Mededeling

Collapse
No announcement yet.

wat is hier fout aan ?

Collapse
This topic is closed.
X
X
 
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • wat is hier fout aan ?

    ik krijg steeds een werkbalk van coolwebsites hoe te verwijderen?


    Logfile of HijackThis v1.98.2
    Scan saved at 23:58:52, on 1-11-2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\RaboCommSrv.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\PROGRA~1\KEMailKb\KEMailKb.EXE
    C:\Program Files\Messenger Plus! 3\MsgPlus.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    c:\progra~1\intern~1\iexplore.exe
    c:\progra~1\intern~1\iexplore.exe
    C:\Program Files\Rabotwin\RaboComm\RaboSessionMon.exe
    C:\Program Files\TVFM Tuner\QuickTV.exe
    C:\Program Files\Windows NT\Bureau-accessoires\wordpad.exe
    D:\Installatie\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.ebskbnpwfjagknipmkmusjnjn.com/YaXjPVnmWa8anCa1JLl/_h/n6wukXHtiboLb74yuL6EFa98eI93G4vAcRmP6P4fd.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bydmteumlgilwbphhjbtb.us/YaXjPVnmWa/nJTzVLn_YUnUVHcQa6VZxe63vmfmsS0M.jpg
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {C3E56083-9409-9254-840F-A8F9475D7E77} - C:\DOCUME~1\MATTH~1\APPLIC~1\SCRMPE~1\MessLive.exe
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [KEMailKb] C:\PROGRA~1\KEMailKb\KEMailKb.EXE
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKLM\..\Run: [About Bird Each Inter] C:\Documents and Settings\All Users\Application Data\Errorpopaboutbird\creative proxy.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Htm browse] C:\DOCUME~1\MATTH~1\APPLIC~1\ONLINE~1\flap boob.exe
    O4 - Startup: QuickTV.lnk = C:\Program Files\TVFM Tuner\QuickTV.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Rabo Session Monitor.lnk = C:\Program Files\Rabotwin\RaboComm\RaboSessionMon.exe
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093549673050

  • #2
    Hoi Boekm02,

    Welkom op ASO!

    1. Vink onderstaande regels aan in HijackThis:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.ebskbnpwfjagknipmkmusjnjn...AcRmP6P4fd.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bydmteumlgilwbphhjbtb.us/...63vmfmsS0M.jpg

    O2 - BHO: (no name) - {C3E56083-9409-9254-840F-A8F9475D7E77} - C:\DOCUME~1\MATTH~1\APPLIC~1\SCRMPE~1\MessLive.exe

    O4 - HKLM\..\Run: [About Bird Each Inter] C:\Documents and Settings\All Users\Application Data\Errorpopaboutbird\creative proxy.exe
    O4 - HKCU\..\Run: [Htm browse] C:\DOCUME~1\MATTH~1\APPLIC~1\ONLINE~1\flap boob.exe
    2. Sluit alle andere vensters en browsers, en klik op de knop “Fix Checked”.

    3. Start opnieuw op in veilige modus.
    Zorg ervoor dat verborgen bestanden en mappen zichtbaar zijn: Verkenner > Extra > Mapopties > Tablad Weergave > scroll naar beneden en vink het vakje voor "Verborgen bestanden en mappen weergeven" aan.

    4. Ga naar Windows Verkenner (Rechtsklikken op Start - Verkennen). Zoek en verwijder het volgende:
    Mappen:
    C:\Documents and Settings\MATTH~1\Application Data\SCRMPE...
    C:\Documents and Settings\All Users\Application Data\Errorpopaboutbird
    C:\Documents and Settings\MATTH~1\Application Data\ONLINE...

    5. Start opnieuw op in normale modus, maak een nieuw logje aan met HijackThis, en post dat hier

    Comment


    • #3
      Aangezien reactie is uitgebleven, veronderstel ik dat het probleem is opgelost en sluit ik deze thread.

      Comment

      Working...
      X