Mijn computer start heel sloom op.
Kan iemand mij helpen?
hier is mijn hijackthis log:
Logfile of HijackThis v1.97.7
Scan saved at 1:13:33, on 24-6-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:Program FilesNetropaMultimedia Keyboardnhksrv.exe
C:Program FilesNorton AntiVirusnavapsvc.exe
C:Program FilesNorton AntiVirusAdvToolsNPROTECT.EXE
C:WINDOWSSystem32nvsvc32.exe
C:WINDOWSntsx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSOUNDMAN.EXE
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesAlcatelSpeedTouch USBDragdiag.exe
C:Program FilesNetropaMultimedia KeyboardMMKeybd.exe
C:WINDOWSSystem32spooldriversw32x863hpztsb07.exe
C:Program FilesCommon Filesslmssslmss.exe
C:Program Filesblssblss.exe
C:WINDOWSSystem32acledit.exe
C:Program FilesNetropaMultimedia KeyboardTrayMon.exe
C:Program FilesNetropaOnscreen DisplayOSD.exe
C:Program FilesNetropaInetKbInetkb.exe
C:WINDOWSSystem32taskinf.exe
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe
C:Program FilesJavaj2re1.4.2_03binjusched.exe
C:PROGRA~1LITEHE~1citywavedent.exe
C:Program FilesBTVbtv.exe
C:Program FilesMessenger Plus! 3MsgPlus.exe
C:WINDOWSsystem32crer32.exe
C:Program FilesWeb_RebatesWebRebates0.exe
C:Program FileswebHancerProgramswhAgent.exe
C:Program FileswebHancerProgramswhSurvey.exe
C:WINDOWSSystem32rundll32.exe
C:WINDOWSSystem32javaw.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesCommon FilesMicrosoft SharedWorks
Sharedwkcalrem.exe
C:Program FilesWeb_RebatesWebRebates1.exe
C:WINDOWSSystem32wuauclt.exe
C:Program FilesWebSavingsfromEbatesWebSavingsfromEbates.exe
C:Program FilesInternet Exploreriexplore.exe
C:PROGRA~1NetropaInetKbikbupd.exe
C:COMPUTER CLEANINGHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
http://searchweb2.com/searchbar.htmlR1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page =
res://C:WINDOWSsystem32osyhz.dll/sp.html#44272
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
res://osyhz.dll/index.html#44272
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant
=
http://searchweb2.com/searchbar.htmlR0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
res://osyhz.dll/index.html#44272
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar =
http://searchweb2.com/searchbar.htmlR1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
res://C:WINDOWSsystem32osyhz.dll/sp.html#44272
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL
= res://osyhz.dll/index.html#44272
R1 - HKLMSoftwareMicrosoftInternet
ExplorerMain,Default_Search_URL = res://C:WINDOWSsystem32
osyhz.dll/sp.html#44272
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch
=
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
http://www.seekseek.com/quicksearch.asp?keyphrase=R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Startpagina =
file:///C:/Program%20Files/NowOnline/Portal/portal.html
R0 - HKCUSoftwareMicrosoftInternet
ExplorerToolbar,LinksFolderName =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} -
C:Program FilesNorton AntiVirusNavShExt.dll
O2 - BHO: (no name) - {F3C35F31-DCAA-23E8-21EA-00AC5AD3470E} -
C:WINDOWSsystem32wingl.dll
O4 - HKLM..Run: [Microsoft Works Update Detection] c:Program
FilesMicrosoft WorksWkDetect.exe
O4 - HKLM..Run: [Microsoft Works Portfolio] c:Program FilesMicrosoft
WorksWksSb.exe /AllUsers
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE
C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec
SharedccApp.exe"
O4 - HKLM..Run: [ccRegVfy] "C:Program FilesCommon FilesSymantec
SharedccRegVfy.exe"
O4 - HKLM..Run: [Advanced Tools Check] C:PROGRA~1NORTON~1
AdvToolsADVCHK.EXE
O4 - HKLM..Run: [SpeedTouch USB Diagnostics] "C:Program
FilesAlcatelSpeedTouch USBDragdiag.exe" /icon
O4 - HKLM..Run: [LWBMOUSE] C:Program FilesFSCWireless Wheel
MouseMOUSE32A.EXE
O4 - HKLM..Run: [MULTIMEDIA KEYBOARD] C:Program
FilesNetropaMultimedia KeyboardMMKeybd.exe
O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32
spooldriversw32x863hpztsb07.exe
O4 - HKLM..Run: [spoolsvv] C:WINDOWSsystem32spoolsvv.exe -
invisible
O4 - HKLM..Run: [slmss] C:Program FilesCommon
Filesslmssslmss.exe
O4 - HKLM..Run: [blss] C:Program Filesblssblss.exe
O4 - HKLM..Run: [WinDSNX] C:WINDOWSSystem32acledit.exe
O4 - HKLM..Run: [NeroCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [task] C:WINDOWSSystem32taskinf.exe
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon
FilesRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [SunJavaUpdateSched] C:Program
FilesJavaj2re1.4.2_03binjusched.exe
O4 - HKLM..Run: [WipeStart] C:PROGRA~1LITEHE~1citywavedent.exe
O4 - HKLM..Run: [BTV] C:Program FilesBTVbtv.exe
O4 - HKLM..Run: [Breg] "C:Program FilesCommon FilesJavabreg.exe"
O4 - HKLM..Run: [MessengerPlus3] "C:Program FilesMessenger Plus!
3MsgPlus.exe"
O4 - HKLM..Run: [crer32.exe] C:WINDOWSsystem32crer32.exe
O4 - HKLM..Run: [WebRebates0] "C:Program
FilesWeb_RebatesWebRebates0.exe"
O4 - HKLM..Run: [webHancer Agent] "C:Program
FileswebHancerProgramswhAgent.exe"
O4 - HKLM..Run: [webHancer Survey Companion] "C:Program
FileswebHancerProgramswhSurvey.exe"
O4 - HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1NEWDOT~1
NEWDOT~3.DLL,NewDotNetStartup -s
O4 - HKLM..Run: [WebSavingsfromEbates] javaw -cp "C:Program
FilesWebSavingsfromEbatesSystemCode" Main lp: "C:Program
FilesWebSavingsfromEbates"
O4 - HKCU..Run: [MSMSGS] "C:Program
FilesMessengermsmsgs.exe" /background
O4 - HKLM..RunOnce: [ntsx.exe] C:WINDOWSntsx.exe
O4 - HKLM..RunOnce: [d3pg.exe] C:WINDOWSd3pg.exe
O4 - HKLM..RunOnce: [addar32.exe] C:WINDOWSaddar32.exe
O4 - HKLM..RunOnce: [winuw.exe] C:WINDOWSwinuw.exe
O4 - HKLM..RunOnce: [d3ry32.exe] C:WINDOWSd3ry32.exe
O4 - HKLM..RunOnce: [winjp.exe] C:WINDOWSsystem32winjp.exe
O4 - HKLM..RunOnce: [appjn32.exe] C:WINDOWSappjn32.exe
O4 - HKLM..RunOnce: [appjc.exe] C:WINDOWSsystem32appjc.exe
O4 - HKLM..RunOnce: [ntqf32.exe] C:WINDOWSsystem32ntqf32.exe
O4 - HKLM..RunOnce: [appdu32.exe] C:WINDOWSsystem32
appdu32.exe
O4 - HKLM..RunOnce: [winhe.exe] C:WINDOWSwinhe.exe
O4 - HKLM..RunOnce: [atlta32.exe] C:WINDOWSatlta32.exe
O4 - HKLM..RunOnce: [sdkep.exe] C:WINDOWSsystem32sdkep.exe
O4 - HKLM..RunOnce: [netfo32.exe] C:WINDOWSnetfo32.exe
O4 - HKLM..RunOnce: [crtb.exe] C:WINDOWSsystem32crtb.exe
O4 - HKLM..RunOnce: [nthl32.exe] C:WINDOWSsystem32nthl32.exe
O4 - HKLM..RunOnce: [ippf.exe] C:WINDOWSsystem32ippf.exe
O4 - HKLM..RunOnce: [addqq32.exe] C:WINDOWSaddqq32.exe
O4 - HKLM..RunOnce: [mfceo32.exe] C:WINDOWSsystem32
mfceo32.exe
O4 - HKLM..RunOnce: [ntjq.exe] C:WINDOWSsystem32ntjq.exe
O4 - HKLM..RunOnce: [atlhv.exe] C:WINDOWSatlhv.exe
O4 - HKLM..RunOnce: [iecw32.exe] C:WINDOWSiecw32.exe
O4 - HKLM..RunOnce: [msyd.exe] C:WINDOWSsystem32msyd.exe
O4 - HKLM..RunOnce: [sdknn32.exe] C:WINDOWSsystem32
sdknn32.exe
O4 - HKLM..RunOnce: [appsw32.exe] C:WINDOWSsystem32
appsw32.exe
O4 - HKLM..RunOnce: [atlqh32.exe] C:WINDOWSsystem32atlqh32.exe
O4 - HKLM..RunOnce: [atlpk32.exe] C:WINDOWSsystem32atlpk32.exe
O4 - HKLM..RunOnce: [ntul32.exe] C:WINDOWSsystem32ntul32.exe
O4 - HKLM..RunOnce: [sdkdv32.exe] C:WINDOWSsystem32
sdkdv32.exe
O4 - HKLM..RunOnce: [netsk32.exe] C:WINDOWSsystem32
netsk32.exe
O4 - HKLM..RunOnce: [appot.exe] C:WINDOWSsystem32appot.exe
O4 - HKLM..RunOnce: [sdkha.exe] C:WINDOWSsystem32sdkha.exe
O4 - HKLM..RunOnce: [d3tx32.exe] C:WINDOWSsystem32d3tx32.exe
O4 - HKLM..RunOnce: [apihu32.exe] C:WINDOWSapihu32.exe
O4 - HKLM..RunOnce: [sdkzk32.exe] C:WINDOWSsystem32
sdkzk32.exe
O4 - HKLM..RunOnce: [d3jx32.exe] C:WINDOWSsystem32d3jx32.exe
O4 - HKLM..RunOnce: [atlcf.exe] C:WINDOWSsystem32atlcf.exe
O4 - HKLM..RunOnce: [appnh32.exe] C:WINDOWSappnh32.exe
O4 - HKLM..RunOnce: [ntjx32.exe] C:WINDOWSsystem32ntjx32.exe
