Big Andrew
Gebruiker
- Lid geworden
- 15 apr 2003
- Berichten
- 31
Explorer doet raar; myn computer werkt niet en ook valt nu internet uit!!
Sinds 4 dagen krijg ik onderstaand foutmelding als ik op de systeemiconen (mijn computer, netwerkverbinding, mijn documenten, mijn muziek) op het bureaublad tik, ze werken niet meer en geven het volgende te lezen: EXPLORER heeft een fout met betrekking tot een ongeldige pagina veroorzaakt in
module <onbekend> op0000:07c7fc6e.
Registers:
EAX=0045d44c CS=0187 EIP=07c7fc6e EFLGS=00010246
EBX=01d609f0 SS=018f ESP=00e8be20 EBP=00e8be3c
ECX=50002fa8 DS=018f ESI=01d609f8 FS=380f
EDX=00e8be30 ES=018f EDI=00e8c150 GS=0000
Bytes in CS:EIP:
Stackdump:
01c25da1 0045d44c 00e8be30 00000000 00000000 0045d44c 00444080 00e8be88 01c25de2 00e8c150 01d609f8 00000000 00000000 00000000 00000000 00e8c0a0
Sinds vandaag valt ook af en toe de internetverbinding weg.
Verder kan ik emails alleen maar verzenden als ik Norton antivirus uitzet (anders valt de verbinding tijdens de scan van NAV weg). Voor de volledigheid plaats ik mijn logfil hieronder voor de kenners.
Wie weet raad?.
Alle programmaicoontjes werken wel. Hoe kan ik dit herstellen? Herstarten helpt niet!
Inmiddels Spyware scan gedaan; helpt niet; dan maar de Hijack eroverheen gezet en bijgaande logfiles aangemaakt:
Zie hieronder
--- Search result list ---
--- Spybot - Search && Destroy version: 1.3 ---
2004-05-25 Includes\Cookies.sbi
2004-05-29 Includes\Dialer.sbi
2004-05-28 Includes\Hijackers.sbi
2004-05-28 Includes\Keyloggers.sbi
2004-05-28 Includes\Malware.sbi
2004-05-04 Includes\Revision.sbi
2004-04-12 Includes\Security.sbi
2004-05-28 Includes\Spybots.sbi
2004-05-28 Includes\Trojans.sbi
2004-05-12 Includes\LSP.sbi
2004-05-24 Includes\Tracks.uti
--- System information ---
Windows 98 (Build: 2222) A
/ DataAccess: Patch Available For XMLHTTP Vulnerability
/ DataAccess: Buffer Overrun in Microsoft Data Access Components Could Lead to Code Execution
/ DataAccess: Security update for Microsoft Data Access Components
/ Windows Media Player: Windows Media Update 320920
/ Windows Media Player: Windows Media Update 819639
/ DirectX: DirectX Update 819696
--- Startup entries list ---
Located: HK_LM:Run, NAV Agent
command: C:\PROGRA~1\NORTON~1\NAVAPW32.EXE
file: C:\PROGRA~1\NORTON~1\NAVAPW32.EXE
size: 79480
MD5: 44a716c6eda439a804c2833e0c16da82
Located: HK_LM:Run, ScanRegistry
command: C:\WINDOWS\scanregw.exe /autorun
file: C:\WINDOWS\scanregw.exe
size: 90112
MD5: 197de4470e262d1f86fb088949c0386a
Located: HK_LM:Run, Symantec NetDriver Monitor
command: C:\PROGRA~1\SYMANTEC\LIVEUP~1\SNDMON.EXE
file: C:\PROGRA~1\SYMANTEC\LIVEUP~1\SNDMON.EXE
size: 87184
MD5: c16b92488d9499171a63225f487f7d20
Located: HK_LM:Run, CMESys (DISABLED)
command: "C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE"
Located: HK_LM:Run, CriticalUpdate (DISABLED)
command: C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
file: C:\WINDOWS\SYSTEM\wucrtupd.exe
size: 135168
MD5: d4060358f5955cfe4fbad2c2f5dc8a40
Located: HK_LM:Run, FLMTRUSTMOUSE (DISABLED)
command: C:\Program Files\Trust mouse utility\1.0\mouse32a.exe
file: C:\Program Files\Trust mouse utility\1.0\mouse32a.exe
size: 429568
MD5: a06b0f3b1aaac26f3a96f640b1108320
Located: HK_LM:Run, LoadQM (DISABLED)
command: loadqm.exe
Located: HK_LM:Run, QuickTime Task (DISABLED)
command: "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
file: C:\WINDOWS\SYSTEM\QTTASK.EXE
size: 77824
MD5: 5d22b4258489575412f6d18affc847a2
Located: HK_LM:Run, SpeedOptimizer (DISABLED)
command: "C:\PROGRA~1\SPEEDO~1\SPO.EXE" -s
file: C:\PROGRA~1\SPEEDO~1\SPO.EXE
size: 607232
MD5: 9e39286bd9af22d5991df64d58556f43
Located: HK_LM:Run, SpeedTouch USB Diagnostics (DISABLED)
command: "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
file: C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
size: 861184
MD5: 6551d483e62ebb75015686845092d4df
Located: HK_LM:Run, SystemTray (DISABLED)
command: SysTray.Exe
file: C:\WINDOWS\SYSTEM\SysTray.Exe
size: 27648
MD5: c7e1448ef194081ca615b2601e9751fd
Located: HK_LM:Run, Taakcontrole (DISABLED)
command: C:\WINDOWS\taskmon.exe
file: C:\WINDOWS\taskmon.exe
