Beste Pieter,
Het probleem is terug.
Alleen heeft het bestand in c;\windiws\system nu een andere naam en heet nu: dbhcba.dll
Ik heb dezelfde procedure gedraaid als waarmee ik de vorige keer de problemen verholpen heb:
1) cwschredder gedraaid..alles laten verwijderen
2) adaware gedraaid..alles laten verwijderen
3) met killbox genoemd bestandje verwijderd
4) hijacklog gedraaid en alle regels waar dbhcba.dll in voorkomt verwijderd (gefixed)
5) in configuraitescherm startpagina weer juist ingesteld
6) reboot
Alles zou nu weer opgelost moeten zijn !!!!!!!
ECHTER:
Ik krijg nu steeds wanneer ik de pc opnieuw opstart bij het opstarten van explorer de volgende internet explorer melding: SPYWARE ALERT-Microsoft internet explorer.
Spyware activity detected on your computer.
Vervolgens ga ik kijken of alles weggebleven is.
1) CWSchredder vindt continu dezelfde fouten. Ik zal de lijst zometeen bijvoegen. Steeds de searchx wordt removed en 6 infected IE registry values.
2) adaware vindt dan nog 1 spybot. (STEEDS HOMEOLDSP). lijst wordt toegevoegd.
3) bestand staat wederom in c windows system
Ik kan de procedure weer doorlopen, echter steeds dezelfde situatie.
CWSCHREDDER log:
Done!
Removed from your system:
- CWS.Searchx
- 6 infected IE registry values
Windows ME (4.90.3000 )
CWShredder v1.57.0
Written by Merijn - 
merijn@spywareinfo.com
For any additional help with this program or removing CWS, visit:
http://forums.spywareinfo.com/
For information and documentation on the Coolwebsearch
trojan and its variants, visit:
http://www.spywareinfo.com/~merijn/cwschronicles.html
For donations to help support CWShredder, visit:
http://www.spywareinfo.com/~merijn/donate.html
ADWARE LOG:
Lavasoft Ad-aware Personal Build 6.181
Logfile created on  :zondag 2 mei 2004 17:46:24
Created with Ad-aware Personal, free for private use.
Using reference-file :01R300 28.04.2004
______________________________________________________
Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
2-5-2004 17:46:24 - Scan started. (Smart mode)
Listing running processes
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
#:1 [kernel32.dll]
    FilePath           : C:\WINDOWS\SYSTEM\
    ProcessID          : 4279195411
    Threads            : 8
    Priority           : High
    FileSize           : 532 KB
    FileVersion        : 4.90.3000
    ProductVersion     : 4.90.3000
    Copyright          : Copyright (C) Microsoft Corp. 1991-2000
    CompanyName        : Microsoft Corporation
    FileDescription    : Win32 Kernel-kerncomponent
    InternalName       : KERNEL32
    OriginalFilename   : KERNEL32.DLL
    ProductName        : Besturingssysteem Microsoft(R) Windows(R) Millennium
    Created on         : 1-1-1601
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 8-6-2000 15:00:00
#:2 [msgsrv32.exe]
    FilePath           : C:\WINDOWS\SYSTEM\
    ProcessID          : 4294935179
    Threads            : 1
    Priority           : Normal
    FileSize           : 11 KB
    FileVersion        : 4.90.3000
    ProductVersion     : 4.90.3000
    Copyright          : Copyright (C) Microsoft Corp. 1992-1998
    CompanyName        : Microsoft Corporation
    FileDescription    : Windows 32-bits VxD-berichtserver
    InternalName       : MSGSRV32
    OriginalFilename   : MSGSRV32.EXE
    ProductName        : Besturingssysteem Microsoft(R) Windows(R) Millennium
    Created on         : 1-1-1601
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 8-6-2000 15:00:00
#:3 [mmtask.tsk]
    FilePath           : C:\WINDOWS\SYSTEM\
    ProcessID          : 4294845087
    Threads            : 1
    Priority           : Normal
    FileSize           : 1 KB
    FileVersion        : 4.90.3000
    ProductVersion     : 4.90.3000
    Copyright          : Copyright  
    CompanyName        : Microsoft Corporation
    FileDescription    : Multimedia background task support module
    InternalName       : mmtask.tsk
    OriginalFilename   : mmtask.tsk
    ProductName        : Microsoft Windows
    Created on         : 1-1-1601
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 8-6-2000 15:00:00
#:4 [mprexe.exe]
    FilePath           : C:\WINDOWS\SYSTEM\
    ProcessID          : 4294847707
    Threads            : 2
    Priority           : Normal
    FileSize           : 28 KB
    FileVersion        : 4.90.3000
    ProductVersion     : 4.90.3000
    Copyright          : Copyright (C) Microsoft Corp. 1993-2000
    CompanyName        : Microsoft Corporation
    FileDescription    : WIN32 Network Interface Service Process
    InternalName       : MPREXE
    OriginalFilename   : MPREXE.EXE
    ProductName        : Microsoft(R) Windows(R) Millennium Operating System
    Created on         : 1-1-1601
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 8-6-2000 15:00:00
#:5 [mstask.exe]
    FilePath           : C:\WINDOWS\SYSTEM\
    ProcessID          : 4294862627
    Threads            : 4
    Priority           : Normal
    FileSize           : 124 KB
    FileVersion        : 4.71.2721.1
    ProductVersion     : 4.71.2721.1
    Copyright          : Copyright (C) Microsoft Corp. 2000
    CompanyName        : Microsoft Corporation
    FileDescription    : Taakplanner Engine
    InternalName       : Taakplanner
    OriginalFilename   : mstask.exe
    ProductName        : Microsoft 
    Created on         : 1-1-1601
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 8-6-2000 15:00:00
#:6 [ssdpsrv.exe]
    FilePath           : C:\WINDOWS\SYSTEM\
    ProcessID          : 4294876091
    Threads            : 5
    Priority           : Normal
    FileSize           : 55 KB
    FileVersion        : 4.90.3002.0
    ProductVersion     : 4.90.3002.0
    Copyright          : Copyright (C) Microsoft Corp. 1981-2000
    CompanyName        : Microsoft Corporation
    FileDescription    : SSDP Service on Windows Millennium
    InternalName       : ssdpsrv.exe
    OriginalFilename   : ssdpsrv.exe
    ProductName        : Microsoft(R) Windows(R) Millennium Operating System
    Created on         : 19-2-2002 21:30:43
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 28-9-2001 15:53:22
#:7 [ccevtmgr.exe]
    FilePath           : C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\
    ProcessID          : 4294785227
    Threads            : 19
    Priority           : Normal
    FileSize           : 313 KB
    FileVersion        : 1.03.4
    ProductVersion     : 1.03.4
    Copyright          : Copyright (c) 2000-2002 Symantec Corporation. All rights reserved.
    CompanyName        : Symantec Corporation
    FileDescription    : Event Manager Service
    InternalName       : ccEvtMgr
    OriginalFilename   : ccEvtMgr.exe
    ProductName        : Event Manager
    Created on         : 28-11-2002 7:44:02
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 28-11-2002 7:44:02
#:8 [explorer.exe]
    FilePath           : C:\WINDOWS\
    ProcessID          : 4294800615
    Threads            : 26
    Priority           : Normal
    FileSize           : 220 KB
    FileVersion        : 5.50.4134.100
    ProductVersion     : 5.50.4134.100
    Copyright          : Copyright (C) Microsoft Corp. 1981-2000
    CompanyName        : Microsoft Corporation
    FileDescription    : Windows Verkenner
    InternalName       : explorer
    OriginalFilename   : EXPLORER.EXE
    ProductName        : Besturingssysteem Microsoft(R) Windows (R) 2000
    Created on         : 8-6-2000 15:00:00
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 8-6-2000 15:00:00
#:9 [stmgr.exe]
    FilePath           : C:\WINDOWS\SYSTEM\RESTORE\
    ProcessID          : 4294740163
    Threads            : 5
    Priority           : Normal
    FileSize           : 60 KB
    FileVersion        : 4.90.0.2533
    ProductVersion     : 4.90.0.2533
    Copyright          : Copyright (C) Microsoft Corp. 1981-2000
    CompanyName        : Microsoft Corporation
    FileDescription    : Microsoft (R) PC State Manager
    InternalName       : StateMgr.exe
    OriginalFilename   : StateMgr.exe
    ProductName        : Microsoft (r) PCHealth
    Created on         : 1-1-1601
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 8-6-2000 15:00:00
#:10 [taskmon.exe]
    FilePath           : C:\WINDOWS\
    ProcessID          : 4294669663
    Threads            : 2
    Priority           : Normal
    FileSize           : 28 KB
    FileVersion        : 4.90.3000
    ProductVersion     : 4.90.3000
    Copyright          : Copyright (C) Microsoft Corp. 1998
    CompanyName        : Microsoft Corporation
    FileDescription    : Task Monitor
    InternalName       : TaskMon
    OriginalFilename   : TASKMON.EXE
    ProductName        : Microsoft(R) Windows(R) Millennium Operating System
    Created on         : 1-1-1601
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 8-6-2000 15:00:00
#:11 [systray.exe]
    FilePath           : C:\WINDOWS\SYSTEM\
    ProcessID          : 4294759595
    Threads            : 3
    Priority           : Normal
    FileSize           : 36 KB
    FileVersion        : 4.90.3000
    ProductVersion     : 4.90.3000
    Copyright          : Copyright (C) Microsoft Corp. 1993-2000
    CompanyName        : Microsoft Corporation
    FileDescription    : Systeemwerkblad-applet
    InternalName       : SYSTRAY
    OriginalFilename   : SYSTRAY.EXE
    ProductName        : Besturingssysteem Microsoft(R) Windows(R) Millennium
    Created on         : 1-1-1601
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 8-6-2000 15:00:00
#:12 [starter.exe]
    FilePath           : C:\WINDOWS\
    ProcessID          : 4294691539
    Threads            : 2
    Priority           : Normal
    FileSize           : 32 KB
    FileVersion        : 5.00.05
    ProductVersion     : 5.00.05
    Copyright          : Copyright  
    CompanyName        : Creative Technology, Ltd.
