Hijack this log

Status
Niet open voor verdere reacties.

robertjan

Gebruiker
Lid geworden
27 apr 2001
Berichten
375
Last van een dikke balk onder in beeld telkens als ik internet explorer open.. startpagine die steeds wijzigt en ik heb bovenin beeld een zoek balk.. en knoppen die woorden aannemen die in me scherm staan..

alvast bedankt..

Ps. Adaware en spybot vinden niks meer..


Logfile of HijackThis v1.98.2
Scan saved at 11:15:53, on 25-9-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
F:\Program Files\GFI\LANguard Network Security Scanner 5.0\lnssatt.exe
f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
F:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
F:\webserver\mysql\bin\mysqld-nt.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\r_server.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\svchost.exe
f:\PROGRA~1\mcafee.com\vso\mcshield.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\RAM Idle LE\RAM_XP.exe
F:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
F:\PROGRA~1\mcafee.com\agent\mcagent.exe
f:\progra~1\mcafee.com\vso\mcvsescn.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
F:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
F:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
F:\WINDOWS\System32\ctfmon.exe
F:\Program Files\MSN Messenger\msnmsgr.exe
F:\Program Files\Serv-U\ServUTray.exe
F:\Program Files\IBM\Bluetooth Software\BTTray.exe
F:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
F:\PROGRA~1\IBM\BLUETO~1\BTSTAC~1.EXE
F:\Program Files\Serv-U\ServUDaemon.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
f:\progra~1\mcafee.com\vso\mcvsftsn.exe
F:\Program Files\Messenger\msmsgs.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Internet Explorer\iexplore.exe
f:\progra~1\intern~1\iexplore.exe
F:\Program Files\WinRAR\WinRAR.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\Rar$EX04.331\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ml75.nl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bnmdqoqjaqf.com/ZYrOCbo5/YV8irjyX0PJMKE0XbWorsCIpfpkLS1XmNLazqquL3IWcc/ctYEZ_sQB.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.ml75.nl/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 81.208.96.4:1080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {A748F38A-8D00-108D-A353-32E2A8819F0D} - F:\PROGRA~1\FIVEBO~1\bags software.exe
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [RAM Idle Professional] F:\Program Files\RAM Idle LE\RAM_XP.exe
O4 - HKLM\..\Run: [VSOCheckTask] "f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] F:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [DataLayer] F:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] F:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "F:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ServUTrayIcon] F:\Program Files\Serv-U\ServUTray.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Download with &DAP - F:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - F:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Download All Files by HiDownload - F:\Program Files\HiDownload\HDGetAll.htm
O8 - Extra context menu item: Download by HiDownload - F:\Program Files\HiDownload\HDGet.htm
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Verzenden naar &Bluetooth - F:\Program Files\IBM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\IBM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\IBM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: HiDownload - {F4FBA929-A891-492C-A0F6-5C79CC4F1742} - F:\Program Files\HiDownload\hidownload.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/26512945663cbb16be05/netzip/RdxIE601.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {858B4F85-E945-4F0C-AF65-059E0AD9EEC0} (IntraLaunch.MainControl) - file://D:\hacking\hacking cd\Interface\IntraLaunch.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://activex.webcam.nl/AxisCamControl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.jackjones.com/XUpload.ocx
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
 
Laatst bewerkt:
Geplaatst door robertjan

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bnmdqoqjaqf.com/ZYrOCbo5/YV8irjyX0PJMKE0XbWorsCIpfpkLS1XmNLazqquL3IWcc/ctYEZ_sQB.htm

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {A748F38A-8D00-108D-A353-32E2A8819F0D} - F:\PROGRA~1\FIVEBO~1\bags software.exe

O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/26512945663cbb16be05/netzip/RdxIE601.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab


Dag Robertjan,

Heb je zelf al dingen gefixt, of uitgevinkt in MSConfig? Ik heb de indruk dat dit log geen volledig beeld geeft van de problemen.

Maak eerst even een eigen, permanente map voor HijackThis, bijvoorbeeld F:\Program Files\HJT. Plaats HijackThis.exe in die map en draai het nu dus vanuit die map.

1. Scan opnieuw met HijackThis, vink de bovenstaande items (zie quote) aan, sluit alle vensters behalve HijackThis zelf en klik op "Fix checked".

