Sorry, Ik schijn steeds bij het verkeerde topic mijn vraag neer te leggen, ik hoop dat het nu op de goede plaats staat. (sorry voor de overlast bij de andere posten 
Graag zou ik jullie een hijackthis log voor willen leggen om tot een "schone"computer (mijn zoon, die oen!!) te komen: 
Ik heb het volgende gedaan: 
alle upgrades van Adaware, spybot en Norton gehaald , alle 3 de programma's gescand en alles laten verwijderen, virussen verwijderd en opnieuw opgestart, maar de direct host wil maar niet van het systeem af. 
Graag jullie hulp hierbij. 
Hartelijk dank 
Hebe 
Logfile of HijackThis v1.97.7 
Scan saved at 10:48:59, on 13-12-2003 
Platform: Windows XP SP1 (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) 
Running processes: 
C:\WINDOWS\System32\smss.exe 
C:\WINDOWS\system32\winlogon.exe 
C:\WINDOWS\system32\services.exe 
C:\WINDOWS\system32\lsass.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\System32\svchost.exe 
C:\WINDOWS\Explorer.EXE 
C:\WINDOWS\system32\spoolsv.exe 
C:\Program Files\Norton AntiVirus\navapsvc.exe 
C:\Program Files\Norton Internet Security\NISUM.EXE 
C:\WINDOWS\System32\nvsvc32.exe 
C:\Program Files\Norton Internet Security\NISSERV.EXE 
C:\Program Files\Norton Internet Security\SymProxySvc.exe 
C:\Program Files\Norton Internet Security\IAMAPP.EXE 
C:\PROGRA~1\NORTON~1\navapw32.exe 
C:\Program Files\Winamp3\winampa.exe 
C:\WINDOWS\SOINTGR.EXE 
C:\Program Files\QuickTime\qttask.exe 
C:\WINDOWS\System32\ctfmon.exe 
C:\WINDOWS\System32\RUNDLL32.EXE 
C:\Program Files\Norton Internet Security\ATRACK.EXE 
C:\Program Files\Internet Explorer\iexplore.exe 
C:\Documents and Settings\JeroenD\Local Settings\Temp\Tijdelijke map 1 voor hijackthis.zip\HijackThis.exe 
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = 
http://in.webcounter.cc/--/?toaqy (obfuscated) 
R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page = 
http://vrape.hardloved.com/top/search.php?id=2&s= 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = 
http://ie-search.com/srchasst.html (obfuscated) 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = 
http://in.webcounter.cc/--/?toaqy (obfuscated) 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = 
http://www.startpagina.nl/ 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
http://in.webcounter.cc/-/?toaqy (obfuscated) 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
http://in.webcounter.cc/--/?toaqy (obfuscated) 
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
http://in.webcounter.cc/---/?toaqy (obfuscated) 
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
http://in.webcounter.cc/--/?toaqy (obfuscated) 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = 
http://in.webcounter.cc/-/?toaqy about :blank (obfuscated) 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = 
http://ie-search.com/srchasst.html (obfuscated) 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = 
http://in.webcounter.cc/--/?toaqy (obfuscated) 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
http://www.startpagina.nl 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
http://in.webcounter.cc/--/?toaqy (obfuscated) 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
http://in.webcounter.cc/--/?toaqy (obfuscated) 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
http://in.webcounter.cc/---/?toaqy (obfuscated) 
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about :blank 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen 
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = 
http://in.webcounter.cc/--/?toaqy (obfuscated) 
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = 
http://in.webcounter.cc/--/?toaqy (obfuscated) 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = 
http://ie-search.com/srchasst.html (obfuscated) 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = 
http://ie-search.com/srchasst.html (obfuscated) 
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = 
http://ie-search.com/srchasst.html (obfuscated) 
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe 
O1 - Hosts: 66.197.100.83 auto.search.msn.com 
O1 - Hosts: 66.197.100.83 sitefinder.verisign.com 
O2 - BHO: (no name) - {0549E6CB-9985-42F6-8FD6-4EC017E6AAE1} - C:\Program Files\mathies.com\PopThis!\PopThis.dll 
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx 
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll 
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll 
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx 
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup 
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install 
O4 - HKLM\..\Run: [Windows Shell Library Loader] load shell.dll /c /set -- by windows setup -- 
O4 - HKLM\..\Run: [Soundmx] \soundmx.exe 
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE 
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe 
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe" 
O4 - HKLM\..\Run: [SO5 Integrator Pass Two] C:\WINDOWS\SOINTGR.EXE 
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime 
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe 
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto 
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe 
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit 
O4 - HKCU\..\Run: [sws.exe] c:\program files\GlobalDialer\jbest00000\34838609.exe -remove 
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE 
O8 - Extra context menu item: Web Search - c:\windows\ex.htm 
O9 - Extra 'Tools' menuitem: PopThis! Options... (HKLM) 
O9 - Extra button: Messenger (HKLM) 
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) 
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.nl 
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - 
http://www.apple.com/qtactivex/qtplugin.cab 
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - 
http://download.macromedia.com/pub/...director/sw.cab 
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - 
http://security.symantec.com/SSC/Sh...bin/AvSniff.cab 
O16 - DPF: {83B67220-025C-416C-8049-398E12764B36} (Flo2_L2 Control) - 
http://www.nokiagame.com/games/2K1E...yas/flo2_l2.cab 
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - 
http://66.230.143.209/loader/dploader.cab 
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - 
http://security.symantec.com/SSC/Sh...n/bin/cabsa.cab 
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - 
http://download.macromedia.com/pub/...ash/swflash.cab 
O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - 
https://gto.postbank.nl/GTO/PBGNX.cab 
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - 
http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocx