Mededeling

Collapse
No announcement yet.

Vervelende startpagina

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Vervelende startpagina

    Hier het log van Hans,

    Hij heeft gescanned met Adaware en Spybot en mij het log toegestuurd.
    Switch dialer verwijderd.
    Graag jullie advies.

    bvd Sonja

    Logfile of HijackThis v1.99.0
    Scan saved at 20:23:02, on 27-12-04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WIN98\SYSTEM\KERNEL32.DLL
    C:\WIN98\SYSTEM\MSGSRV32.EXE
    C:\WIN98\SYSTEM\MPREXE.EXE
    C:\WIN98\SYSTEM\mmtask.tsk
    C:\WIN98\SYSTEM\MSTASK.EXE
    C:\WIN98\SYSTEM\ZONELABS\VSMON.EXE
    C:\WIN98\EXPLORER.EXE
    C:\OPLIMIT\OCRAWARE.EXE
    C:\OPLIMIT\OCRAWR32.EXE
    C:\WIN98\SYSTEM\SYSTRAY.EXE
    C:\WIN98\SYSTEM\ATICWD32.EXE
    C:\WIN98\SYSTEM\ATITASK.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
    C:\WIN98\LOADQM.EXE
    C:\WIN98\SYSTEM\QTTASK.EXE
    C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
    C:\WIN98\RunDLL.exe
    C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE
    C:\PROGRAM FILES\REDEI ENTERPRISES\POPUPKILLER\DLLMGR.EXE
    C:\WIN98\SYSTEM\WMIEXE.EXE
    C:\BORGIRC 2\MIRC.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\WIN98\DESKTOP\NIEUWE MAP\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.nl/0SENLNL/SAOS01
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.nl/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Startpagina = file:///C:/Program%20Files/EnterOne/Portal/portal.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    F1 - win.ini: load=C:\OPLIMIT\ocraware.exe
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_5_5_0.DLL
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WIN98\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_5_5_0.DLL
    O4 - HKLM\..\Run: [ScanRegistry] C:\WIN98\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
    O4 - HKLM\..\Run: [AtiKey] Atitask.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
    O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WIN98\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [CriticalUpdate] C:\WIN98\SYSTEM\wucrtupd.exe -startup
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [TrueVector] C:\WIN98\SYSTEM\ZONELABS\VSMON.EXE -service
    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Application\Software\Microsoft Office\Office10\OSA.EXE
    O4 - Startup: PopupKiller.lnk = C:\Program Files\Redei Enterprises\PopupKiller\DLLmgr.exe
    O4 - User Startup: Microsoft Office.lnk = C:\Program Files\Application\Software\Microsoft Office\Office10\OSA.EXE
    O4 - User Startup: PopupKiller.lnk = C:\Program Files\Redei Enterprises\PopupKiller\DLLmgr.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\APPLIC~1\SOFTWARE\MICROS~1\OFFICE10\EXCEL.EXE/3000
    O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab
    Last edited by esjeka; 27-12-04, 21:40.

  • #2
    Hoi Esjeka, welkom op ASO

    Hans mag dit item nog even laten fixen:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Startpagina = file:///C:/Program%20Files/EnterOne/Portal/portal.html

    Daarna moet de map C:\Program Files\EnterOne nog even worden verwijderd, als die er nog is. Maar die is er vast niet meer.

    Comment


    • #3
      Alles is weer prima in orde.
      Mijn hartelijke dank, ook namens Hans

      Gr. Sonja

      Comment


      • #4
        Graag gedaan.

        Comment

        Sorry, you are not authorized to view this page
        Working...
        X