Hoi Saldos,
Gooi die link naar die uninstaller maar weg. De brancard was geen overbodige luxe.
Ik heb een paar HijackTHis logs gemaakt en daar alles wat niet met lop.com te maken had uitgeknipt.
Na installatie lop.com:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://thko.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://thko.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=thko.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://thko.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar=http://thko.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=http://thko.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://thko.com/searchbar.html
O2 - BHO: (no name) - {00000EF1-34E3-4633-87C6-1AA7A44296DA} - C:\WINDOWS\System32\bleetrfrzdf.dll
O2 - BHO: (no name) - {652d61d4-65df-4c4d-8cdf-bdbe9b9342ff} - C:\DOCUME~1\Pieter\APPLIC~1\gllnprgrtrf.dll
O4 - HKLM\..\Run: [zgrtrl] C:\DOCUME~1\Pieter\APPLIC~1\dhfrstee.exe -QuieT
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = thko.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{575C73D2-1A72-4A39-B8F3-1B8B44829DA9}: Domain = thko.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{73C972C2-467E-4772-8FB2-D4D283F6F173}: Domain = thko.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{7B52223B-7618-4D0D-9866-5D64F0715A42}: Domain = thko.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = thko.com
O18 - Protocol: ayb - {07C0D34D-11D7-43F7-832B-C6BB41726F5F}
Na het runnen van de uninstaller:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://thko.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://thko.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=thko.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://thko.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar=http://thko.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=http://thko.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://thko.com/searchbar.html
O2 - BHO: (no name) - {00000EF1-34E3-4633-87C6-1AA7A44296DA} - C:\WINDOWS\System32\bleetrfrzdf.dll
O2 - BHO: (no name) - {652d61d4-65df-4c4d-8cdf-bdbe9b9342ff} - C:\DOCUME~1\Pieter\APPLIC~1\gllnprgrtrf.dll
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = thko.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{575C73D2-1A72-4A39-B8F3-1B8B44829DA9}: Domain = thko.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{7B52223B-7618-4D0D-9866-5D64F0715A42}: Domain = thko.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = thko.com
O18 - Protocol: ayb - {07C0D34D-11D7-43F7-832B-C6BB41726F5F}
Na het cleanen met Spybot S&D en Adaware6:
O17 - HKLM\System\CCS\Services\Tcpip\..\{575C73D2-1A72-4A39-B8F3-1B8B44829DA9}: Domain = thko.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{7B52223B-7618-4D0D-9866-5D64F0715A42}: Domain = thko.com
Daarna heb ik handmatig nog 5 snelkoppelingen van mijn bureablad en 5
mappen die toegevoegd waren aan mijn favorieten moeten verwijderen. En nu ga ik voor de zekerheid systeemherstel doen.

De Uninstaller verwijderde dus wel de opstartsleutel in het regsister en de bijbehorende exe, maar repareerde verder niks.
Groetjes,
Pieter