hijackthis logs

Status
Niet open voor verdere reacties.

bolletje40

Gebruiker
Lid geworden
9 jan 2004
Berichten
103
Hallo ik heb net mijn pc gescand met hijackthis

elke keer werd er gevraagd of de startpagina veranderd mocht worden

hier komt ie------ ik hoop dat het geod gegaan is

bedankt alvast

wim

Altnet Software (HKCR\Interface\{258A3625-183B-4477-AEE2-EA54DF6D878D}) Registry *
Altnet Software (HKCR\Interface\{29E825AA-13BC-457C-806A-D72E4A25B3C5}) Registry *
Altnet Software (HKCR\Interface\{9D4548CE-92FD-4C6C-AE7F-3DBE3BC763D8}) Registry *
Altnet Software (HKCR\Interface\{E79DADC6-18D0-4A2A-831F-D196D41F8438}) Registry *
Altnet Software (HKCR\Interface\{E813099D-5529-47F4-9B37-4AFAFCB00A43}) Registry *
Altnet Software (HKLM\SOFTWARE\Altnet) Registry *
Altnet Software (HKLM\SOFTWARE\Microsoft\DownloadManager) Registry *
Altnet Software (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AltnetDM) Registry *
C-Dilla (HKLM\SOFTWARE\C07ft5Y) Registry *
CWS (HKCR\protocols\filter\text/plain) Registry *
EasyBar (HKCU\software\microsoft\internet explorer\toolbar\webbrowser##{9AD55269-A21C-4260-BA7F-866FD09E8A8E}) Registry *
eZula (HKLM\software\microsoft\windows\currentversion\app management\arpcache\ezula) Registry *
HotBar (HKLM\software\microsoft\windows\currentversion\uninstall\hotbara) Registry *
HotBar (HKLM\software\microsoft\windows\currentversion\uninstall\hotbarb) Registry *
HotBar (HKLM\software\microsoft\windows\currentversion\uninstall\hotbarc) Registry *
IEPlugin (HKLM\SOFTWARE\Microsoft\Internet Explorer\Main##Search Bar) Registry *
Joltid P2P Networking (HKCR\JCDE_Stack) Registry *
Joltid P2P Networking (HKCR\JCDE_Stack.1) Registry *
Joltid P2P Networking (HKCR\WebP2PInstaller.Installer) Registry *
Joltid P2P Networking (HKCR\WebP2PInstaller.Installer.1) Registry *
Joltid P2P Networking (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run##P2P Networking) Registry *
Joltid P2P Networking (HKCU\Software\P2P Networking) Registry *
Joltid P2P Networking (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\P2P Networking) Registry *
Joltid P2P Networking (HKCR\CLSID\{1D6711C8-7154-40BB-8380-3DEA45B69CBF}) Registry *
Joltid P2P Networking (HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D6711C8-7154-40BB-8380-3DEA45B69CBF}) Registry *
Joltid P2P Networking (HKCR\CLSID\{C91E8926-D4BE-4685-99F4-0D996B96BAC0}) Registry *
Joltid P2P Networking (HKCR\Interface\{C91E8926-D4BE-4685-99F4-0D996B96BAC0}) Registry *
Joltid P2P Networking (HKCR\CLSID\{CC7A6223-3759-4075-8CEA-971F5CFC0ED2}) Registry *
Joltid P2P Networking (HKCR\TypeLib\{F720B40F-3A38-4B22-B30D-DCF095D42498}) Registry *
Joltid P2P Networking (HKCR\Interface\{D273D427-57C6-4B12-860F-BBB8195F6E2A}) Registry *
Joltid P2P Networking (HKCR\Interface\{16097036-894C-4C00-A61F-93CA0D49A70E}) Registry *
Joltid P2P Networking (HKCR\Interface\{1B540D44-3F61-4394-AE30-25FDC3649405}) Registry *
Joltid P2P Networking (HKCR\Interface\{2ED5AF98-9258-45BA-B79B-06625C92F662}) Registry *
Joltid P2P Networking (HKCR\Interface\{700DC0DD-F409-42E0-9DE5-21EE1A2BA9FD}) Registry *
Joltid P2P Networking (HKLM\Software\P2P Networking) Registry *
Joltid P2P Networking (HKCR\Interface\{FD42F6D3-7AB1-470C-979B-7996EDC99099}) Registry *
Joltid P2P Networking (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468e-B848-2B2E8E697B74} 2##%SystemRoot%\System32\P2P Networking v126.cpl) Registry *
Mnibug (HKCU\Software\AWS) Registry *
Mnibug (HKCU\Software\Microsoft\Internet Explorer\Extensions\{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}) Registry *
Mnibug (HKCR\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C}) Registry *
Mnibug (HKCR\Interface\{04A38F6B-006F-4247-BA4C-02A139D5531C}) Registry *
Mnibug (HKCR\MiniBugTransporter.MiniBugTransporterX) Registry *
Mnibug (HKCR\MiniBugTransporter.MiniBugTransporterX.1) Registry *
Mnibug (HKCR\TypeLib\{3C2D2A1E-031F-4397-9614-87C932A848E0}) Registry *
Mnibug (HKCU\Software\Microsoft\Internet Explorer\Extensions\{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}##ButtonText) Registry *
Mnibug (HKCU\Software\Microsoft\Internet Explorer\Extensions\{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}##CLSID) Registry *
