Die rare balk

Status
Niet open voor verdere reacties.

Renze

Gebruiker
Lid geworden
13 jun 2003
Berichten
112
Ik heb na msn plus downloaden ook zo'n rare balk.

Logfile of HijackThis v1.94.0
Scan saved at 11:27:15, on 13-6-2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://m32048.find-quick.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://m32048.find-quick.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.leeuwarden.startbewijs.nl/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://m32048.find-quick.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.wanadoo.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar=http://m32048.find-quick.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=http://m32048.find-quick.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=http://www.wanadoo.nl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://m32048.find-quick.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Startpagina=file:///C:/Program%20Files/MS-Connect/Portal/portal.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {b20ccf0d-2437-41d3-80fd-c9c0c635561a} - C:\DOCUME~1\Renze\APPLIC~1\gpoucrqulo.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: rryccreafrn - {bfb039c9-157e-4e83-b441-0f1389407362} - C:\DOCUME~1\Renze\APPLIC~1\gpoucrqulo.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [iqulp] C:\DOCUME~1\Renze\APPLIC~1\earaoofr.exe -QuieT
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Wanadoo Menu] C:\Program Files\Wanadoo\NL\Mnu\IGOMNU.EXE /S:T
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: FreedomAudio - http://www.internetpiraten.com/webplayer/freedominstall.cab
O16 - DPF: {06EE5631-8B69-4BF6-A531-91BDDF785734} (chelloInstall.Install) - http://quickfix.chello.nl/esupport/asp/chelloInstall.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/17281d545e7ca4493e15/netzip/RdxIE601.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {841A9192-5690-11D4-A258-0040954A01BE} (DialXSCtl Object) - http://dialxs.nl/install/dialxs.ocx
O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} - http://mywebpage.netscape.com/fullalbumsplugin/full_albums.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = f22.find-quick.com
O17 - HKLM\Software\..\Telephony: DomainName = f22.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{C570608B-4527-4D3A-B00B-3259581C49E3}: Domain = f22.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{E078631D-0024-4320-8CD0-A592FB018044}: Domain = f22.find-quick.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = f22.find-quick.com
 
Je kan veel dingen doen om het weg te halen:
- Download Spybot
- Download Ad-ware
- Start -> Uitvoeren -> msconfig en bekijk menu start
- MSN Plus verwijderen
- Balk weghalen door rechte muis en vinkje weg
 
Hoi renze,

Vink de volgende items aan in HijackThis, sluit alle IE, OE en verkenner vensters en klik op Fix checked:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://m32048.find-quick.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://m32048.find-quick.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://m32048.find-quick.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar=http://m32048.find-quick.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=http://m32048.find-quick.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://m32048.find-quick.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Startpagina=file:///C:/Program%20Files/MS-Connect/Portal/portal.html
O2 - BHO: (no name) - {b20ccf0d-2437-41d3-80fd-c9c0c635561a} - C:\DOCUME~1\Renze\APPLIC~1\gpoucrqulo.dll
O3 - Toolbar: rryccreafrn - {bfb039c9-157e-4e83-b441-0f1389407362} - C:\DOCUME~1\Renze\APPLIC~1\gpoucrqulo.dll
O4 - HKLM\..\Run: [iqulp] C:\DOCUME~1\Renze\APPLIC~1\earaoofr.exe -QuieT
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O16 - DPF: FreedomAudio - http://www.internetpiraten.com/webp...edominstall.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/17281d545e7ca4...ip/RdxIE601.cab
O16 - DPF: {841A9192-5690-11D4-A258-0040954A01BE} (DialXSCtl Object) - http://dialxs.nl/install/dialxs.ocx
O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} - http://mywebpage.netscape.com/fulla...full_albums.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = f22.find-quick.com
O17 - HKLM\Software\..\Telephony: DomainName = f22.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{C570608B-4527-4D3A-B00B-3259581C49E3}: Domain = f22.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{E078631D-0024-4320-8CD0-A592FB018044}: Domain = f22.find-quick.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = f22.find-quick.com

Start daarna je computer opnieuw op en scan met AdAware en/of Spybot S&D.
Ze zijn hier te krijgen:
Spybot:
http://security.kolla.de/index.php?lang=en&page=download
Ad-aware:
http://www.lavasoftusa.com/software/adaware/

Die fijne balk had je aan MessengerPlus te danken.

Groetjes,

Pieter
 
Geplaatst door rkwebdesign
Je kan veel dingen doen om het weg te halen:
- Download Spybot
- Download Ad-ware
- Start -> Uitvoeren -> msconfig en bekijk menu start
- MSN Plus verwijderen
- Balk weghalen door rechte muis en vinkje weg

Spybot en AdAware (slechts gedeeltelijk)
msconfig (niet)
MSN Plus (ik durf te gokken dat lop.com dan gewoon achterblijft)
Balk weghalen (als dat lukt is het symptoombestrijding)

Groetjes,

Pieter
 
Hoi Pieter Arntz,

Bedankt voor je hulp. Ik ben nu eindelijk verlost van die balk.

Groetjes
 
Status
Niet open voor verdere reacties.
Terug
Bovenaan Onderaan