2. Herstart de pc in veilige modus.
Mocht je niet weten hoe dat moet, kijk dan hier even: http://www.virushelp.nl/veilige_modus.htm

Zorg ervoor dat verborgen bestanden en mappen worden weergegeven.
Hier kun je lezen hoe dat moet: http://users.telenet.be/marcvn/spyware/1117602.htm

Verwijder nu, in veilige modus dus, de volgende map:

F:\PROGRAM FILES\FIVEBO~1 <- d.w.z. die map waarvan de naam begint met "Fivebo..."

3. Herstart de pc in 'normale modus'.

4. Plaats een nieuw log.
 
Dank je wel voor je antwoord, ik heb alleen bij program files de mappen : Fordborefive, fiveings, five bore, Fettings Bore..


die lijken wel erg op elkaar. wat denk jij daarvan?
 
Verwijder in ieder geval de map Fiveborefive, maar kijk voordat je dat doet even wanneer die map gemaakt is (rechtsklikken op de map -> Eigenschappen).

Kijk of die andere mappen van dezelfde datum zijn (waarschijnlijk wel) en, zo ja, verwijder die dan ook.

Wil je mijn vraag of je zelf al dingen had gefixt of zaken hebt uitgevinkt in MSConfig nog even beantwoorden?
 
Ik heb inderdaad in msconfig een paar dingen al uitgevinkt.. er staat daar een enorme waslijst van programma's ondertussen.. maar je kan ze er niet uit verwijderen.. kan ook niks vinden om ze daar weg te halen.. weet jij toevallig hoe dat moet?
 
Vink alles wat je hebt uitgevinkt in MSConfig weer aan. Start daarna de pc opnieuw op. Maak vervolgens een nieuw HijackThis-log en plaats dat hier.
 
weyo.... haha ok dat ga ik doen...het is echt veel wat er niet is aangevinkt.. hopen dat me processor het gaat overleven :)


er staan ook dingen tussen die ik al niet eens meer op me pc heb.. ook die aanvinken?
 
Nou, ik heb alles aangevinkt in me msconfig, het is een hoop en sommige staan er dubbel? in, zoals ik al zei gebruik ik een aantal programma's niet meer, of niet vaak. maar nu is alles aangevinkt en heb ik een nieuwe hijack this log gemaakt

