe
C:\Program Files (x86)\Common
Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files (x86)\Labtec\WebCam10\WebCam10.exe
C:\Program Files (x86)\OpenOffice.org
3\program\soffice.exe
C:\Program Files (x86)\Creative\SB Live! 24-bit\Surround
Mixer\CTSysVol.exe
C:\Program Files
(x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files
(x86)\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files (x86)\Common
Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files (x86)\Common
Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection
Service\Bin\ACDaemon.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection
Service\Bin\ACService.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection
Service\Bin\ArcCon.ac
C:\Program Files (x86)\OpenOffice.org
3\program\soffice.bin
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files
(x86)\TrendMicro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page =
http://www.nos.nl/nos/voorpagina/
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start
Page =
http://www.duxet.com/
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F3 - REG:win.ini: load=
F3 - REG:win.ini: run=
F2 - REG:system.ini: UserInit=userinit
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files
(x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for
Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA}
- c:\program
files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) -
{78875F5C-A685-4405-8DC5-D48DC65452B0} - (no file)
O2 - BHO: (no name) -
{D032570A-5F63-4812-A094-87D007C23012} -
C:\PROGRA~2\PRIVAC~1\tools\sp\spbho.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper -
{DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files
(x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl -
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files
(x86)\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Cooliris Plug-In for Internet Explorer -
{EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files
(x86)\PicLensIE\cooliris.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files
(x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files
(x86)\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [JMB36X Configure]
C:\WINDOWS\SysWOW64\JMRaidTool.exe boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files
(x86)\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [PowerDVD] "C:\Program Files
(x86)\CyberLink\PowerDVD\PowerDVD.exe" /autostart
O4 - HKLM\..\Run: [LogitechCommunicationsManager]
"C:\Program Files (x86)\Common
Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program
Files (x86)\Labtec\WebCam10\WebCam10.exe" /hide
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files
(x86)\Creative\SB Live! 24-bit\Surround
Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files
(x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program
Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files
(x86)\PowerISO\PWRISOVM.EXE"
O4 - HKLM\..\Run: [avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files
(x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ArcSoft Connection Service] "C:\Program
Files (x86)\Common Files\ArcSoft\Connection
Service\Bin\ACDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files
(x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AsioReg] REGSVR32 /S CTASIO.DLL
O4 - HKCU\..\Run: [CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files
(x86)\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
AcRdB7_1_0
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files
(x86)\DNA\btdna.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and
Settings\Administrator\Local Settings\Application
Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run:
[IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files (x86)\Common
Files\Nero\Lib\NMIndexStoreSvr.exe"
ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [RssReader] C:\Program Files
(x86)\RssReader\RssReader.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater]
C:\WINDOWS\SysWOW64\Adobe\SHOCKW~1\SWHELP~2.EXE -Update
-1103470 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT
5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR
3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 1.1.4322; .NET
CLR 3.0.4506.2152; .NET CLR 3.5.30729)"
-"http://www.9lives.be/spelletjes/snake/snake-3d"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall]
%systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall]
%systemroot%\system32\tscupgrd.exe (User 'NETWORK
SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall]
%systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall]
%systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: Marktplaats Zoekassistent.lnk = C:\Program
Files (x86)\Marktplaats Zoekassistent\Marktplaats.exe
O4 - Startup: OpenOffice.org 3.1 .lnk = C:\Program Files
(x86)\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk =
C:\Program Files (x86)\Adobe\Acrobat
7.0\Reader\reader_sl.exe
O4 - Global Startup: TMMonitor.lnk = C:\Program Files
(x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe
O8 - Extra context menu item: ImTranslator -
C:\PROGRA~2\SMARTL~1\IMTRAN~1\startup.html
O8 - Extra context menu item: Toevoegen aan &Windows Live