size: 28672
MD5: 68c189ce09541b3efd9b502f3c18c7c6
Located: HK_LM:Run, TrustInstaller (DISABLED)
command: D:\SETUP.EXE
Located: HK_LM:Run, WinampAgent (DISABLED)
command: "C:\Program Files\Winamp3\winampa.exe"
file: C:\Program Files\Winamp3\winampa.exe
size: 12288
MD5: 6bf81517c708f53b8e22eb624ee3723a
Located: HK_LM:RunServices, LoadPowerProfile (DISABLED)
command: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
file: C:\WINDOWS\Rundll32.exe
size: 24576
MD5: 5b093875e9f565e086f8aefb94160f79
Located: HK_LM:RunServices, MessengerPlus2 (DISABLED)
command: "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
Located: HK_LM:RunServices, SchedulingAgent (DISABLED)
command: mstask.exe
file: C:\WINDOWS\SYSTEM\mstask.exe
size: 112912
MD5: a31befa7baa6947cda52b2bc3857d2cc
Located: HK_LM:RunServices, ScriptBlocking (DISABLED)
command: "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
file: C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
size: 54408
MD5: 3db0459e2661531bfe88ae0a182d019a
Located: HK_LM:RunServices, WinRoute (DISABLED)
command: C:\PROGRAM FILES\WINROUTE PRO\Winroute.exe /hide
Located: HK_CU:Run, MessengerPlus2 (DISABLED)
command: "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
Located: HK_CU:Run, MSMSGS (DISABLED)
command: "C:\Program Files\Messenger\msmsgs.exe" /background
Located: HK_CU:Run, Taskbar Display Controls (DISABLED)
command: RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
file: C:\WINDOWS\RunDLL.exe
size: 5155
MD5: c6bb2a882611a6351b1dee41e6ef2198
--- Browser helper object list ---
{0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} (DAPBHO Class)
BHO name:
CLSID name: DAPBHO Class
description: Download Accelerator plus
classification: Open for discussion
known filename: Dapiebar.dll
info link: http://www.speedbit.com/DefaultT.asp?
info source: TonyKlein
Path: C:\PROGRAM FILES\DAP\
Long name: DAPIEBAR.DLL
Short name:
Date (created): 29-7-02 17:29:46
Date (last access): 7-6-04
Date (last write): 11-11-03 10:19:24
Filesize: 405504
Attributes: archive
MD5: 8E21C09D56A479532B55BBEAC6062730
CRC32: A57567A2
Version: 0.5.0.3
{BDF3E430-B101-42AD-A544-FADC6B084872} (NAV Helper)
BHO name: NAV Helper
CLSID name: CNavExtBho Class
description: Norton Antivirus
classification: Legitimate
known filename: NavShExt.dll
info link: http://www.symantec.com/nav/nav_9xnt/
info source: TonyKlein
Path: C:\Program Files\Norton AntiVirus\
Long name: NAVSHEXT.DLL
Short name:
Date (created): 29-4-02 11:50:30
Date (last access): 7-6-04
Date (last write): 20-3-02 12:00:40
Filesize: 102400
Attributes: archive
MD5: 2EAB9D2A0AFE9BE089924458522CDF93
CRC32: 95E2EA74
Version: 0.8.0.0
{F281FFC7-6C63-4bf9-83F2-AB7A6157B109} (Core Library)
BHO name: Core Library
CLSID name: Veevo Object
Path: C:\WINDOWS\SYSTEM\
Long name: KDP3313.dll
Short name: KDP3313.DLL
Date (created): 29-5-04 0:07:12
Date (last access): 7-6-04
Date (last write): 29-5-04 0:07:14
Filesize: 159744
Attributes: archive
MD5: CBE6F8A705F911D52C7A10D4B26A4042
CRC32: 1F047AD5
{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDHelper.dll
info link: http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\PROGRA~1\SPYBOT~1\
Long name: SDHelper.dll
Short name: SDHELPER.DLL
Date (created): 12-5-04 1:03:00
Date (last access): 7-6-04
Date (last write): 12-5-04 1:03:00
Filesize: 744960
Attributes: archive
MD5: ABF5BA518C6A5ED104496FF42D19AD88
CRC32: 5587736E
Version: 0.1.0.3
--- ActiveX list ---
Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla
DirectAnimation Java Classes (DirectAnimation Java Classes)
DPF name: DirectAnimation Java Classes
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\dajava.cab
info link:
info source: Patrick M. Kolla
Internet Explorer Classes for Java (Internet Explorer Classes for Java)
DPF name: Internet Explorer Classes for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\iejava.cab
info link:
info source: Patrick M. Kolla
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM\MACROMED\FLASH\
Long name: Flash.ocx
Short name: FLASH.OCX
Date (created): 4-9-03 14:17:58
Date (last access): 7-6-04
Date (last write): 8-12-03 14:01:58