Mnibug (HKCU\Software\Microsoft\Internet Explorer\Extensions\{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}##ClsidExtension) Registry *
Mnibug (HKCU\Software\Microsoft\Internet Explorer\Extensions\{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}##Default Visible) Registry *
Mnibug (HKCU\Software\Microsoft\Internet Explorer\Extensions\{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}##Exec) Registry *
Mnibug (HKCU\Software\Microsoft\Internet Explorer\Extensions\{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}##HotIcon) Registry *
Mnibug (HKCU\Software\Microsoft\Internet Explorer\Extensions\{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}##Icon) Registry *
Mnibug (HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping##{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}) Registry *
My Way (HKCR\CLSID\{3646C2BD-3554-49CA-8125-44DEEFB881DE}) Registry *
My Way (HKCR\CLSID\{3f4d4f88-0198-4921-b630-957f3eb814e0}) Registry *
Slotchbar (HKLM\SOFTWARE\Microsoft\DownloadManager) Registry *
TopSearch (HKCR\TopSearch.TSLink) Registry *
TopSearch (HKCR\TopSearch.TSLink.1) Registry *
TopSearch (HKCR\CLSID\{B7156514-A76C-4545-9D5B-A4E1D02C7AEC}) Registry *
TopSearch (HKCR\TypeLib\{EDD3B3E9-3FFD-4836-A6DE-D4A9C473A971}) Registry *
TopSearch (HKCR\Interface\{582AB125-1403-42FB-9EFB-198690BA1496}) Registry *
Virtual Bouncer (HKCR\CLSID\{48E59293-9880-11CF-9754-00AA00C00908}) Registry *
Virtual Bouncer (HKCR\CLSID\{48E59294-9880-11CF-9754-00AA00C00908}) Registry *
Virtual Bouncer (HKCR\CLSID\{48E59295-9880-11CF-9754-00AA00C00908}) Registry *
Virtual Bouncer (HKCR\InetCtls.Inet) Registry *
Virtual Bouncer (HKCR\InetCtls.Inet.1) Registry *
Virtual Bouncer (HKCR\Interface\{48E59291-9880-11CF-9754-00AA00C00908}) Registry *
Virtual Bouncer (HKCR\Interface\{48E59292-9880-11CF-9754-00AA00C00908}) Registry *
Virtual Bouncer (HKCR\TypeLib\{48E59290-9880-11CF-9754-00AA00C00908}) Registry *
WildTangent (HKCR\WildTangent.ActiveLauncher) Registry *
WildTangent (HKCR\WildTangent.ActiveLauncher.1) Registry *
WildTangent (HKCR\CLSID\{3A7FE611-1994-4ef1-A09F-99456752289D}) Registry *
WildTangent (HKCR\clsid\{fa13a9fa-ca9b-11d2-9780-00104b242ea3}) Registry *
WildTangent (HKCR\Interface\{1DE680D4-84B7-4239-A887-9482A29DBE14}) Registry *
WildTangent (HKCR\Interface\{25F53F41-0C37-40FA-AE9F-A260DB2D64CF}) Registry *
WildTangent (HKCR\TypeLib\{4A165BD0-165F-474F-AF66-40CD5AC4613E}) Registry *
WildTangent (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls##wtControlPanel) Registry *
XXXToolbar (HKCU\Software\Policies\Avenue Media) Registry *
XXXToolbar (HKLM\SOFTWARE\Policies\Avenue Media) Registry *
XXXToolbar (HKLM\SYSTEM\LastKnownGoodRecovery\LastGood) Registry *
Zango Search Assistant (HKCU\Software\Policies\Avenue Media) Registry *
Zango Search Assistant (HKLM\SOFTWARE\Policies\Avenue Media) Registry *
eUniverse/IncrediFind (multiple) general malware *
Grokster (multiple) general malware *
Kazaa Promotional Items (multiple) general malware *
Mnibug (multiple) general malware *
TopSearch (multiple) general malware *
Tracking Cookie (wim@tribalfusion[1].txt) cookie file *
Mnibug (C:\Program Files\AWS\WeatherBug\REMOVE.EXE) file *
HotBar (C:\Program Files\hbinst\hbinst.exe) file *
Kazaa Promotional Items (C:\Program Files\Kazaa\Promotions\Free Casino Chips.ico) file *
Kazaa Promotional Items (C:\Program Files\Kazaa\Promotions\Play cards now.ico) file *
Joltid P2P Networking (C:\WINDOWS\browserxtras\pn\remove.exe) file *
Joltid P2P Networking (C:\WINDOWS\cdmxtras\uninst.exe) file *
Joltid P2P Networking (C:\WINDOWS\Downloaded Program Files\WebP2PInstaller.dll) file *
eZula (C:\WINDOWS\ezulains.exe) file *
Grokster (C:\WINDOWS\smdat32a.sys) file *
Grokster (C:\WINDOWS\smdat32m.sys) file *
Joltid P2P Networking (C:\WINDOWS\System32\P2P Networking\MARSHAL.DLL) file *
Joltid P2P Networking (C:\WINDOWS\System32\P2P Networking\P2P Networking.eng) file *
Joltid P2P Networking (C:\WINDOWS\System32\P2P Networking\P2P Networking.exe) file *
Dyfuca/Internet Optimizer (C:\WINDOWS\optimize.exe) file *
Mnibug (C:\PROGRAM FILES\AWS\WeatherBug\MiniBugTransporter.dll) file *
 
