Ik heb weinig verstand van dit soort zaken maar ik herkende dit probleem bij anderen en ik zag hoe zij dit doorspelen naar Helpmij. Hierbij dus ook de LOG van de laptop van mijn broer die problemen heeft met Internet Explorer en steeds de melding krijgt: Microsoft Visual C++, Runtime Library. Runtime Error! Program C:\Program Files\Internet Explorer\IEXPLORE.EXE
Abnormal program termination. Tevens staat in zijn lege browser een y met umlaut, links boven in de hoek. Het adres luidt dan About:blank.
Het O.S. is Windows XP Prof.
Wie wil even naar het log kijken en reageren?
Logfile of HijackThis v1.97.7
Scan saved at 23:35:56, on 2004-10-07
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\windows\System32\Ati2evxx.exe
D:\Aladdin Systems\Internet Cleanup\icserv.exe
C:\Program Files\Norton AntiVirus 2003\navapsvc.exe
C:\windows\System32\svchost.exe
C:\windows\Explorer.EXE
C:\windows\System32\atiptaxx.exe
C:\WINDOWS\System32\CePMTray.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\windows\Lxscho.exe
C:\Documents and Settings\PALM\Application Data\ehab.exe
C:\windows\jawa32.exe
C:\windows\System32\itnaegd.exe
D:\Aladdin Systems\Internet Cleanup\onictask.exe
D:\Crazy Browser\Crazy Browser.exe
D:\LeechGet 2002\LeechGet.exe
D:\LeechGet downloads\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.seekseek.com/quicksearch.asp?keyphrase=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer aangeboden door Het Net
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.hetnet.nl/
R3 - URLSearchHook: URLSearch Class - {965A592F-8EFA-4250-8630-7960230792F1} - C:\windows\System32\cdsm32.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497 - (no file)
O2 - BHO: (no name) - {1f0c8547-2639-4c91-b8aa-c7eca24c3163} - D:\Aladdin Systems\Internet Cleanup\ic3hlpr.dll
O2 - BHO: PopupFilter Class - {1F2E844B-8211-46ff-8262-772F03295CF4} - D:\Aladdin Systems\Internet Cleanup\PopFiltr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {6A6E50DC-BFA8-4B40-AB1B-159E03E829FD} - C:\windows\System32\lmf32.dll
O2 - BHO: (no name) - {6CFE3708-BC1C-7BB4-D357-60557FA37B3C} - C:\windows\System32\mgwvb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus 2003\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus 2003\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\windows\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\WINDOWS\System32\CePMTray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NsUpdate] C:\windows\NsUpdate.exe UPDATE
O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
O4 - HKLM\..\Run: [aqadcup] C:\windows\aqadcup.exe
O4 - HKLM\..\Run: [Jawa32] C:\windows\jawa32.exe
O4 - HKLM\..\Run: [jrzgw] C:\windows\Lxscho.exe
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.exe min
O4 - HKCU\..\Run: [Wsha] C:\Documents and Settings\PALM\Application Data\ehab.exe
O4 - HKCU\..\Run: [Jawa32] C:\windows\jawa32.exe
O4 - HKCU\..\Run: [Dssfsfe] C:\windows\System32\itnaegd.exe
O4 - Startup: IC Task Manager.lnk = D:\Aladdin Systems\Internet Cleanup\onictask.exe
O8 - Extra context menu item: Download met LeechGet - file://D:\LeechGet 2002\\AddUrl.html
O8 - Extra context menu item: Download met LeechGet Wizard - file://D:\LeechGet 2002\\Wizard.html
O8 - Extra context menu item: Verwerk met LeechGet (Parse) - file://D:\LeechGet 2002\\Parser.html
O9 - Extra button: IC 3.0 (HKLM)
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38161.6341666667
Abnormal program termination. Tevens staat in zijn lege browser een y met umlaut, links boven in de hoek. Het adres luidt dan About:blank.
Het O.S. is Windows XP Prof.
Wie wil even naar het log kijken en reageren?
Logfile of HijackThis v1.97.7
Scan saved at 23:35:56, on 2004-10-07
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\windows\System32\Ati2evxx.exe
D:\Aladdin Systems\Internet Cleanup\icserv.exe
C:\Program Files\Norton AntiVirus 2003\navapsvc.exe
C:\windows\System32\svchost.exe
C:\windows\Explorer.EXE
C:\windows\System32\atiptaxx.exe
C:\WINDOWS\System32\CePMTray.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\windows\Lxscho.exe
C:\Documents and Settings\PALM\Application Data\ehab.exe
C:\windows\jawa32.exe
C:\windows\System32\itnaegd.exe
D:\Aladdin Systems\Internet Cleanup\onictask.exe
D:\Crazy Browser\Crazy Browser.exe
D:\LeechGet 2002\LeechGet.exe
D:\LeechGet downloads\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.seekseek.com/quicksearch.asp?keyphrase=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer aangeboden door Het Net
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.hetnet.nl/
R3 - URLSearchHook: URLSearch Class - {965A592F-8EFA-4250-8630-7960230792F1} - C:\windows\System32\cdsm32.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497 - (no file)
O2 - BHO: (no name) - {1f0c8547-2639-4c91-b8aa-c7eca24c3163} - D:\Aladdin Systems\Internet Cleanup\ic3hlpr.dll
O2 - BHO: PopupFilter Class - {1F2E844B-8211-46ff-8262-772F03295CF4} - D:\Aladdin Systems\Internet Cleanup\PopFiltr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {6A6E50DC-BFA8-4B40-AB1B-159E03E829FD} - C:\windows\System32\lmf32.dll
O2 - BHO: (no name) - {6CFE3708-BC1C-7BB4-D357-60557FA37B3C} - C:\windows\System32\mgwvb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus 2003\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus 2003\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\windows\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\WINDOWS\System32\CePMTray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NsUpdate] C:\windows\NsUpdate.exe UPDATE
O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
O4 - HKLM\..\Run: [aqadcup] C:\windows\aqadcup.exe
O4 - HKLM\..\Run: [Jawa32] C:\windows\jawa32.exe
O4 - HKLM\..\Run: [jrzgw] C:\windows\Lxscho.exe
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.exe min
O4 - HKCU\..\Run: [Wsha] C:\Documents and Settings\PALM\Application Data\ehab.exe
O4 - HKCU\..\Run: [Jawa32] C:\windows\jawa32.exe
O4 - HKCU\..\Run: [Dssfsfe] C:\windows\System32\itnaegd.exe
O4 - Startup: IC Task Manager.lnk = D:\Aladdin Systems\Internet Cleanup\onictask.exe
O8 - Extra context menu item: Download met LeechGet - file://D:\LeechGet 2002\\AddUrl.html
O8 - Extra context menu item: Download met LeechGet Wizard - file://D:\LeechGet 2002\\Wizard.html
O8 - Extra context menu item: Verwerk met LeechGet (Parse) - file://D:\LeechGet 2002\\Parser.html
O9 - Extra button: IC 3.0 (HKLM)
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O10 - Unknown file in Winsock LSP: d:\aladdin systems\internet cleanup\adlsp.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38161.6341666667