Filesize: 933888
Attributes: archive
MD5: F7E435D02F7A48120B746E33254A70BC
CRC32: 02AF493D
Version: 0.7.0.0
{9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class)
DPF name:
CLSID name: Update Class
description: Windows Update
classification: Legitimate
known filename: %WINDIR%\System32\iuctl.dll,iuengine.dll
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM\
Long name: iuctl.dll
Short name: IUCTL.DLL
Date (created): 21-8-03 16:47:54
Date (last access): 7-6-04
Date (last write): 21-8-03 16:47:54
Filesize: 162400
Attributes:
MD5: DB2F1F57D3057FEBC19C61AB9AA77198
CRC32: 5A03D776
Version: 0.5.0.3
{CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class)
DPF name:
CLSID name: Downloader Class
Path: C:\WINDOWS\DOWNLO~1\
Long name: dwnldr.dll
Short name: DWNLDR.DLL
Date (created): 15-12-02 6:46:04
Date (last access): 7-6-04
Date (last write): 15-12-02 6:46:04
Filesize: 102400
Attributes:
MD5: 6C85378C0DD243C9C4685EB01DE7CB72
CRC32: 2F4BF700
Version: 0.2.0.0
{2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy)
DPF name:
CLSID name: ChainCast VMR Client Proxy
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: ccpm_0237.dll
Short name: CCPM_0~1.DLL
Date (created): 19-12-02 19:09:44
Date (last access): 7-6-04
Date (last write): 19-12-02 19:09:44
Filesize: 1488120
Attributes:
MD5: 2E2942127C097A132ED6FA3451BAEA06
CRC32: 9CCC07CD
Version: 0.3.0.0
{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} ()
DPF name:
CLSID name:
{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
description: Macromedia ShockWave Flash Player 7
classification: Unknown
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\
Long name: SWDIR.DLL
Short name:
Date (created): 15-11-03 14:25:56
Date (last access): 7-6-04
Date (last write): 11-2-03 6:02:58
Filesize: 32768
Attributes: archive
MD5: 92FA0AE21D3A08B65D291724AA7D0E43
CRC32: 7B63A9DB
Version: 0.8.0.5
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object)
DPF name:
CLSID name: QuickTime Object
description: Apple Quicktime
classification: Legitimate
known filename: QTPLUGIN.OCX
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM\
Long name: QTPlugin.ocx
Short name: QTPLUGIN.OCX
Date (created): 24-11-03 19:51:34
Date (last access): 7-6-04
Date (last write): 24-11-03 19:51:36
Filesize: 327736
Attributes: archive
MD5: CE3D865CCF4267C85934D9B7CA8521F2
CRC32: F9306ACA
Version: 0.6.0.4
{CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class)
DPF name:
CLSID name: Live365Player Class
Path: C:\WINDOWS\DOWNLO~1\
Long name: Play365.dll
Short name: PLAY365.DLL
Date (created): 6-6-03 18:06:56
Date (last access): 7-6-04
Date (last write): 6-6-03 18:06:56
Filesize: 335872
Attributes:
MD5: 02D3243B77F6C3EFBF67AAD62C26B443
CRC32: FA8AB3C6
Version: 0.1.0.0
{8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class)
DPF name:
CLSID name: MessengerStatsClient Class
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: messengerstatsclient.dll
Short name: MESSEN~1.DLL
Date (created): 29-5-03 15:00:20
Date (last access): 7-6-04
Date (last write): 29-5-03 15:00:20
Filesize: 160864
Attributes:
MD5: B069B555A00AA026F657AA4FD13AE154
CRC32: 89BB01E1
Version: 0.7.0.1
{2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class)
DPF name:
CLSID name: Minesweeper Flags Class
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: minesweeper.dll
Short name: MINESW~1.DLL
Date (created): 29-5-03 15:00:22
Date (last access): 7-6-04
Date (last write): 29-5-03 15:00:22
Filesize: 84064
Attributes:
MD5: F951FD0EA383DF2D49CA0359E4A86968
CRC32: 50A69718
Version: 0.7.0.1
{00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class)
DPF name:
CLSID name: Checkers Class
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: msgrchkr.dll
Short name: MSGRCHKR.DLL
Date (created): 29-5-03 15:00:18
Date (last access): 7-6-04
Date (last write): 29-5-03 15:00:18
Filesize: 77408
Attributes:
MD5: 42D567DF86B9B7AC4A89664C9651B68B
CRC32: 47FF3D19
Version: 0.7.0.1
{F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class)
DPF name:
CLSID name: Solitaire Showdown Class
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: solitaireshowdown.dll