okey nu moet het goed zijn

hier komt mijn log nog een keer

bedankt buffy voor de uitleg

Logfile of HijackThis v1.98.2
Scan saved at 15:17:59, on 19-10-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\ewupdater.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
F:\scan\Spyware Doctor\spydoctor.exe
C:\Program Files\FSG\DialerDetect\dd.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.boogo.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.easywebsearch.nl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {CA268D0C-7AEB-434C-AEF4-6FC930E5162E} - C:\WINDOWS\System32\dcppa.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ewupdater] C:\WINDOWS\ewupdater.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [Windows SyncroAd] C:\Program Files\Windows SyncroAd\SyncroAd.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "F:\scan\Spyware Doctor\spydoctor.exe" /Q
O4 - Startup: Dialer Detect.lnk = C:\Program Files\FSG\DialerDetect\dd.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://surechat.com:9000/Java/cfs31229.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {22222222-2222-2222-2222-222222222222} - file://c:\x.cab
O16 - DPF: {3F2705D0-C9D8-4020-A15C-E495A0050EC6} (Easywebinstaller Control) - http://s7.blingblingcontent.com/toolbarcash/activex/easywebinstaller.ocx
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Filter: text/html - {840C9E84-658B-4FCE-8515-F083D5ADD059} - C:\WINDOWS\System32\dcppa.dll
O18 - Filter: text/plain - {840C9E84-658B-4FCE-8515-F083D5ADD059} - C:\WINDOWS\System32\dcppa.dll
O21 - SSODL: SystemCheck - {54645654-2225-4455-44A1-9F4543D34544} - C:\WINDOWS\System32\vbsys.dll
 
Geplaatst door bolletje40

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.easywebsearch.nl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: (no name) - {CA268D0C-7AEB-434C-AEF4-6FC930E5162E} - C:\WINDOWS\System32\dcppa.dll