    FileDescription    : This program launches the mixer application.
    InternalName       : starter
    OriginalFilename   : starter.exe
    ProductName        : starter
    Created on         : 20-2-2001 11:54:42
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 10-8-2000 9:58:46
#:13 [mhotkey.exe]
    FilePath           : C:\WINDOWS\
    ProcessID          : 4294676655
    Threads            : 2
    Priority           : Normal
    FileSize           : 438 KB
    FileVersion        : 2, 0, 0, 8
    ProductVersion     : 2, 0, 0, 8
    Copyright          : Copyright (c) 2000 Chicony
    CompanyName        : Chicony
    FileDescription    : Chicony Multimedia Driver
    InternalName       : Multimedia Hotkey Driver
    OriginalFilename   : mHotkey.res
    ProductName        : Chicony Multimedia Driver
    Created on         : 20-2-2001 17:49:14
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 4-7-2000 14:38:04
#:14 [loadqm.exe]
    FilePath           : C:\WINDOWS\
    ProcessID          : 4294519579
    Threads            : 4
    Priority           : Normal
    FileSize           : 7 KB
    FileVersion        : 5.4.1103.3
    ProductVersion     : 5.4.1103.3
    Copyright          : Copyright (C) Microsoft Corp. 1981-1999
    CompanyName        : Microsoft Corporation
    FileDescription    : Microsoft QMgr
    InternalName       : LOADQM.EXE
    OriginalFilename   : LOADQM.EXE
    ProductName        : QMgr Loader
    Created on         : 4-11-2002 21:24:01
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 3-5-2000 15:23:10
#:15 [wmiexe.exe]
    FilePath           : C:\WINDOWS\SYSTEM\
    ProcessID          : 4294601079
    Threads            : 4
    Priority           : Normal
    FileSize           : 16 KB
    FileVersion        : 4.90.2452.1
    ProductVersion     : 4.90.2452.1
    Copyright          : Copyright (C) Microsoft Corp. 1981-1999
    CompanyName        : Microsoft Corporation
    FileDescription    : WMI service exe housing
    InternalName       : wmiexe
    OriginalFilename   : wmiexe.exe
    ProductName        : Microsoft(R) Windows(R) Millennium Operating System
    Created on         : 1-1-1601
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 8-6-2000 15:00:00
#:16 [hpztsb05.exe]
    FilePath           : C:\WINDOWS\SYSTEM\
    ProcessID          : 4294637655
    Threads            : 2
    Priority           : Normal
    FileSize           : 184 KB
    FileVersion        : 2,121,0,0
    ProductVersion     : 2,121,0,0
    Copyright          : Copyright (c) Hewlett-Packard Company 1999-2002
    CompanyName        : HP
    ProductName        : HP DeskJet
    Created on         : 26-3-2003 17:41:10
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 6-6-2002 19:31:34
#:17 [ccapp.exe]
    FilePath           : C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\
    ProcessID          : 4294717807
    Threads            : 18
    Priority           : Normal
    FileSize           : 56 KB
    FileVersion        : 1.08.01
    ProductVersion     : 1.08.01
    Copyright          : Copyright (c) 2000-2002 Symantec Corporation. All rights reserved.
    CompanyName        : Symantec Corporation
    FileDescription    : Common Client CC App
    InternalName       : ccApp
    OriginalFilename   : ccApp.exe
    ProductName        : Common Client
    Created on         : 13-8-2003 9:52:46
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 15-7-2003 12:56:58
#:18 [spool32.exe]
    FilePath           : C:\WINDOWS\SYSTEM\
    ProcessID          : 4294629839
    Threads            : 3
    Priority           : Normal
    FileSize           : 44 KB
    FileVersion        : 4.90.3000
    ProductVersion     : 4.90.3000
    Copyright          : Copyright (C) Microsoft Corp. 1994 - 1998
    CompanyName        : Microsoft Corporation
    FileDescription    : Spooler Sub System Process
    InternalName       : spool32
    OriginalFilename   : spool32.exe
    ProductName        : Microsoft(R) Windows(R) Millennium Operating System
    Created on         : 1-1-1601
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 8-6-2000 15:00:00
#:19 [realsched.exe]
    FilePath           : C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\
    ProcessID          : 4294626251
    Threads            : 3
    Priority           : Normal
    FileSize           : 176 KB
    FileVersion        : 0.1.0.3018
    ProductVersion     : 0.1.0.3018
    Copyright          : Copyright  
    CompanyName        : RealNetworks, Inc.