Short name: SOLITA~1.DLL
Date (created): 29-5-03 15:00:20
Date (last access): 7-6-04
Date (last write): 29-5-03 15:00:20
Filesize: 86112
Attributes:
MD5: 6E0E81210B17C225AD8DBB86F0C41E32
CRC32: 1C944476
Version: 0.7.0.1
{841A9192-5690-11D4-A258-0040954A01BE} ()
DPF name:
CLSID name:
{018A066F-584A-422F-AC4C-0B1F5FE5C040} (VacPro.olanda_ver3)
DPF name:
CLSID name: VacPro.olanda_ver3
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: olanda_ver3.ocx
Short name: OLANDA~1.OCX
Date (created): 1-4-04 15:23:30
Date (last access): 7-6-04
Date (last write): 1-4-04 15:23:30
Filesize: 49152
Attributes:
MD5: 3FE1E3BAE0E58C66B6582332B658F60A
CRC32: 31B67F0F
Version: 0.1.0.0
{80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control)
DPF name:
CLSID name: AvxScanOnline Control
description: BitDefender online virus scanner
classification: Legitimate
known filename: bitdefender.ocx
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\DOWNLO~1\
Long name: bitdefender.ocx
Short name: BITDEF~1.OCX
Date (created): 22-3-02 16:58:34
Date (last access): 7-6-04
Date (last write): 22-3-02 16:58:34
Filesize: 344064
Attributes:
MD5: EAEAED4BF93D9BD5A87415DB3121C46B
CRC32: E0EDEC5D
Version: 0.2.0.0
--- Process list ---
Spybot - Search && Destroy process list report, 7-6-04 16:51:34
PID: 4291802967 (2121258659) C:\WINDOWS\SYSTEM\KERNEL32.DLL
PID: 4294574767 (4294902343) C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE
PID: 4294668903 (4294561755) C:\WINDOWS\SYSTEM\DDHELP.EXE
PID: 4294709959 (4294693271) C:\WINDOWS\SYSTEM\PSTORES.EXE
PID: 4294753039 (4294652431) C:\WINDOWS\SYSTEM\SPOOL32.EXE
PID: 4294759519 (4294784127) C:\WINDOWS\SYSTEM\TAPISRV.EXE
PID: 4294784127 (4294858563) C:\WINDOWS\SYSTEM\RNAAPP.EXE
PID: 4294880047 (4294902343) C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
PID: 4294902343 (4294919111) C:\WINDOWS\EXPLORER.EXE
PID: 4294906695 (4294919111) C:\WINDOWS\SYSTEM\mmtask.tsk
PID: 4294919111 (4291802967) C:\WINDOWS\SYSTEM\MSGSRV32.EXE
PID: 4294931575 (4294919111) C:\WINDOWS\SYSTEM\MPREXE.EXE
--- Browser start & search pages list ---
Spybot - Search && Destroy browser pages report, 7-6-04 16:51:34
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\SYSTEM\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
http://g.msn.nl/0SENLNL/SAOS01
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.deeppurple.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Startpagina
file:///C:/Program%20Files/QuickPage/Portal/portal.html
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\SYSTEM\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
--- Winsock Layered Service Provider list ---
Protocol 0: MS.w95.spi.osp
GUID: {FF017DE1-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\mswsosp.dll
Description: Microsoft Windows 9x/ME name space provider
DB filename: %windir%\system\mswsosp.dll
DB protocol: MS.w95.spi.*
Protocol 1: MS.w95.spi.tcp
GUID: {FF017DE0-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\msafd.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\msafd.dll
DB protocol: MS.w95.spi.*
Protocol 2: MS.w95.spi.udp
GUID: {FF017DE0-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\msafd.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\msafd.dll
DB protocol: MS.w95.spi.*
Protocol 3: MS.w95.spi.raw
GUID: {FF017DE0-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\msafd.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\msafd.dll
DB protocol: MS.w95.spi.*
Protocol 4: MS.w95.spi.rsvptcp
GUID: {ECBDCBA0-334A-11D0-BD88-0000C082E69A}
Filename: C:\WINDOWS\SYSTEM\rsvpsp.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\rsvoso.dll
DB protocol: MS.w95.spi.*
Protocol 5: MS.w95.spi.rsvpudp
GUID: {ECBDCBA0-334A-11D0-BD88-0000C082E69A}
Filename: C:\WINDOWS\SYSTEM\rsvpsp.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\rsvoso.dll
DB protocol: MS.w95.spi.*
Namespace Provider 0: DNS Name Space Provider.
GUID: {FF017DE2-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\rnr20.dll
Description: Microsoft Windows 9x/ME name space provider
DB filename: %windir%\system\rnr20.dll
DB protocol: DNS Name Space Provider.
