(07-12-2009 09:25)miekiemoes schreef: [ -> ]Hoi,
Doe even het volgende..
* Download DDS en bewaar het op je bureaublad.
Schakel programma's uit die scripts blokkeren, zoals je Antivirus
Dubbelklik dds.scr om de tool te starten.
Daarna zal DDS.txt openen.
Klik Yes voor de Optional Scan. Dit zal het bestand Attach.txt maken.
Kopieer en plak beide logs in je volgende post Het is beter om hiervoor twee posts te maken aangezien beide logs niet in één post zullen passen.
en Hier het tweede "DDS"
DDS (Ver_09-12-01.01) - NTFSx86
Run by Adri at 8:38:44,92 on ma 07/12/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.3262.2787 [GMT 1:00]
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: ActiveArmor Firewall *disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
============== Running Processes ===============
C:\WINXP\system32\nvsvc32.exe
C:\WINXP\system32\svchost -k DcomLaunch
svchost.exe
C:\WINXP\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\WINXP\Explorer.EXE
svchost.exe
C:\WINXP\system32\svchost.exe -k imgsvc
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINXP\system32\spool\drivers\w32x86\3\hpztsb06.exe
C:\WINXP\system32\RUNDLL32.EXE
C:\WINXP\system32\ctfmon.exe
C:\Program Files\Tiptel 118 USB Phone\tiptel 118 USB phone.exe
D:\Program Files\WinZip\WZQKPICK.EXE
D:\Programs\Thunderbird\thunderbird.exe
D:\Programs\Firefox\firefox.exe
D:\Program Files\Kasperski 2010\klwtblfs.exe
C:\WINXP\system32\wscript.exe
D:\Download\dds.scr
============== Pseudo HJT Report ===============
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - d:\program files\kasperski 2010\ievkbd.dll
uRun: [ctfmon.exe] c:\winxp\system32\ctfmon.exe
mRun: [SoundMax] "c:\program files\analog devices\soundmax\Smax4.exe" /tray
mRun: [nwiz] nwiz.exe /install
mRun: [NvCplDaemon] RUNDLL32.EXE c:\winxp\system32\NvCpl.dll,NvStartup
mRun: [AVP] "d:\program files\kasperski 2010\avp.exe"
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [HPDJ Taskbar Utility] c:\winxp\system32\spool\drivers\w32x86\3\hpztsb06.exe
mRun: [NeroCheck] c:\winxp\system32\NeroCheck.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\winxp\system32\NvMcTray.dll,NvTaskbarInit
dRun: [CTFMON.EXE] c:\winxp\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\menust~1\progra~1\opstar~1\tiptel~1.lnk - c:\program files\tiptel 118 usb phone\tiptel 118 USB phone.exe
StartupFolder: c:\docume~1\alluse~1\menust~1\progra~1\opstar~1\winzip~1.lnk - d:\program files\winzip\WZQKPICK.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110}
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F}
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: klogon - c:\winxp\system32\klogon.dll
Notify: winvct32 - winvct32.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\adri\nieuw\applic~1\mozilla\firefox\profiles\6by014cr.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/
FF - component: d:\programs\firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - plugin: d:\programs\adobe\reader\browser\nppdf32.dll
FF - HiddenExtension: Java Console: No Registry Reference - d:\programs\firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