Favorites -
http://favorites.live.com/quickadd.aspx
O9 - Extra button: Launch Cooliris -
{3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files
(x86)\PicLensIE\cooliris.dll
O9 - Extra button: Bonjour -
{7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files
(x86)\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra button: ImTranslator -
{AE436396-55E7-4ec4-AD6D-45E88A530A4C} -
C:\PROGRA~2\SMARTL~1\IMTRAN~1\startup.html (HKCU)
O9 - Extra 'Tools' menuitem: ImTranslator -
{AE436396-55E7-4ec4-AD6D-45E88A530A4C} -
C:\PROGRA~2\SMARTL~1\IMTRAN~1\startup.html (HKCU)
O15 - ESC Trusted Zone:
http://runonce.msn.com
O16 - DPF: {03B39B10-9AB9-4DBB-8189-7F76E0CE5F3F}
(FavImport Class) -
https://favorites.live.com/cab/ImportAx.cab?v=13,0,1609,00
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System
Requirements Lab) -
http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/s
rl_bin/sysreqlab3.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System
Requirements Lab) -
http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/s
rl_bin/sysreqlab_nvd.cab
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289}
(CoGSManager Class) -
http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
(WUWebControl Class) -
http://www.update.microsoft.com/windowsupdate/v6/V5Control
s/en/x86/client/wuweb_site.cab?1222350258656
O16 - DPF: {B8A48F42-30E1-48f8-AE87-7BD7C75DB8AA} (System
Requirements Lab) -
http://www.systemrequirementslab.com/srl_bin/sysreqlab_tes
t.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash
/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6}
(IWinAmpActiveX Class) -
http://www.rtvkatwijk.nl/webtelevisie/ampx_en_dl.cab
O22 - SharedTaskScheduler: Browseui preloader -
{438755C2-A8BA-11D1-B96B-00A0C90312E1} -
C:\WINDOWS\SysWow64\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache
daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} -
C:\WINDOWS\SysWow64\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft
Inc. - C:\Program Files (x86)\Common
Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) -
Acronis - C:\Program Files (x86)\Common
Files\Acronis\Schedule2\schedul2.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) -
ALWIL Software - C:\Program Files\Alwil
Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software -
C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software -
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software -
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple
Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Logical Disk Manager Administrative Service
(dmadmin) - Unknown owner -
C:\WINDOWS\System32\dmadmin.exe (file missing)
O23 - Service: Event Log (Eventlog) - Unknown owner -
C:\WINDOWS\system32\services.exe (file missing)
O23 - Service: Remote Connections Service (FlexService) -
BitMicro Software Corporation - C:\Program Files
(x86)\RapidBIT\cisvc.exe
O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner -
C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: IMAPI CD-Burning COM Service (ImapiService)
- Unknown owner - C:\WINDOWS\system32\imapi.exe (file
missing)
O23 - Service: Java Quick Starter
(JavaQuickStarterService) - Sun Microsystems, Inc. -
C:\Program Files (x86)\Java\jre6\bin\jqs.exe
O23 - Service: Lina Service - Unknown owner - C:\Program
Files (x86)\Lina Software\LINA Runtime
Environment\bin\linawindowsservice.exe (file missing)
O23 - Service: LVSrvLauncher - Labtec Inc. - C:\Program
Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Distributed Transaction Coordinator (MSDTC)
- Unknown owner - C:\WINDOWS\system32\msdtc.exe (file
missing)
O23 - Service: Net Logon (Netlogon) - Unknown owner -
C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program
Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NT LM Security Support Provider (NtLmSsp) -
Unknown owner - C:\WINDOWS\system32\lsass.exe (file
missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) -
Unknown owner - C:\WINDOWS\system32\nvsvc64.exe (file
missing)
O23 - Service: Plug and Play (PlugPlay) - Unknown owner -
C:\WINDOWS\system32\services.exe (file missing)
O23 - Service: IPSEC Services (PolicyAgent) - Unknown
owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Protected Storage (ProtectedStorage) -
Unknown owner - C:\WINDOWS\system32\lsass.exe (file
missing)
O23 - Service: ProtexisLicensing - Unknown owner -
C:\WINDOWS\SysWOW64\PSIService.exe
O23 - Service: Remote Desktop Help Session Manager
(RDSessMgr) - Unknown owner -
C:\WINDOWS\system32\sessmgr.exe (file missing)
O23 - Service: Security Accounts Manager (SamSs) - Unknown
owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files
(x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Virtual Disk Service (vds) - Unknown owner
- C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: Volume Shadow Copy (VSS) - Unknown owner -
C:\WINDOWS\System32\vssvc.exe (file missing)
O23 - Service: WMI Performance Adapter (WmiApSrv) -
Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
(file missing)
--
End of file - 14338 bytes
Sorry voor dit vreemde bericht, maar op het moment heeft het afsluiten de melding niet meer, ik kan ook op de computer niets vinden van dit "programma"