Sinds 4 dagen krijg ik onderstaand foutmelding als ik op de systeemiconen (mijn computer, netwerkverbinding, mijn documenten, mijn muziek) op het bureaublad tik, ze werken niet meer en geven het volgende te lezen: EXPLORER heeft een fout met betrekking tot een ongeldige pagina veroorzaakt in
module <onbekend> op0000:07c7fc6e.
Registers:
EAX=0045d44c CS=0187 EIP=07c7fc6e EFLGS=00010246
EBX=01d609f0 SS=018f ESP=00e8be20 EBP=00e8be3c
ECX=50002fa8 DS=018f ESI=01d609f8 FS=380f
EDX=00e8be30 ES=018f EDI=00e8c150 GS=0000
Bytes in CS:EIP:
Stackdump:
01c25da1 0045d44c 00e8be30 00000000 00000000 0045d44c 00444080 00e8be88 01c25de2 00e8c150 01d609f8 00000000 00000000 00000000 00000000 00e8c0a0
Sinds vandaag valt ook af en toe de internetverbinding weg.
Verder kan ik emails alleen maar verzenden als ik Norton antivirus uitzet (anders valt de verbinding tijdens de scan van NAV weg). Voor de volledigheid plaats ik mijn logfil hieronder voor de kenners.
Wie weet raad?.
Alle programmaicoontjes werken wel. Hoe kan ik dit herstellen? Herstarten helpt niet!
Inmiddels Spyware scan gedaan; helpt niet; dan maar de Hijack eroverheen gezet en bijgaande logfiles aangemaakt:
Zie hieronder
--- Search result list ---
--- Spybot - Search && Destroy version: 1.3 ---
2004-05-25 Includes\Cookies.sbi
2004-05-29 Includes\Dialer.sbi
2004-05-28 Includes\Hijackers.sbi
2004-05-28 Includes\Keyloggers.sbi
2004-05-28 Includes\Malware.sbi
2004-05-04 Includes\Revision.sbi
2004-04-12 Includes\Security.sbi
2004-05-28 Includes\Spybots.sbi
2004-05-28 Includes\Trojans.sbi
2004-05-12 Includes\LSP.sbi
2004-05-24 Includes\Tracks.uti
--- System information ---
Windows 98 (Build: 2222) A
/ DataAccess: Patch Available For XMLHTTP Vulnerability
/ DataAccess: Buffer Overrun in Microsoft Data Access Components Could Lead to Code Execution
/ DataAccess: Security update for Microsoft Data Access Components
/ Windows Media Player: Windows Media Update 320920
/ Windows Media Player: Windows Media Update 819639
/ DirectX: DirectX Update 819696
--- Startup entries list ---
Located: HK_LM:Run, NAV Agent
command: C:\PROGRA~1\NORTON~1\NAVAPW32.EXE
file: C:\PROGRA~1\NORTON~1\NAVAPW32.EXE
size: 79480
MD5: 44a716c6eda439a804c2833e0c16da82
Located: HK_LM:Run, ScanRegistry
command: C:\WINDOWS\scanregw.exe /autorun
file: C:\WINDOWS\scanregw.exe
size: 90112
MD5: 197de4470e262d1f86fb088949c0386a
Located: HK_LM:Run, Symantec NetDriver Monitor
command: C:\PROGRA~1\SYMANTEC\LIVEUP~1\SNDMON.EXE
file: C:\PROGRA~1\SYMANTEC\LIVEUP~1\SNDMON.EXE
size: 87184
MD5: c16b92488d9499171a63225f487f7d20
Located: HK_LM:Run, CMESys (DISABLED)
command: "C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE"
Located: HK_LM:Run, CriticalUpdate (DISABLED)
command: C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
file: C:\WINDOWS\SYSTEM\wucrtupd.exe
size: 135168
MD5: d4060358f5955cfe4fbad2c2f5dc8a40
Located: HK_LM:Run, FLMTRUSTMOUSE (DISABLED)
command: C:\Program Files\Trust mouse utility\1.0\mouse32a.exe
file: C:\Program Files\Trust mouse utility\1.0\mouse32a.exe
size: 429568
MD5: a06b0f3b1aaac26f3a96f640b1108320
Located: HK_LM:Run, LoadQM (DISABLED)
command: loadqm.exe
Located: HK_LM:Run, QuickTime Task (DISABLED)
command: "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
file: C:\WINDOWS\SYSTEM\QTTASK.EXE
size: 77824
MD5: 5d22b4258489575412f6d18affc847a2
Located: HK_LM:Run, SpeedOptimizer (DISABLED)
command: "C:\PROGRA~1\SPEEDO~1\SPO.EXE" -s
file: C:\PROGRA~1\SPEEDO~1\SPO.EXE
size: 607232
MD5: 9e39286bd9af22d5991df64d58556f43
Located: HK_LM:Run, SpeedTouch USB Diagnostics (DISABLED)
command: "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
file: C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
size: 861184
MD5: 6551d483e62ebb75015686845092d4df
Located: HK_LM:Run, SystemTray (DISABLED)
command: SysTray.Exe
file: C:\WINDOWS\SYSTEM\SysTray.Exe
size: 27648
MD5: c7e1448ef194081ca615b2601e9751fd
Located: HK_LM:Run, Taakcontrole (DISABLED)
command: C:\WINDOWS\taskmon.exe
file: C:\WINDOWS\taskmon.exe
size: 28672
MD5: 68c189ce09541b3efd9b502f3c18c7c6
Located: HK_LM:Run, TrustInstaller (DISABLED)