d:\programs\firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 kl1;Kl1;c:\winxp\system32\drivers\kl1.sys [2009-5-24 128016]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\winxp\system32\drivers\klbg.sys [2008-12-15 33808]
R1 KLIF;Kaspersky Lab Driver;c:\winxp\system32\drivers\klif.sys [2009-12-2 296976]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\winxp\system32\drivers\klim5.sys [2009-5-13 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\winxp\system32\drivers\klmouflt.sys [2009-5-16 19472]
S2 AVP;Kaspersky Anti-Virus;d:\program files\kasperski 2010\avp.exe [2009-5-25 303376]
=============== Created Last 30 ================
2009-12-04 06:11:02 12800 ----a-w- c:\winxp\BS_DEF.sys
2009-12-04 06:08:48 0 d-----r- c:\winxp\AsDmiHtm
2009-12-04 06:06:37 43008 ----a-w- c:\winxp\system32\drivers\AmdK8.sys
2009-12-04 06:06:06 0 d-----w- c:\program files\AMD
2009-12-03 13:28:39 37376 ----a-w- c:\winxp\system32\winvct32.dll
2009-12-03 12:04:30 0 d-----w- c:\docume~1\adri\nieuw\applic~1\Serif
2009-12-03 11:47:39 0 d-----w- c:\docume~1\adri\nieuw\applic~1\FreshDiagnose
2009-12-03 11:31:04 0 d-----w- c:\docume~1\alluse~1\applic~1\Soulseek
2009-12-03 10:32:54 89184 ----a-w- c:\winxp\system32\drivers\imagedrv.sys
2009-12-03 10:32:54 57344 ----a-w- c:\winxp\system32\ImageDrive.cpl
2009-12-03 10:32:49 38912 ----a-w- c:\winxp\system32\picn20.dll
2009-12-03 10:32:48 569344 ----a-w- c:\winxp\system32\imagr5.dll
2009-12-03 10:32:48 544768 ----a-w- c:\winxp\system32\imagx5.dll
2009-12-03 10:32:48 283920 ----a-w- c:\winxp\system32\ImagXpr5.dll
2009-12-03 10:32:47 155648 ----a-w- c:\winxp\system32\NeroCheck.exe
2009-12-03 10:28:55 45056 ----a-w- c:\winxp\system32\prnunins.exe
2009-12-03 10:28:49 807 ----a-w- c:\winxp\hpinfo.lnk
2009-12-03 10:28:45 0 d-----w- c:\program files\hp deskjet 5550 series
2009-12-03 10:28:38 147512 ----a-w- c:\winxp\system32\hpzlnt06.dll
2009-12-03 10:26:01 306688 ----a-w- c:\winxp\IsUninst.exe
2009-12-03 08:15:13 0 d-----w- c:\winxp\Easy CD-DA Extractor 12.0
2009-12-03 08:12:50 299552 ----a-w- c:\winxp\wmsysprx.prx
2009-12-03 08:11:16 0 d-----w- c:\docume~1\adri\nieuw\applic~1\Acoustica
2009-12-03 08:09:56 348160 ----a-w- c:\winxp\system32\msvcr71.dll
2009-12-03 08:01:53 0 d-----w- c:\winxp\SHELLNEW
2009-12-03 07:29:50 0 d-----w- c:\docume~1\adri\nieuw\applic~1\Auslogics
2009-12-02 21:50:56 69 ----a-w- c:\winxp\winhelp.ini
2009-12-02 21:50:56 537 ----a-w- c:\winxp\mahjongg32.cfg
2009-12-02 21:28:59 81 ----a-w- c:\winxp\Scrabman.INI
2009-12-02 13:47:09 56 ---ha-w- c:\winxp\system32\ezsidmv.dat
2009-12-02 13:23:14 0 d-----w- c:\winxp\system32\nl-nl
2009-12-02 13:23:13 0 d-----w- c:\winxp\system32\nl
2009-12-02 13:23:13 0 d-----w- c:\winxp\system32\bits
2009-12-02 13:23:13 0 d-----w- c:\winxp\l2schemas
2009-12-02 13:20:57 0 d-----w- c:\winxp\network diagnostic
2009-12-02 12:13:19 0 d-----w- c:\docume~1\adri\nieuw\applic~1\nView_Wallpaper
2009-12-02 12:07:27 203136 -c----w- c:\winxp\system32\dllcache\rmcast.sys
2009-12-02 12:07:24 455296 -c----w- c:\winxp\system32\dllcache\mrxsmb.sys