mijn dank ik groot, bij voorbaat al

Logfile of HijackThis v1.98.2
Scan saved at 13:22:43, on 2-10-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\RAM Idle LE\RAM_XP.exe
F:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
F:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
F:\PROGRA~1\mcafee.com\agent\mcagent.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
F:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
F:\Program Files\GFI\LANguard Network Security Scanner 5.0\lnssatt.exe
f:\progra~1\mcafee.com\vso\mcvsescn.exe
F:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
f:\progra~1\intern~1\iexplore.exe
F:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
F:\Program Files\QuickTime\qttask.exe
F:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
F:\Program Files\NetLimiter\NetLimiter.exe
F:\Program Files\Messenger Plus! 3\MsgPlus.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
F:\WINDOWS\System32\LVCOMSX.EXE
F:\Program Files\Logitech\Video\LogiTray.exe
F:\WINDOWS\kdx\KHost.exe
F:\WINDOWS\System32\ctfmon.exe
F:\Program Files\MSN Messenger\msnmsgr.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
F:\Program Files\Serv-U\ServUTray.exe
F:\Program Files\Messenger\msmsgs.exe
F:\Program Files\Logitech\Video\ManifestEngine.exe
F:\webserver\mysql\bin\mysqld-nt.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\r_server.exe
f:\progra~1\mcafee.com\vso\mcvsftsn.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\IBM\Bluetooth Software\BTTray.exe
F:\WINDOWS\system32\svchost.exe
F:\PROGRA~1\IBM\BLUETO~1\BTSTAC~1.EXE
F:\Program Files\GhostSurf 2005\Proxy.exe
f:\PROGRA~1\mcafee.com\vso\mcshield.exe
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\webserver\Apache2\bin\ApacheMonitor.exe
F:\Program Files\Logitech\Video\FxSvr2.exe
F:\webserver\mysql\bin\winmysqladmin.exe
F:\WINDOWS\System32\wuauclt.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ml75.nl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://web.oobxuonyhncahctjam.com/Z...XbWorsCIpfpkLS1XmNIyhz8mDFJbOc/ctYEZ_sQB.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.ml75.nl/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [RAM Idle Professional] F:\Program Files\RAM Idle LE\RAM_XP.exe
O4 - HKLM\..\Run: [VSOCheckTask] "f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] F:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MPFExe] F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [DataLayer] F:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] F:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [SAVE DRV] F:\PROGRA~1\JUGSPU~1\curbteamdvd.exe
O4 - HKLM\..\Run: [GhostSurfDelSatellite] F:\Program Files\GhostSurf 2005\DeleteSatellite.exe
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Titan FTP Server Tray App] F:\Program Files\South River Technologies\Titan FTP Server\srxTray.exe
O4 - HKLM\..\Run: [SurfAnonymous] F:\Program Files\SurfAnonymous\SurfAnonymous.exe -1
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NetPumper] "F:\NetPumper\NetPumperIEProxy.exe"
O4 - HKLM\..\Run: [NetLimiter] F:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MSKDetectorExe] F:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] F:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [MessengerPlus3] "F:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [LVCOMSX] F:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] F:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] F:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] F:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] F:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [kdx] F:\WINDOWS\kdx\KHost.exe
O4 - HKLM\..\Run: [Hotbar] F:\Program Files\Hotbar\bin\Hbinst.exe /Upgrade
O4 - HKLM\..\Run: [eDonkey2000] F:\Program Files\eDonkey2000\eDonkey2000.exe -t
O4 - HKLM\..\Run: [dumb mp3 boob new] F:\Documents and Settings\All Users\Application Data\Owns Flaw Dumb Mp3\Extramath.exe
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "F:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ServUTrayIcon] F:\Program Files\Serv-U\ServUTray.exe
O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MessengerPlus2] "F:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "F:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LiteWeb] F:\Program Files\LiteWeb\liteweb.exe
O4 - HKCU\..\Run: [CDFoon System-Tray] F:\cdfoon\cdftray.exe
O4 - Startup: Monitor Apache Servers.lnk = F:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Startup: NewsGrabber Auto Update.lnk = F:\Program Files\NewsGrabber3\WiseUpdt.exe
O4 - Startup: WinMySQLadmin.lnk = F:\webserver\mysql\bin\winmysqladmin.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: DUSuperControler.lnk = F:\Program Files\DU Super Controler\DUSuperControler.exe
O4 - Global Startup: GhostSurf proxy.lnk = F:\Program Files\GhostSurf 2005\Proxy.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Monitor Apache Servers.lnk = F:\webserver\Apache2\bin\ApacheMonitor.exe
O8 - Extra context menu item: &Download with &DAP - F:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - F:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Download All Files by HiDownload - F:\Program Files\HiDownload\HDGetAll.htm
O8 - Extra context menu item: Download by HiDownload - F:\Program Files\HiDownload\HDGet.htm
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Verzenden naar &Bluetooth - F:\Program Files\IBM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\IBM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\IBM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: HiDownload - {F4FBA929-A891-492C-A0F6-5C79CC4F1742} - F:\Program Files\HiDownload\hidownload.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {858B4F85-E945-4F0C-AF65-059E0AD9EEC0} (IntraLaunch.MainControl) - file://D:\hacking\hacking cd\Interface\IntraLaunch.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://activex.webcam.nl/AxisCamControl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.jackjones.com/XUpload.ocx
 
Geplaatst door robertjan

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://web.oobxuonyhncahctjam.com/Z...XbWorsCIpfpkLS1XmNIyhz8mDFJbOc/ctYEZ_sQB.html

R3 - Default URLSearchHook is missing

O4 - HKLM\..\Run: [SAVE DRV] F:\PROGRA~1\JUGSPU~1\curbteamdvd.exe
O4 - HKLM\..\Run: [kdx] F:\WINDOWS\kdx\KHost.exe
O4 - HKLM\..\Run: [Hotbar] F:\Program Files\Hotbar\bin\Hbinst.exe /Upgrade
O4 - HKLM\..\Run: [dumb mp3 boob new] F:\Documents and Settings\All Users\Application Data\Owns Flaw Dumb Mp3\Extramath.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

O16 - DPF: {858B4F85-E945-4F0C-AF65-059E0AD9EEC0} (IntraLaunch.MainControl) - file://D:\hacking\hacking cd\Interface\IntraLaunch.CAB
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://activex.webcam.nl/AxisCamControl.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.jackjones.com/XUpload.ocx


Mooi zo, nu zie ik in het log wat ik moet zien om die balkenellende te kunnen verwijderen.


1. Scan met HijackThis, vink de bovenstaande items (zie quote) aan, sluit alle vensters behalve HijackThis zelf en klik op "Fix checked".

2. Herstart de pc in veilige modus.
Mocht je niet weten hoe dat moet, kijk dan hier even: http://www.virushelp.nl/veilige_modus.htm

Zorg ervoor dat verborgen bestanden en mappen worden weergegeven.
Hier kun je lezen hoe dat moet: http://users.telenet.be/marcvn/spyware/1117602.htm

Verwijder nu, in veilige modus dus, de volgende mappen:

F:\PROGRAM FILES\JUGSPU... <- die map waarvan de naam begint met "Jugspu..."
F:\WINDOWS\kdx <- die map
F:\Documents and Settings\All Users\Application Data\Owns Flaw Dumb Mp3 <- die map
F:\Program Files\Hotbar <- die map (als die er nog is)

3. Herstart de pc in 'normale modus'.

4. Maak een nieuw log en plaats dat hier.
 
Ok dan, de 2 balken zijn weg... dat is zeer zeer mooi.. eindelijk ervan af..

nou heb ik nog 2 vraagjes.... kan ik zelf in hijackthis naar die dingen die opstarten kijken.. bijvoorbeeld titan ftp .. dat heb i niet eens meer op me computer.. kan ik die dan daar fixen ook zodat ie weg gaat daaruit?

Verder heb ik de volgende mappen in program files staan:

Fordborefive (1 file.. my own settings.bin van 32 bytes)
Fiveings (1 file.. my own settings.bin van 32 bytes)
Fettingsbore (1 file.. my own settings.bin van 32 bytes)
Gridkbore (1 file.. my own settings.bin van 32 bytes)
Gridkbep (1 file.. my own settings.bin van 32 bytes)
Settbore (1 file.. my own settings.bin van 32 bytes)
Settibore (1 file.. my own settings.bin van 32 bytes)
settiNgs (1 file.. my own settings.bin van 40 bytes)
settingsbore (1 file.. my own settings.bin van 32 bytes)
settingsfivebore (1 file.. my own settings.bin van 32 bytes)


allemaal dus de zelfde inhoud.. wat zijn dit voor mappen en kan ik die gewoon verwijderen?

dit is me nieuwe hijack log


Logfile of HijackThis v1.98.2
Scan saved at 14:11:13, on 2-10-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe
F:\Program Files\GFI\LANguard Network Security Scanner 5.0\lnssatt.exe
f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
F:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
F:\webserver\mysql\bin\mysqld-nt.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\r_server.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\Explorer.EXE
f:\PROGRA~1\mcafee.com\vso\mcshield.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
F:\Program Files\RAM Idle LE\RAM_XP.exe
F:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
F:\PROGRA~1\mcafee.com\agent\mcagent.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
F:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
f:\progra~1\mcafee.com\vso\mcvsescn.exe
F:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
F:\Program Files\QuickTime\qttask.exe
F:\Program Files\NetLimiter\NetLimiter.exe
F:\WINDOWS\System32\wuauclt.exe
F:\Program Files\Messenger Plus! 3\MsgPlus.exe
F:\WINDOWS\System32\LVCOMSX.EXE
F:\Program Files\Logitech\Video\LogiTray.exe
F:\WINDOWS\System32\ctfmon.exe
F:\Program Files\Serv-U\ServUTray.exe
F:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
F:\Program Files\Messenger\msmsgs.exe
F:\Program Files\IBM\Bluetooth Software\BTTray.exe
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\webserver\Apache2\bin\ApacheMonitor.exe
F:\Program Files\MSN Messenger\msnmsgr.exe
F:\PROGRA~1\IBM\BLUETO~1\BTSTAC~1.EXE
f:\progra~1\mcafee.com\vso\mcvsftsn.exe
F:\Program Files\Logitech\Video\FxSvr2.exe
F:\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ml75.nl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.yklqjyslzavodyh.info/ZYrOCbo5/YV8irjyX0PJMKE0XbWorsCIpfpkLS1XmNJjnPisMn/wbc/ctYEZ_sQB.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.ml75.nl/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [RAM Idle Professional] F:\Program Files\RAM Idle LE\RAM_XP.exe
O4 - HKLM\..\Run: [VSOCheckTask] "f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] F:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MPFExe] F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [DataLayer] F:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] F:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [GhostSurfDelSatellite] F:\Program Files\GhostSurf 2005\DeleteSatellite.exe
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Titan FTP Server Tray App] F:\Program Files\South River Technologies\Titan FTP Server\srxTray.exe
O4 - HKLM\..\Run: [SurfAnonymous] F:\Program Files\SurfAnonymous\SurfAnonymous.exe -1
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NetPumper] "F:\NetPumper\NetPumperIEProxy.exe"
O4 - HKLM\..\Run: [NetLimiter] F:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MSKDetectorExe] F:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] F:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [MessengerPlus3] "F:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [LVCOMSX] F:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] F:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] F:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] F:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] F:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [eDonkey2000] F:\Program Files\eDonkey2000\eDonkey2000.exe -t
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "F:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ServUTrayIcon] F:\Program Files\Serv-U\ServUTray.exe
O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "F:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LiteWeb] F:\Program Files\LiteWeb\liteweb.exe
O4 - HKCU\..\Run: [CDFoon System-Tray] F:\cdfoon\cdftray.exe
O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Monitor Apache Servers.lnk = F:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Startup: NewsGrabber Auto Update.lnk = F:\Program Files\NewsGrabber3\WiseUpdt.exe
O4 - Startup: WinMySQLadmin.lnk = F:\webserver\mysql\bin\winmysqladmin.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: DUSuperControler.lnk = F:\Program Files\DU Super Controler\DUSuperControler.exe
O4 - Global Startup: GhostSurf proxy.lnk = F:\Program Files\GhostSurf 2005\Proxy.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Monitor Apache Servers.lnk = F:\webserver\Apache2\bin\ApacheMonitor.exe
O8 - Extra context menu item: &Download with &DAP - F:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - F:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Download All Files by HiDownload - F:\Program Files\HiDownload\HDGetAll.htm
O8 - Extra context menu item: Download by HiDownload - F:\Program Files\HiDownload\HDGet.htm
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Verzenden naar &Bluetooth - F:\Program Files\IBM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\IBM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\IBM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: HiDownload - {F4FBA929-A891-492C-A0F6-5C79CC4F1742} - F:\Program Files\HiDownload\hidownload.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
 
Fix

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.yklqjyslzavodyh.info/ZYrOCbo5/YV8irjyX0PJMKE0XbWorsCIpfpkLS1XmNJjnPisMn/wbc/ctYEZ_sQB.htm

nog even.



Geplaatst door robertjan
nou heb ik nog 2 vraagjes.... kan ik zelf in hijackthis naar die dingen die opstarten kijken.. bijvoorbeeld titan ftp .. dat heb i niet eens meer op me computer.. kan ik die dan daar fixen ook zodat ie weg gaat daaruit?

04-items van programma's die niet meer op je pc staan mag je fixen.
Neem hier ook eens een kijkje: http://www.helpmij.nl/forum/showthread.php?threadid=173272

Geplaatst door robertjan
Verder heb ik de volgende mappen in program files staan:

Fordborefive (1 file.. my own settings.bin van 32 bytes)
Fiveings (1 file.. my own settings.bin van 32 bytes)
Fettingsbore (1 file.. my own settings.bin van 32 bytes)
Gridkbore (1 file.. my own settings.bin van 32 bytes)
Gridkbep (1 file.. my own settings.bin van 32 bytes)
Settbore (1 file.. my own settings.bin van 32 bytes)
Settibore (1 file.. my own settings.bin van 32 bytes)
settiNgs (1 file.. my own settings.bin van 40 bytes)
settingsbore (1 file.. my own settings.bin van 32 bytes)
settingsfivebore (1 file.. my own settings.bin van 32 bytes)


allemaal dus de zelfde inhoud.. wat zijn dit voor mappen en kan ik die gewoon verwijderen?

Allemaal mappen van Lop.com (waar die balkenellende ook bij hoort). Verwijder deze mappen.

Je hebt die Lop.com ellende trouwens cadeau gekregen bij Messenger Plus.
 
Ok cool, hartstikke bedankt voor je hulp,


als ik trouwens in hijack nu wat 04 dingen verwijder.. dan kan ik ze toch wel gewoon handmatig nog opstarten?

thnx a lot
 
Geplaatst door robertjan
als ik trouwens in hijack nu wat 04 dingen verwijder.. dan kan ik ze toch wel gewoon handmatig nog opstarten?

Jazeker, het fixen zorgt er alleen maar voor dat de betreffende programma-onderdelen niet meer automatisch geladen worden wanneer Windows opstart.

Maar heb je twijfels over het al dan niet fixen van een bepaald 04-item, fix het dan niet met HijackThis maar vink het uit in MSConfig -> Opstarten. Dan kun je het gemakkelijk weer aanvinken, als je toch spijt van je keuze krijgt.
Ik raad je aan met HijackThis alleen die 04-items te fixen die bij programma's horen die niet meer op je pc staan. Maak voor de overige opstartitems gebruik van MSConfig -> Opstarten.
 
Status
Niet open voor verdere reacties.
Terug
Bovenaan Onderaan