command: D:\SETUP.EXE
Located: HK_LM:Run, WinampAgent (DISABLED)
command: "C:\Program Files\Winamp3\winampa.exe"
file: C:\Program Files\Winamp3\winampa.exe
size: 12288
MD5: 6bf81517c708f53b8e22eb624ee3723a
Located: HK_LM:RunServices, LoadPowerProfile (DISABLED)
command: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
file: C:\WINDOWS\Rundll32.exe
size: 24576
MD5: 5b093875e9f565e086f8aefb94160f79
Located: HK_LM:RunServices, MessengerPlus2 (DISABLED)
command: "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
Located: HK_LM:RunServices, SchedulingAgent (DISABLED)
command: mstask.exe
file: C:\WINDOWS\SYSTEM\mstask.exe
size: 112912
MD5: a31befa7baa6947cda52b2bc3857d2cc
Located: HK_LM:RunServices, ScriptBlocking (DISABLED)
command: "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
file: C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
size: 54408
MD5: 3db0459e2661531bfe88ae0a182d019a
Located: HK_LM:RunServices, WinRoute (DISABLED)
command: C:\PROGRAM FILES\WINROUTE PRO\Winroute.exe /hide
Located: HK_CU:Run, MessengerPlus2 (DISABLED)
command: "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
Located: HK_CU:Run, MSMSGS (DISABLED)
command: "C:\Program Files\Messenger\msmsgs.exe" /background
Located: HK_CU:Run, Taskbar Display Controls (DISABLED)
command: RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
file: C:\WINDOWS\RunDLL.exe
size: 5155
MD5: c6bb2a882611a6351b1dee41e6ef2198
--- Browser helper object list ---
{0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} (DAPBHO Class)
BHO name:
CLSID name: DAPBHO Class
description: Download Accelerator plus
classification: Open for discussion
known filename: Dapiebar.dll
info link: http://www.speedbit.com/DefaultT.asp?
info source: TonyKlein
Path: C:\PROGRAM FILES\DAP\
Long name: DAPIEBAR.DLL
Short name:
Date (created): 29-7-02 17:29:46
Date (last access): 7-6-04
Date (last write): 11-11-03 10:19:24
Filesize: 405504
Attributes: archive
MD5: 8E21C09D56A479532B55BBEAC6062730
CRC32: A57567A2
Version: 0.5.0.3
{BDF3E430-B101-42AD-A544-FADC6B084872} (NAV Helper)
BHO name: NAV Helper
CLSID name: CNavExtBho Class
description: Norton Antivirus
classification: Legitimate
known filename: NavShExt.dll
info link: http://www.symantec.com/nav/nav_9xnt/
info source: TonyKlein
Path: C:\Program Files\Norton AntiVirus\
Long name: NAVSHEXT.DLL
Short name:
Date (created): 29-4-02 11:50:30
Date (last access): 7-6-04
Date (last write): 20-3-02 12:00:40
Filesize: 102400
Attributes: archive
MD5: 2EAB9D2A0AFE9BE089924458522CDF93
CRC32: 95E2EA74
Version: 0.8.0.0
{F281FFC7-6C63-4bf9-83F2-AB7A6157B109} (Core Library)
BHO name: Core Library
CLSID name: Veevo Object
Path: C:\WINDOWS\SYSTEM\
Long name: KDP3313.dll
Short name: KDP3313.DLL
Date (created): 29-5-04 0:07:12
Date (last access): 7-6-04
Date (last write): 29-5-04 0:07:14
Filesize: 159744
Attributes: archive
MD5: CBE6F8A705F911D52C7A10D4B26A4042
CRC32: 1F047AD5
{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDHelper.dll
info link: http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\PROGRA~1\SPYBOT~1\
Long name: SDHelper.dll
Short name: SDHELPER.DLL
Date (created): 12-5-04 1:03:00
Date (last access): 7-6-04
Date (last write): 12-5-04 1:03:00
Filesize: 744960
Attributes: archive
MD5: ABF5BA518C6A5ED104496FF42D19AD88
CRC32: 5587736E
Version: 0.1.0.3
--- ActiveX list ---
Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla
DirectAnimation Java Classes (DirectAnimation Java Classes)
DPF name: DirectAnimation Java Classes
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\dajava.cab
info link:
info source: Patrick M. Kolla
Internet Explorer Classes for Java (Internet Explorer Classes for Java)
DPF name: Internet Explorer Classes for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\iejava.cab
info link:
info source: Patrick M. Kolla
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM\MACROMED\FLASH\
Long name: Flash.ocx
Short name: FLASH.OCX
Date (created): 4-9-03 14:17:58
Date (last access): 7-6-04
Date (last write): 8-12-03 14:01:58
Filesize: 933888
Attributes: archive
MD5: F7E435D02F7A48120B746E33254A70BC
