werkbalken

Status
Niet open voor verdere reacties.

Viperrr

Gebruiker
Lid geworden
7 aug 2001
Berichten
737
Hallo,
Door voor mij onbekende redenen heb ik nu in ene t een en ander aan rotzooi op mu pc staan qua spyware, ongevraagde software etc...
Ik gok dat t de sguld is van mu zuz (Digibeet), want kben altijd heel voorzigtug :)
Naja anyway, skip the bs, keb nu n werkbalk diek nie wil! in me IE.. Ik heb de adres balk, daaronder de google balk en daaronder n balk die heet (in t contextmenu) oacmeastcki. Verbergen kan ik m, maar eraf gooien... hoe doe ik dat?
 
had ik laatst ook last van, moet je ff naar config. scherm, software en dan alle troep die jij niet wil gooi je er daar vanaf, voor spyware is er een handig programma dat heet Ad Aware 6 deze kun je downloaden onder andere bij www.hetnet.nl dan ff naar shareware /de 10 hotste downloads (rechtsonder aan de site) dan staatie als 2e in het rijtje.
weet niet of je er uitkomt maar suc6 in ieder geval!!
 
grmbl... had Ad-Aware er al overheen gehaald, virusscanner ook, zal nog ff in mu software kijke...

En dan nog wat
als ik m verberg zet ie zichzelf weer trug.... das erges in t register... weet iemand waar?
 
Zou je het volgende willen doen:

Ga naar http://www.tomcoyote.org/hjt/ , en download daar 'Hijack This'.

Uitpakken, en vervolgens dubbelklikken op HijackThis.exe.
Klik op "Scan", en vervolgens op "Save Log File" , en post vervolgens de inhoud van die log hier.
 
Logfile of HijackThis v1.94.0
Scan saved at 13:51:30, on 2-6-2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://w26125.find-quick.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://w26125.find-quick.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.google.nl/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://w26125.find-quick.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar=http://w26125.find-quick.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=http://w26125.find-quick.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=http://www.wanadoo.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://w26125.find-quick.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title=Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
O2 - BHO: (no name) - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - C:\DAP\DAPIEBar.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {82e09eec-6072-42ae-82fa-768dc5178192} - C:\DOCUME~1\SilverX\APPLIC~1\brssoeajfdr.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\WINDOWS\Downloaded Program Files\googlenav.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\DAP\DAPIEBar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: oacmeastcki - {bc2ab08e-56e5-4f83-8463-42052fd1059a} - C:\DOCUME~1\SilverX\APPLIC~1\brssoeajfdr.dll
O4 - HKLM\..\Run: [DisplayTrayIcon] C:\WINDOWS\System32\TrayIcon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AudioHQ] C:\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [DownloadAccelerator] C:\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [lljfss] C:\DOCUME~1\SilverX\APPLIC~1\stoacrkc.exe -QuieT
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Popup Ad Filter] C:\Popup Ad Filter\PopFilter.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [System Tray] C:\WINDOWS\msccn32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - C:\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\Downloaded Program Files\googlenav.dll/cmsearch.html
O8 - Extra context menu item: Allow Popups - C:\Popup Ad Filter\WhiteGetUrl.js
O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\Downloaded Program Files\googlenav.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\Downloaded Program Files\googlenav.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\Downloaded Program Files\googlenav.dll/cmsimilar.html
O9 - Extra button: Run DAP (HKLM)
O9 - Extra button: Help (HKCU)
O9 - Extra button: Website (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.nl
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/SU-NewOCX/ocx/CTSUEng.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) - http://toolbar.google.com/data/nl/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37651.1917824074
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/SU-NewOCX/ocx/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = w26783.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{01A78854-53F7-4022-A16D-2E2F5D78C6CE}: Domain = w26783.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{84CE7A3C-622A-41BC-B0D0-E0F5B12424A0}: Domain = w26783.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{9722F945-BC07-4A26-A507-0EE4BEA0218C}: Domain = w26783.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{BDD20647-A314-4859-8848-0D316C6F58BD}: Domain = w26783.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{FABFA752-658B-44FD-AE92-5FEE421397E1}: Domain = w26783.find-quick.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = w26783.find-quick.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{01A78854-53F7-4022-A16D-2E2F5D78C6CE}: Domain = w26783.find-quick.com
 
Hoi Viperrr,

Het lijkt heel veel, maar het is alleen maar lop.com en de ingebouwde HP spyware.
Vink de volgende aan in HijackTHis, sluit alle IE, OE en verkenner vensters en klik op Fix checked:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://w26125.find-quick.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://w26125.find-quick.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://w26125.find-quick.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar=http://w26125.find-quick.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=http://w26125.find-quick.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://w26125.find-quick.com/searchbar.html
O2 - BHO: (no name) - {82e09eec-6072-42ae-82fa-768dc5178192} - C:\DOCUME~1\SilverX\APPLIC~1\brssoeajfdr.dll
O3 - Toolbar: oacmeastcki - {bc2ab08e-56e5-4f83-8463-42052fd1059a} - C:\DOCUME~1\SilverX\APPLIC~1\brssoeajfdr.dll
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = w26783.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{01A78854-53F7-4022-A16D-2E2F5D78C6CE}: Domain = w26783.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{84CE7A3C-622A-41BC-B0D0-E0F5B12424A0}: Domain = w26783.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{9722F945-BC07-4A26-A507-0EE4BEA0218C}: Domain = w26783.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{BDD20647-A314-4859-8848-0D316C6F58BD}: Domain = w26783.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{FABFA752-658B-44FD-AE92-5FEE421397E1}: Domain = w26783.find-quick.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = w26783.find-quick.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{01A78854-53F7-4022-A16D-2E2F5D78C6CE}: Domain = w26783.find-quick.com

Opnieuw opstarten en dit bestandje verwijderen C:\DOCUME~1\SilverX\APPLIC~1\brssoeajfdr.dll

Dan zou het weer goed moeten zijn.

Groetjes,

Pieter
 
WOOHOO!
Het = weg.
Ik dank jullie allen zeer.

Now if you'll escuse me, I have to go bitchslap my sister...
 
Status
Niet open voor verdere reacties.
Terug
Bovenaan Onderaan