O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [ewupdater] C:\WINDOWS\ewupdater.exe
O4 - HKLM\..\Run: [Windows SyncroAd] C:\Program Files\Windows SyncroAd\SyncroAd.exe

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://surechat.com:9000/Java/cfs31229.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {22222222-2222-2222-2222-222222222222} - file://c:\x.cab
O16 - DPF: {3F2705D0-C9D8-4020-A15C-E495A0050EC6} (Easywebinstaller Control) - http://s7.blingblingcontent.com/toolbarcash/activex/easywebinstaller.ocx

O18 - Filter: text/html - {840C9E84-658B-4FCE-8515-F083D5ADD059} - C:\WINDOWS\System32\dcppa.dll
O18 - Filter: text/plain - {840C9E84-658B-4FCE-8515-F083D5ADD059} - C:\WINDOWS\System32\dcppa.dll

O21 - SSODL: SystemCheck - {54645654-2225-4455-44A1-9F4543D34544} - C:\WINDOWS\System32\vbsys.dll




1. Installeer CWShredder 2.0 alvast, maar gebruik het programma nog niet: http://cwshredder.net/bin/CWSInstall.exe

2. Scan met HijackThis, vink de bovenstaande items (zie quote) aan, sluit alle vensters behalve HijackThis zelf en klik op "Fix checked".

3. Draai nú CWShredder. Gebruik de Fix knop.

4. Herstart de pc in veilige modus.
Mocht je niet weten hoe dat moet, kijk dan hier even: http://www.virushelp.nl/veilige_modus.htm

Zorg ervoor dat verborgen bestanden en mappen worden weergegeven.
Hier kun je lezen hoe dat moet: http://users.telenet.be/marcvn/spyware/1117602.htm

Verwijder nu, in veilige modus dus, de volgende bestanden en mappen (voor zover nog aanwezig):

Bestanden:
C:\WINDOWS\ewupdater.exe
C:\WINDOWS\vsnpstd.exe
C:\WINDOWS\System32\dcppa.dll
C:\WINDOWS\System32\vbsys.dll

Mappen:
C:\Program Files\Windows SyncroAd
C:\WINDOWS\System32\P2P Networking

5. Herstart de pc in 'normale modus'.

6. Installeer CleanUp!: http://downloads.stevengould.org/cleanup/CleanUp312.exe
Draai dit programma door op de knop "CleanUp!" te klikken. Dan even geduld hebben tot het venstertje met "CleanUp! Finished..." verschijnt. Enfin, het wijst zichzelf wel, het is een simpel programma.

7. Installeer AdAware SE 1.05: http://www.majorgeeks.com/download506.html
Haal de nieuwste updates op, doe de volledige scan en laat alles verwijderen wat wordt gevonden.
Start daarna de pc opnieuw op.

8. Maak een nieuw HijackThis-log en plaats dat hier.
 
hoi hoi

ik heb alles uitgevoerd zoals boven beschreven

hier de nieuwe log


Logfile of HijackThis v1.98.2
Scan saved at 17:10:33, on 19-10-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
F:\scan\Spyware Doctor\spydoctor.exe
C:\Program Files\FSG\DialerDetect\dd.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
F:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.boogo.nl/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [ewupdater] C:\WINDOWS\ewupdater.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\RunOnce: [CleanUp!] C:\Program Files\CleanUp!\Cleanup.exe /WindowsRestart
O4 - Startup: Dialer Detect.lnk = C:\Program Files\FSG\DialerDetect\dd.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
 
1. Scan met HijackThis en vink het volgende item aan:

O4 - HKLM\..\Run: [ewupdater] C:\WINDOWS\ewupdater.exe

Sluit alle vensters behalve HijackThis zelf en klik op "Fix checked".

2. Start de pc opnieuw op.

3. Maak een nieuw log en plaats dat hier.
 
okey ,dit moet hem dan zijn

bedankt voor je hulp buffy:thumb: :thumb:

Logfile of HijackThis v1.98.2
Scan saved at 17:24:51, on 19-10-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\FSG\DialerDetect\dd.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
F:\hijackthis\HijackThis.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
C:\WINDOWS\system32\rundll32.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.boogo.nl/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - Startup: Dialer Detect.lnk = C:\Program Files\FSG\DialerDetect\dd.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
 
Status
Niet open voor verdere reacties.
Terug
Bovenaan Onderaan