CRC32: 02AF493D
Version: 0.7.0.0
{9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class)
DPF name:
CLSID name: Update Class
description: Windows Update
classification: Legitimate
known filename: %WINDIR%\System32\iuctl.dll,iuengine.dll
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM\
Long name: iuctl.dll
Short name: IUCTL.DLL
Date (created): 21-8-03 16:47:54
Date (last access): 7-6-04
Date (last write): 21-8-03 16:47:54
Filesize: 162400
Attributes:
MD5: DB2F1F57D3057FEBC19C61AB9AA77198
CRC32: 5A03D776
Version: 0.5.0.3
{CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class)
DPF name:
CLSID name: Downloader Class
Path: C:\WINDOWS\DOWNLO~1\
Long name: dwnldr.dll
Short name: DWNLDR.DLL
Date (created): 15-12-02 6:46:04
Date (last access): 7-6-04
Date (last write): 15-12-02 6:46:04
Filesize: 102400
Attributes:
MD5: 6C85378C0DD243C9C4685EB01DE7CB72
CRC32: 2F4BF700
Version: 0.2.0.0
{2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy)
DPF name:
CLSID name: ChainCast VMR Client Proxy
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: ccpm_0237.dll
Short name: CCPM_0~1.DLL
Date (created): 19-12-02 19:09:44
Date (last access): 7-6-04
Date (last write): 19-12-02 19:09:44
Filesize: 1488120
Attributes:
MD5: 2E2942127C097A132ED6FA3451BAEA06
CRC32: 9CCC07CD
Version: 0.3.0.0
{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} ()
DPF name:
CLSID name:
{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
description: Macromedia ShockWave Flash Player 7
classification: Unknown
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\
Long name: SWDIR.DLL
Short name:
Date (created): 15-11-03 14:25:56
Date (last access): 7-6-04
Date (last write): 11-2-03 6:02:58
Filesize: 32768
Attributes: archive
MD5: 92FA0AE21D3A08B65D291724AA7D0E43
CRC32: 7B63A9DB
Version: 0.8.0.5
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object)
DPF name:
CLSID name: QuickTime Object
description: Apple Quicktime
classification: Legitimate
known filename: QTPLUGIN.OCX
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM\
Long name: QTPlugin.ocx
Short name: QTPLUGIN.OCX
Date (created): 24-11-03 19:51:34
Date (last access): 7-6-04
Date (last write): 24-11-03 19:51:36
Filesize: 327736
Attributes: archive
MD5: CE3D865CCF4267C85934D9B7CA8521F2
CRC32: F9306ACA
Version: 0.6.0.4
{CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class)
DPF name:
CLSID name: Live365Player Class
Path: C:\WINDOWS\DOWNLO~1\
Long name: Play365.dll
Short name: PLAY365.DLL
Date (created): 6-6-03 18:06:56
Date (last access): 7-6-04
Date (last write): 6-6-03 18:06:56
Filesize: 335872
Attributes:
MD5: 02D3243B77F6C3EFBF67AAD62C26B443
CRC32: FA8AB3C6
Version: 0.1.0.0
{8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class)
DPF name:
CLSID name: MessengerStatsClient Class
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: messengerstatsclient.dll
Short name: MESSEN~1.DLL
Date (created): 29-5-03 15:00:20
Date (last access): 7-6-04
Date (last write): 29-5-03 15:00:20
Filesize: 160864
Attributes:
MD5: B069B555A00AA026F657AA4FD13AE154
CRC32: 89BB01E1
Version: 0.7.0.1
{2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class)
DPF name:
CLSID name: Minesweeper Flags Class
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: minesweeper.dll
Short name: MINESW~1.DLL
Date (created): 29-5-03 15:00:22
Date (last access): 7-6-04
Date (last write): 29-5-03 15:00:22
Filesize: 84064
Attributes:
MD5: F951FD0EA383DF2D49CA0359E4A86968
CRC32: 50A69718
Version: 0.7.0.1
{00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class)
DPF name:
CLSID name: Checkers Class
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: msgrchkr.dll
Short name: MSGRCHKR.DLL
Date (created): 29-5-03 15:00:18
Date (last access): 7-6-04
Date (last write): 29-5-03 15:00:18
Filesize: 77408
Attributes:
MD5: 42D567DF86B9B7AC4A89664C9651B68B
CRC32: 47FF3D19
Version: 0.7.0.1
{F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class)
DPF name:
CLSID name: Solitaire Showdown Class
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: solitaireshowdown.dll
Short name: SOLITA~1.DLL