    FileDescription    : RealNetworks Scheduler
    InternalName       : schedapp
    OriginalFilename   : realsched.exe
    ProductName        : RealPlayer (32-bit) 
    Created on         : 20-4-2004 21:40:44
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 20-4-2004 21:40:46
#:20 [msnmsgr.exe]
    FilePath           : C:\PROGRAM FILES\MSN MESSENGER\
    ProcessID          : 4294536699
    Threads            : 9
    Priority           : Normal
    FileSize           : 4768 KB
    FileVersion        : 6.2.0133
    ProductVersion     : Version 6.2
    Copyright          : Copyright (c) Microsoft Corporation 1997-2004
    CompanyName        : Microsoft Corporation
    FileDescription    : MSN Messenger
    InternalName       : msnmsgr
    OriginalFilename   : msnmsgr.exe
    ProductName        : MSN Messenger
    Created on         : 19-4-2004 3:45:08
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 19-4-2004 3:45:08
#:21 [iexplore.exe]
    FilePath           : C:\PROGRAM FILES\INTERNET EXPLORER\
    ProcessID          : 4294258339
    Threads            : 1
    Priority           : Normal
    FileSize           : 89 KB
    FileVersion        : 6.00.2800.1106
    ProductVersion     : 6.00.2800.1106
    CompanyName        : Microsoft Corporation
    FileDescription    : Internet Explorer
    InternalName       : iexplore
    OriginalFilename   : IEXPLORE.EXE
    ProductName        : Besturingssysteem Microsoft 
    Created on         : 4-9-2002 7:10:22
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 4-9-2002 7:10:22
#:22 [ad-aware.exe]
    FilePath           : C:\PROGRAM FILES\LAVASOFT\AD-AWARE 6\
    ProcessID          : 4294398279
    Threads            : 3
    Priority           : Normal
    FileSize           : 668 KB
    FileVersion        : 6.0.1.181
    ProductVersion     : 6.0.0.0
    Copyright          : Copyright  
    CompanyName        : Lavasoft Sweden
    FileDescription    : Ad-aware 6 core application
    InternalName       : Ad-aware.exe
    OriginalFilename   : Ad-aware.exe
    ProductName        : Lavasoft Ad-aware Plus
    Created on         : 24-4-2004 22:06:13
    Last accessed      : 1-5-2004 22:00:00
    Last modified      : 12-7-2003 20:00:20
Memory scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
 CoolWebSearch Object recognized!
    Type               : RegValue
    Data               : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : SOFTWARE\Microsoft\Internet Explorer\Main
    Value              : HOMEOldSP
Registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 1
Objects found so far: 1
Started deep registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Deep registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 1
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Deep scanning and examining files (C

¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Performing conditional scans..
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Conditional scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 1
17:52:52 Scan complete
Summary of this scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Total scanning time :00:06:26:560
Objects scanned :36700
Objects identified :1
Objects ignored :0
New objects :1
DE HIJACKLOG GEEFT STEEDS MAAR WEER AAN:
Logfile of HijackThis v1.97.7
Scan saved at 11:21:38, on 2-5-2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\MHOTKEY.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\HPZTSB05.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\LAVASOFT\AD-AWARE 6\AD-AWARE.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\DBHCBA.DLL/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\SYSTEM\DBHCBA.DLL/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\SYSTEM\DBHCBA.DLL/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\DBHCBA.DLL/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\SYSTEM\DBHCBA.DLL/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\SYSTEM\DBHCBA.DLL/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: OpinionBar IE monitor - {6607C683-AE7C-11D4-ACD7-0050DAC291A2} - C:\PROGRA~1\OPINIO~1\MYIEMO~2.DLL
O2 - BHO: (no name) - {5B03CC1C-DE1C-4767-8A9F-D9FCA4380D10} - C:\WINDOWS\SYSTEM\DBHCBA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN TOOLBAR\01.01.1601.0\NL\MSNTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [CHotKey] mHotkey.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O9 - Extra button: Real.com (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://start.home.nl/
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - 
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - 
http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {5B27C20D-FFB6-4054-BA78-DE4A059BC75A} (Microsoft Office Template Downloader) - 
http://office.microsoft.com/dutch/TemplateGallery/msotd.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - 
http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - 
http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37567.5868287037
IK VERWIJDER steeds de 7 regels waar het genoemde bestandje in staat.
Pieter, heb je nog een advies voor me ???