Hijackthis log

Status
Niet open voor verdere reacties.

bobdaruler

Gebruiker
Lid geworden
25 mrt 2004
Berichten
100
Ik ben bij een vriend en kun je zijn log nakijken. Hij heeft last van een toolbar op zn internetbrowser.
En hij heeft bloodhound op zn pc.



Logfile of HijackThis v1.98.2
Scan saved at 15:00:11, on 4-10-2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\htpatch.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Windows SyncroAd\SyncroAd.exe
C:\WINDOWS\system32\ackbnm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\J\Bureaublad\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.suprnova.org/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.qexjxsptfzsqajfeibsoynp....jgeW1Bw_6ByQ3TxLDwhNCdtgO5KzuVHidqHhpwLU.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: MultimppObj Class - {002EB272-2590-4693-B166-FBD5D9B6FEA6} - C:\WINDOWS\multimpp.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2685818A-97D8-82AA-5B42-8B15202BBA34} - C:\PROGRA~1\METABU~1\Bend army.exe
O2 - BHO: (no name) - {7D46742C-0A06-86F2-0D7B-90F3E4FE22F8} - C:\PROGRA~1\METABU~1\Bend army.exe
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Second Once] C:\PROGRA~1\TRANSS~1\Iso global.exe
O4 - HKLM\..\Run: [fragplaykindcdrom] C:\Documents and Settings\All Users\Application Data\Seek does frag play\IntraDupe.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [Atom Internet Bags Manager] C:\Documents and Settings\All Users\Application Data\Start Knob Atom Internet\Elsetons.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows SyncroAd] C:\Program Files\Windows SyncroAd\SyncroAd.exe
O4 - HKLM\..\Run: [gvml] C:\WINDOWS\gvml.exe
O4 - HKLM\..\Run: [sicjjy] C:\WINDOWS\system32\ackbnm.exe
O4 - HKLM\..\Run: [conscorr] C:\WINDOWS\conscorr.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...1dd4eb01d54f:eeba47ee03d937f4aaa2edc6fc4885a4
O17 - HKLM\System\CCS\Services\Tcpip\..\{0E18EB97-9C76-4168-BA2F-B3D051CC1957}: NameServer = 217.19.16.131,217.19.16.132
O17 - HKLM\System\CCS\Services\Tcpip\..\{E96E6CFF-9EC5-432C-B29D-75E91FA64427}: NameServer = 217.19.16.131,217.19.16.132
O17 - HKLM\System\CS1\Services\Tcpip\..\{0E18EB97-9C76-4168-BA2F-B3D051CC1957}: NameServer = 217.19.16.131,217.19.16.132


Alvast bedankt :thumb:
 
Geplaatst door bobdaruler

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.qexjxsptfzsqajfeibsoynp....jgeW1Bw_6ByQ3TxLDwhNCdtgO5KzuVHidqHhpwLU.html

O2 - BHO: MultimppObj Class - {002EB272-2590-4693-B166-FBD5D9B6FEA6} - C:\WINDOWS\multimpp.dll
O2 - BHO: (no name) - {2685818A-97D8-82AA-5B42-8B15202BBA34} - C:\PROGRA~1\METABU~1\Bend army.exe
O2 - BHO: (no name) - {7D46742C-0A06-86F2-0D7B-90F3E4FE22F8} - C:\PROGRA~1\METABU~1\Bend army.exe

O4 - HKLM\..\Run: [Second Once] C:\PROGRA~1\TRANSS~1\Iso global.exe
O4 - HKLM\..\Run: [fragplaykindcdrom] C:\Documents and Settings\All Users\Application Data\Seek does frag play\IntraDupe.exe
O4 - HKLM\..\Run: [Atom Internet Bags Manager] C:\Documents and Settings\All Users\Application Data\Start Knob Atom Internet\Elsetons.exe
O4 - HKLM\..\Run: [Windows SyncroAd] C:\Program Files\Windows SyncroAd\SyncroAd.exe
O4 - HKLM\..\Run: [gvml] C:\WINDOWS\gvml.exe
O4 - HKLM\..\Run: [sicjjy] C:\WINDOWS\system32\ackbnm.exe
O4 - HKLM\..\Run: [conscorr] C:\WINDOWS\conscorr.exe

O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...1dd4eb01d54f:eeba47ee03d937f4aaa2edc6fc4885a4


1. Scan met HijackThis, vink de bovenstaande items (zie quote) aan, sluit alle vensters behalve HijackThis zelf en klik op "Fix checked".

2. Herstart de pc in veilige modus.
Mocht je niet weten hoe dat moet, kijk dan hier even: http://www.virushelp.nl/veilige_modus.htm

Zorg ervoor dat verborgen bestanden en mappen worden weergegeven.
Hier kun je lezen hoe dat moet: http://users.telenet.be/marcvn/spyware/1117602.htm

Verwijder nu, in veilige modus dus, de volgende bestanden en mappen (voor zover nog aanwezig):

Bestanden:
C:\WINDOWS\gvml.exe
C:\WINDOWS\conscorr.exe
C:\WINDOWS\system32\ackbnm.exe

Mappen:
C:\Program Files\Windows SyncroAd
C:\PROGRA~1\METABU~1 <- d.w.z. die map waarvan de naam begint met "Metabu..."
C:\PROGRA~1\TRANSS~1 <- d.w.z. die map waarvan de naam begint met "Transs..."
C:\Documents and Settings\All Users\Application Data\Seek does frag play
C:\Documents and Settings\All Users\Application Data\Start Knob Atom Internet

3. Herstart de pc in 'normale modus'.

4. Maak een nieuw log en plaats dat hier.
 
Ik ben dus die vriend waar hij toen was, en ik heb die bestanden die ik kon vinden verwijderd. Dit is de log die ik net daarna heb gemaakt.
En nog bedankt dat je me wil helpen. :)

Logfile of HijackThis v1.98.2
Scan saved at 19:26:48, on 15-10-2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\htpatch.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Web_Rebates\WebRebates0.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\DitExp.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\J\Mijn documenten\Mijn programmas\HijackThis\HijackThis.exe
C:\Program Files\Web_Rebates\WebRebates1.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.qjmmidwtjghslfsnoa.com/Z...jgeW1Bw_6ByQ3TxLDwhLQqWCINvTnFHidqHhpwLU.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://xlxhoffidgpo.com/ZAAXFUnhZKl1Z2kb6ZH8eVRsij0_mEAZYthoNAA9OQw.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: MultimppObj Class - {002EB272-2590-4693-B166-FBD5D9B6FEA6} - C:\WINDOWS\multimpp.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7D46742C-0A06-86F2-0D7B-90F3E4FE22F8} - C:\DOCUME~1\J\APPLIC~1\METABU~1\Bend army.exe
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [Windows SyncroAd] C:\Program Files\Windows SyncroAd\SyncroAd.exe
O4 - HKLM\..\Run: [yrwabsgjnuoq] C:\WINDOWS\system32\ackbnm.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [Atom Internet Bags Manager] C:\Documents and Settings\All Users\Application Data\Start Knob Atom Internet\JunkWay.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Second Once] C:\DOCUME~1\J\APPLIC~1\TRANSS~1\Iso global.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...1dd4eb01d54f:eeba47ee03d937f4aaa2edc6fc4885a4
O17 - HKLM\System\CCS\Services\Tcpip\..\{0E18EB97-9C76-4168-BA2F-B3D051CC1957}: NameServer = 217.19.16.131,217.19.16.132
O17 - HKLM\System\CCS\Services\Tcpip\..\{E96E6CFF-9EC5-432C-B29D-75E91FA64427}: NameServer = 217.19.16.131,217.19.16.132
O17 - HKLM\System\CS1\Services\Tcpip\..\{0E18EB97-9C76-4168-BA2F-B3D051CC1957}: NameServer = 217.19.16.131,217.19.16.132
 
Geplaatst door JoosT10

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.qjmmidwtjghslfsnoa.com/Z...jgeW1Bw_6ByQ3TxLDwhLQqWCINvTnFHidqHhpwLU.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://xlxhoffidgpo.com/ZAAXFUnhZKl1Z2kb6ZH8eVRsij0_mEAZYthoNAA9OQw.html

O2 - BHO: MultimppObj Class - {002EB272-2590-4693-B166-FBD5D9B6FEA6} - C:\WINDOWS\multimpp.dll
O2 - BHO: (no name) - {7D46742C-0A06-86F2-0D7B-90F3E4FE22F8} - C:\DOCUME~1\J\APPLIC~1\METABU~1\Bend army.exe

O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [Windows SyncroAd] C:\Program Files\Windows SyncroAd\SyncroAd.exe
O4 - HKLM\..\Run: [yrwabsgjnuoq] C:\WINDOWS\system32\ackbnm.exe
O4 - HKLM\..\Run: [Atom Internet Bags Manager] C:\Documents and Settings\All Users\Application Data\Start Knob Atom Internet\JunkWay.exe
O4 - HKCU\..\Run: [Second Once] C:\DOCUME~1\J\APPLIC~1\TRANSS~1\Iso global.exe

O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...1dd4eb01d54f:eeba47ee03d937f4aaa2edc6fc4885a4




Zou je willen proberen de instructies nu zo zorgvuldig mogelijk te volgen?


1. Scan met HijackThis, vink de bovenstaande items (zie quote) aan, sluit alle vensters behalve HijackThis zelf en klik op "Fix checked".

2. Herstart de pc in veilige modus.
Mocht je niet weten hoe dat moet, kijk dan hier even: http://www.virushelp.nl/veilige_modus.htm

Zorg ervoor dat verborgen bestanden en mappen worden weergegeven.
Hier kun je lezen hoe dat moet: http://users.telenet.be/marcvn/spyware/1117602.htm

Verwijder nu, in veilige modus dus, de volgende bestanden en mappen (voor zover nog aanwezig):

C:\WINDOWS\system32\ackbnm.exe <- dat bestand
C:\Program Files\Web_Rebates <- die map
C:\Program Files\Windows SyncroAd <- die map
C:\Documents and Settings\All Users\Application Data\Start Knob Atom Internet <- die map
C:\Documents and Settings\J\Application Data\METABU~1 <- d.w.z. die map waarvan de naam begint met "Metabu..."
C:\Documents and Settings\J\Application Data\TRANSS~1 <- d.w.z. die map waarvan de naam begint met "Transs..."

3. Herstart de pc in 'normale modus'.

4. Maak een nieuw log en plaats dat hier.
 
Oké deze keer heb ik precies gedaan wat je zei. Alleen ik kon echt een map echt niet vinden. En dat was die gene die in "C:\Documents and Settings\All Users" stond want ik heb helemaal geen "All Users" map. Dat kan komen omdat ik de enige gebruiker ben, dus heb ik ook gekeken bij "C:\Documents and Settings\J\Application Data" daar stond tie ook niet en ook niet bij "C:\Documents and Settings\Administrator\Application Data"
Maar wel heel erg bedankt!!!!:D

Logfile of HijackThis v1.98.2
Scan saved at 16:36:29, on 16-10-2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\htpatch.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\DitExp.exe
C:\Documents and Settings\J\Mijn documenten\Mijn programmas\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://gyowatrdxwmlzg.com/ZAAXFUnhZKnKdrgtafqCv8NbjgeW1Bw_6ByQ3TxLDwhwQLP/3xhT4VHidqHhpwLU.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{0E18EB97-9C76-4168-BA2F-B3D051CC1957}: NameServer = 217.19.16.131,217.19.16.132
O17 - HKLM\System\CCS\Services\Tcpip\..\{E96E6CFF-9EC5-432C-B29D-75E91FA64427}: NameServer = 217.19.16.131,217.19.16.132
O17 - HKLM\System\CS1\Services\Tcpip\..\{0E18EB97-9C76-4168-BA2F-B3D051CC1957}: NameServer = 217.19.16.131,217.19.16.132
 
:thumb: Heel erg bedankt!! :thumb:
Nouw ben ik eidelijk van die vervelende toolbar en andere reclame af :D
 
Status
Niet open voor verdere reacties.
Terug
Bovenaan Onderaan