Date (created): 29-5-03 15:00:20
Date (last access): 7-6-04
Date (last write): 29-5-03 15:00:20
Filesize: 86112
Attributes:
MD5: 6E0E81210B17C225AD8DBB86F0C41E32
CRC32: 1C944476
Version: 0.7.0.1
{841A9192-5690-11D4-A258-0040954A01BE} ()
DPF name:
CLSID name:
{018A066F-584A-422F-AC4C-0B1F5FE5C040} (VacPro.olanda_ver3)
DPF name:
CLSID name: VacPro.olanda_ver3
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: olanda_ver3.ocx
Short name: OLANDA~1.OCX
Date (created): 1-4-04 15:23:30
Date (last access): 7-6-04
Date (last write): 1-4-04 15:23:30
Filesize: 49152
Attributes:
MD5: 3FE1E3BAE0E58C66B6582332B658F60A
CRC32: 31B67F0F
Version: 0.1.0.0
{80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control)
DPF name:
CLSID name: AvxScanOnline Control
description: BitDefender online virus scanner
classification: Legitimate
known filename: bitdefender.ocx
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\DOWNLO~1\
Long name: bitdefender.ocx
Short name: BITDEF~1.OCX
Date (created): 22-3-02 16:58:34
Date (last access): 7-6-04
Date (last write): 22-3-02 16:58:34
Filesize: 344064
Attributes:
MD5: EAEAED4BF93D9BD5A87415DB3121C46B
CRC32: E0EDEC5D
Version: 0.2.0.0
--- Process list ---
Spybot - Search && Destroy process list report, 7-6-04 16:51:34
PID: 4291802967 (2121258659) C:\WINDOWS\SYSTEM\KERNEL32.DLL
PID: 4294574767 (4294902343) C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE
PID: 4294668903 (4294561755) C:\WINDOWS\SYSTEM\DDHELP.EXE
PID: 4294709959 (4294693271) C:\WINDOWS\SYSTEM\PSTORES.EXE
PID: 4294753039 (4294652431) C:\WINDOWS\SYSTEM\SPOOL32.EXE
PID: 4294759519 (4294784127) C:\WINDOWS\SYSTEM\TAPISRV.EXE
PID: 4294784127 (4294858563) C:\WINDOWS\SYSTEM\RNAAPP.EXE
PID: 4294880047 (4294902343) C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
PID: 4294902343 (4294919111) C:\WINDOWS\EXPLORER.EXE
PID: 4294906695 (4294919111) C:\WINDOWS\SYSTEM\mmtask.tsk
PID: 4294919111 (4291802967) C:\WINDOWS\SYSTEM\MSGSRV32.EXE
PID: 4294931575 (4294919111) C:\WINDOWS\SYSTEM\MPREXE.EXE
--- Browser start & search pages list ---
Spybot - Search && Destroy browser pages report, 7-6-04 16:51:34
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\SYSTEM\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
http://g.msn.nl/0SENLNL/SAOS01
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.deeppurple.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Startpagina
file:///C:/Program%20Files/QuickPage/Portal/portal.html
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\SYSTEM\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
--- Winsock Layered Service Provider list ---
Protocol 0: MS.w95.spi.osp
GUID: {FF017DE1-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\mswsosp.dll
Description: Microsoft Windows 9x/ME name space provider
DB filename: %windir%\system\mswsosp.dll
DB protocol: MS.w95.spi.*
Protocol 1: MS.w95.spi.tcp
GUID: {FF017DE0-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\msafd.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\msafd.dll
DB protocol: MS.w95.spi.*
Protocol 2: MS.w95.spi.udp
GUID: {FF017DE0-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\msafd.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\msafd.dll
DB protocol: MS.w95.spi.*
Protocol 3: MS.w95.spi.raw
GUID: {FF017DE0-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\msafd.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\msafd.dll
DB protocol: MS.w95.spi.*
Protocol 4: MS.w95.spi.rsvptcp
GUID: {ECBDCBA0-334A-11D0-BD88-0000C082E69A}
Filename: C:\WINDOWS\SYSTEM\rsvpsp.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\rsvoso.dll
DB protocol: MS.w95.spi.*
Protocol 5: MS.w95.spi.rsvpudp
GUID: {ECBDCBA0-334A-11D0-BD88-0000C082E69A}
Filename: C:\WINDOWS\SYSTEM\rsvpsp.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\rsvoso.dll
DB protocol: MS.w95.spi.*
Namespace Provider 0: DNS Name Space Provider.
GUID: {FF017DE2-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\rnr20.dll
Description: Microsoft Windows 9x/ME name space provider
DB filename: %windir%\system\rnr20.dll
DB protocol: DNS Name Space Provider.
Laatst bewerkt: