Hoi, geweldig dat de tijd wordt genomen om te helpen
ik heb een paar problemen die ik duidelijk kan merken, favorieten menu krijgt wat links erbij, direct na verwijderen (handmatig) zie ik ze weer staan, prefix van freednshost voor de links in adresbalk en IE vensters die opeens openen. Alle spyware wil ik er graag uithebben dus als jullie daarmee kunnen helpen... graag!
Ik hoop dat jullie kunnen helpen en alvast bedankt!
Logfile of HijackThis v1.97.7
Scan saved at 15:22:11, on 11-4-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\Grisoft\AVG6\avgserv.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZONELABS\vsmon.exe
D:\Program Files\Grisoft\AVG6\avgcc32.exe
D:\Program Files\Messenger Plus! 2\MsgPlus.exe
D:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
D:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
D:\WINDOWS\svchost.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Winamp\Winamp.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe
D:\Documents and Settings\secondary\Bureaublad\Nieuwe map (3)\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://freednshost.info/page/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://freednshost.info/page/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://freednshost.info/page/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://freednshost.info/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://freednshost.info/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://freednshost.info/page/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://213.159.118.226/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://213.159.118.226/sp.php
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://freednshost.info/page/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://freednshost.info/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://freednshost.info/page/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://freednshost.info/page/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://freednshost.info/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://freednshost.info/page/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://213.159.118.226/sp.php
O1 - Hosts: 213.159.118.226 1-se.com
O1 - Hosts: 213.159.118.226 58q.com
O1 - Hosts: 213.159.118.226 aifind.cc
O1 - Hosts: 213.159.118.226 aifind.info
O1 - Hosts: 213.159.118.226 allneedsearch.com
O1 - Hosts: 213.159.118.226 approvedlinks.com
O1 - Hosts: 213.159.118.226 auto.ie.searchforge.com
O1 - Hosts: 213.159.118.226 awebfind.biz
O1 - Hosts: 213.159.118.226 best.royalsearch.net
O1 - Hosts: 213.159.118.226 cracks.am
O1 - Hosts: 213.159.118.226 default-homepage-network.com
O1 - Hosts: 213.159.118.226 find.microgirls.com
O1 - Hosts: 213.159.118.226 find4u.net
O1 - Hosts: 213.159.118.226 freshvideogals.com
O1 - Hosts: 213.159.118.226 i-lookup.com
O1 - Hosts: 213.159.118.226 ie-search.com
O1 - Hosts: 213.159.118.226 in.webcounter.cc
O1 - Hosts: 213.159.118.226 itseasy.us
O1 - Hosts: 213.159.118.226 just.find-itnow.com
O1 - Hosts: 213.159.118.226 link.startmake.com
O1 - Hosts: 213.159.118.226 mysearchnow.com
O1 - Hosts: 213.159.118.226 nativehardcore.com
O1 - Hosts: 213.159.118.226 qwertysearch123.biz
O1 - Hosts: 213.159.118.226 search.ieplugin.com
O1 - Hosts: 213.159.118.226 search.psn.cn
O1 - Hosts: 213.159.118.226 searchbar.findthewebsiteyouneed.com
O1 - Hosts: 213.159.118.226 searchcentrix.com
O1 - Hosts: 213.159.118.226 searchmyrequest.com
O1 - Hosts: 213.159.118.226 super-spider.com
O1 - Hosts: 213.159.118.226 t.rack.cc
O1 - Hosts: 213.159.118.226 teen-biz.com
O1 - Hosts: 213.159.118.226 teenhqpics.com
O1 - Hosts: 213.159.118.226 tits.hardcore4ever.net
O1 - Hosts: 213.159.118.226 webcoolsearch.com
O1 - Hosts: 213.159.118.226 wmmse.com
O1 - Hosts: 213.159.118.226
www.008i.com
O1 - Hosts: 213.159.118.226
www.2fastsearch.net
O1 - Hosts: 213.159.118.226
www.8095.com
O1 - Hosts: 213.159.118.226
www.alfa-search.com
O1 - Hosts: 213.159.118.226
www.boredlife.com
O1 - Hosts: 213.159.118.226
www.couldnotfind.com
O1 - Hosts: 213.159.118.226
www.cracks.am
O1 - Hosts: 213.159.118.226
www.daum.net
O1 - Hosts: 213.159.118.226
www.dreamwiz.com
O1 - Hosts: 213.159.118.226
www.find-itnow.com
O1 - Hosts: 213.159.118.226
www.find-itnow.com
O1 - Hosts: 213.159.118.226
www.find4u.net
O1 - Hosts: 213.159.118.226
www.firstbookmark.com
O1 - Hosts: 213.159.118.226
www.gajai.com
O1 - Hosts: 213.159.118.226
www.hand-book.com
O1 - Hosts: 213.159.118.226
www.hao123.com
O1 - Hosts: 213.159.118.226
www.hotsearchbox.com
O1 - Hosts: 213.159.118.226
www.hotwebsearch.com
O1 - Hosts: 213.159.118.226
www.hugesearch.net
O1 - Hosts: 213.159.118.226
www.iquicksearch.com
O1 - Hosts: 213.159.118.226
www.lookfor.cc
O1 - Hosts: 213.159.118.226
www.maxxxhosters.com
O1 - Hosts: 213.159.118.226
www.naver.com
O1 - Hosts: 213.159.118.226
www.nkvd.us
O1 - Hosts: 213.159.118.226
www.nova****.com
O1 - Hosts: 213.159.118.226
www.ohcorea.com
O1 - Hosts: 213.159.118.226
www.omega-search.com
O1 - Hosts: 213.159.118.226
www.onet.pl
O1 - Hosts: 213.159.118.226
www.power-search.info
O1 - Hosts: 213.159.118.226
www.rightfinder.net
O1 - Hosts: 213.159.118.226
www.search-1.net
O1 - Hosts: 213.159.118.226
www.search-and-go.com
O1 - Hosts: 213.159.118.226
www.search-dot.com
O1 - Hosts: 213.159.118.226
www.search-space.com
O1 - Hosts: 213.159.118.226
www.searchforge.com
O1 - Hosts: 213.159.118.226
www.searching-the-net.com
O1 - Hosts: 213.159.118.226
www.searchv.com
O1 - Hosts: 213.159.118.226
www.searchxl.com
O1 - Hosts: 213.159.118.226
www.seznam.cz
O1 - Hosts: 213.159.118.226
www.slotch.com
O1 - Hosts: 213.159.118.226
www.spidersearch.com
O1 - Hosts: 213.159.118.226
www.startium.com
O1 - Hosts: 213.159.118.226
www.therealsearch.com
O1 - Hosts: 213.159.118.226
www.ttjj.com
O1 - Hosts: 213.159.118.226
www.viewpornkey.com
O1 - Hosts: 213.159.118.226
www.wazzupnet.com
O1 - Hosts: 213.159.118.226
www.websearch.com
O1 - Hosts: 213.159.118.226
www.windowws.cc
O1 - Hosts: 213.159.118.226
www.xgmm.com
O1 - Hosts: 213.159.118.226 xwebsearch.biz
O1 - Hosts: 213.159.118.226 yourbookmarks.ws
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [AVG_CC] D:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [MessengerPlus2] "D:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpyHunter] D:\Program Files\SpyHunter\SpyHunter.exe
O4 - HKLM\..\Run: [Zone Labs Client] D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [Network Service] D:\WINDOWS\svchost.exe -sr -0
O4 - HKCU\..\Run: [MessengerPlus2] "D:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Network Service] D:\WINDOWS\svchost.exe -sr -0
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKLM\..\RunOnce: [SpybotSnD] "D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://d:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://d:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Debt Solutions -
http://213.159.118.226/tools.php?qq=Debt+Solutions
O8 - Extra context menu item: Party Poker -
http://213.159.118.226/tools.php?qq=Party+Poker
O8 - Extra context menu item: Party Poker.com -
http://213.159.118.226/tools.php?qq=Party+Poker.com
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra 'Tools' menuitem: Party Poker.com (HKLM)
O9 - Extra 'Tools' menuitem: Party Poker (HKLM)
O9 - Extra 'Tools' menuitem: Debt Solutions (HKLM)
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - DefaultPrefix:
http://freednshost.info/page/
O13 - WWW Prefix:
http://freednshost.info/page/
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://activex.webcam.nl/AxisCamControl.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) -
http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/SolitaireShowdown.cab