2009-12-02 12:07:21 333952 -c----w- c:\winxp\system32\dllcache\srv.sys
2009-12-02 12:07:14 272640 -c----w- c:\winxp\system32\dllcache\bthport.sys
2009-12-02 12:05:41 1315328 -c----w- c:\winxp\system32\dllcache\msoe.dll
2009-12-02 12:05:35 691712 -c----w- c:\winxp\system32\dllcache\inetcomm.dll
2009-12-02 12:04:57 218624 -c----w- c:\winxp\system32\dllcache\wordpad.exe
2009-12-02 12:04:33 0 d-----w- c:\winxp\system32\PreInstall
2009-12-02 12:03:53 147456 -c----w- c:\winxp\system32\dllcache\schannel.dll
2009-12-02 11:59:23 337408 -c----w- c:\winxp\system32\dllcache\netapi32.dll
2009-12-02 11:53:46 604140 --sha-w- c:\winxp\system32\drivers\ISwift3.dat
2009-12-02 11:48:13 43609 ----a-w- c:\winxp\system32\nvapps.nvb
2009-12-02 11:48:00 0 d-----w- c:\winxp\nview
2009-12-02 11:48:00 0 d-----w- c:\winxp\NV13961172.TMP
2009-12-02 11:47:53 3535520 -c--a-w- c:\winxp\system32\dllcache\nv4_mini.sys
2009-12-02 11:47:23 1024 ----a-w- C:\.rnd
2009-12-02 11:47:18 22 ----a-w- c:\winxp\FileName
2009-12-02 11:30:27 21684 ----a-w- c:\winxp\Ascd_log.ini
2009-12-02 11:27:25 5810 ----a-r- c:\winxp\system32\drivers\ASACPI.sys
2009-12-02 11:27:09 5824 ----a-w- c:\winxp\system32\drivers\ASUSHWIO.SYS
2009-12-02 11:24:08 95259 ----a-w- c:\winxp\system32\drivers\klick.dat
2009-12-02 11:24:08 108059 ----a-w- c:\winxp\system32\drivers\klin.dat
2009-12-02 11:17:36 0 d-----w- c:\winxp\ServicePackFiles
2009-12-02 11:17:21 19528 ----a-w- c:\winxp\000001_.tmp
2009-12-02 11:17:14 26488 ----a-w- c:\winxp\system32\spupdsvc.exe
2009-12-02 11:17:12 0 d-----w- c:\winxp\EHome
2009-12-02 11:09:22 0 d-----w- c:\winxp\pss
2009-12-02 11:03:01 8 ----a-w- c:\winxp\system32\nvModes.dat
2009-12-02 11:00:02 0 d-----w- c:\docume~1\alluse~1\applic~1\NVIDIA Corporation
2009-12-02 10:32:51 0 d-----w- c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2009-12-02 10:31:05 0 d-----w- c:\docume~1\alluse~1\applic~1\Kaspersky Lab
2009-12-02 10:31:05 0 d-----w- c:\docume~1\alluse~1\applic~1\Easy CD-DA Extractor
2009-12-02 10:31:02 0 d-----w- c:\docume~1\alluse~1\applic~1\BigFishGamesCache
2009-12-02 10:13:36 0 d--h--w- c:\documents and settings\all users\Sjablonen
2009-12-02 10:13:36 0 d-----w- c:\documents and settings\all users\Favorieten
2009-12-02 10:13:36 0 d-----w- c:\documents and settings\all users\Bureaublad
2009-12-02 10:13:36 0 d-----r- c:\documents and settings\all users\Menu Start
2009-12-02 10:13:36 0 d-----r- c:\documents and settings\all users\Documenten
2009-12-02 09:52:25 0 d-sh--w- c:\documents and settings\all users\DRM
2009-12-02 06:03:58 0 d-----w- c:\program files\Messenger
2009-12-01 04:30:11 0 d-----w- c:\program files\Plus500
2009-11-07 09:55:16 0 d-----w- c:\program files\eToro
==================== Find3M ====================
2009-12-04 06:47:38 53652 ----a-w- c:\winxp\system32\perfc013.dat
2009-12-04 06:47:38 364644 ----a-w- c:\winxp\system32\perfh013.dat
2009-12-02 11:59:44 128016 ----a-w- c:\winxp\system32\drivers\kl1.sys
2009-12-02 09:50:41 21748 ----a-w- c:\winxp\system32\emptyregdb.dat
2009-09-11 14:20:53 136192 ----a-w- c:\winxp\system32\msv1_0.dll
============= FINISH: 8:38:51,95 ===============