Help ik word gek ik heb start pagina wel 20 keer verandert maar toch blijft hij veranderen naar een plek ik heb mijn computer met Spybot Search en Destroy en met Ad-Aware wel 20keer gescant alles verwijdert maar alles blijft terugkomen. Ik word gek!!!!
http://about-blank.ws/page/www.zeelandnet.nl(KLIK NIET OP DE LINK HIERVOOR MISSCHIEN KOMT HET DAN OOK BIJ JULLIE) dit is de site van mijn provider zoals jullie zien staat er in plaats van direcht
www.zeelandnet.nl een heel verhaal. Dan komt er een rooie balkje boven en die balkje word meteen mijn startpagina er komen ook meteen koppelingen in mijn desktop van gratis viagra pillen (stuk of 4). Ik zou graag advies willen hoe ik alles permanent kan verwijderen met hulp van andere programma's. Alvast bedankt en A.U.B snel want ik zit hier al 4 dagen mee ik ben het zat.
Dit is mijn Log:
Logfile of HijackThis v1.97.7
Scan saved at 23:44:43, on 29-3-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\WINDOWS\System32\drivers\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\svchost.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Documents and Settings\Recep\Application Data\tsst.exe
C:\WINDOWS\System32\wnscptr.exe
C:\zeyrek.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Recep\Local Settings\Temp\Tijdelijke map 1 voor hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://about-blank.ws/page/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://about-blank.ws/page/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://about-blank.ws/page/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://about-blank.ws
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://about-blank.ws
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://about-blank.ws/page/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://213.159.118.226/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://213.159.118.226/sp.php
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://about-blank.ws/page/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://about-blank.ws
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://about-blank.ws/page/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://about-blank.ws/page/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://about-blank.ws
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://about-blank.ws/page/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://213.159.118.226/sp.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.blazefind.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.blazefind.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Startpagina = file:///C:/Program%20Files/QuickPage/Portal/portal.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: (no name) - _{9368D063-44BE-49B9-BD14-BB9663FD38FC} - (no file)
R3 - URLSearchHook: (no name) - _{4FC95EDD-4796-4966-9049-29649C80111D} - (no file)
O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
O1 - Hosts: 81.211.105.69 lender-search.com
O1 - Hosts: 81.211.105.68 hot-searches.com
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - C:\WINDOWS\System32\bridge.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKLM\..\Run: [mbwrgtsz] C:\WINDOWS\mbwrgtsz.exe
O4 - HKLM\..\Run: [Network Service] C:\WINDOWS\svchost.exe -sr -0
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [ClickMe] C:\apps\ClickMe\ClickMe.exe
O4 - HKLM\..\Run: [winupgrade] c:\win32.hta
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKCU\..\Run: [Network Service] C:\WINDOWS\svchost.exe -sr -0
O4 - HKCU\..\Run: [Ocrm] C:\Documents and Settings\Recep\Application Data\tsst.exe
O4 - HKCU\..\Run: [WNSI] C:\WINDOWS\System32\wnscptr.exe
O4 - HKCU\..\Run: [dialer] C:\zeyrek.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGCOMLIB_1035.dll,InstantAccess
O4 - HKLM\..\RunOnce: [tlc] C:\WINDOWS\update12.js
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: MS-KB (HKLM)
O9 - Extra 'Tools' menuitem: MS-KB (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\nl.htm
O16 - DPF: ConferenceRoom Java Client -
http://207.218.219.226:8000/java/cr.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://dev-www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_41.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) -
http://virusscan.zdnet.nl/housecall/xscan53.cab
O16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} (brdg Class) -
http://www2.flingstone.com/cab/2000XP/new/bridge-c1.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -
http://dload.ipbill.com/del/loader.cab
O16 - DPF: {CEFB7B49-9652-464F-8AFD-A577C0500F39} (EGP2ECOM Class) -
http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1009_1035_pack_XP.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E3802230-F0E2-4A75-9947-EAB78DD8153F} (InstallerX Class) -
http://www.klikeuro.nl/cab/EroWebInstaller.cab