O4 - Global Startup: Herinneringen van Microsoft Works Agenda.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft
OfficeOfficeOSA9.EXE
O8 - Extra context menu item: Web Rebates - file://C:Program
FilesWeb_RebatesSy1150Tp1150scri1150a.htm
O8 - Extra context menu item: Web Savings - file://C:Program
FilesWebSavingsfromEbatesSystemTempebateswebsavings_script0.
htm
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Unknown file in Winsock LSP: c:windowssystem32inetadpt.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32inetadpt.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32inetadpt.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32inetadpt.dll
O10 - Hijacked Internet access by WebHancer
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers
Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cabO16 - DPF: {13197ACE-6851-45C3-A7FF-C281324D5489} -
http://www.2nd-thought.com/files/install013.exeO16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave
ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cabO16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289}
(CoGSManager Class) -
http://gamingzone.ubisoft.com/dev/packages/GSManager.cabO16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B}
(Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cabO16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D
ActiveX Player) -
http://www.cult3d.com/download/cult.cabO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet
Download Control Class) -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_42.cabO16 - DPF: {6211AC26-A1B4-422A-AC52-1E70B7D24465}
(FileSharingCtrl Class) -
http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/nl/filesharingctrl.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl
Class) -
https://www.gamespyid.com/alaunch.cabO16 - DPF: {841A9192-5690-11D4-A258-0040954A01BE} (DialXSCtl
Object) -
http://dialxs.nl/install/dialxs.ocxO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
(MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update
Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?
37862.2009259259
O16 - DPF: {A7798D6C-C6B5-4F26-9363-F7CDBBFFA607} (download
Class) -
http://www.gigex.com/ActiveX/vxpspeeddelivery.dllO16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl
Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cabO16 - DPF: {BB0578ED-E672-4697-9663-EC5A0460B949}
(SomaticCAB.Setup) -
http://downloads.searchcentrix.com/install/weblz.CABO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave
Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure
Delivery) -
http://www.gamespot.com/KDX/kdx.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat
Control 4.5) -
http://fdl.msn.com/public/chat/msnchat45.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire
Showdown Class) -
http://messenger.zone.msn.com/binary/SolitaireShowdown.cabO17 - HKLMSystemCCSServicesTcpip..{680223C7-293D-4567-98A3-
D3181A965FE7}: NameServer = 195.121.1.34 195.121.1.66