Wie wil mijn hijack log bekijken(mysearchnow)

  • Onderwerp starter Onderwerp starter Sorby
  • Startdatum Startdatum
Status
Niet open voor verdere reacties.

Sorby

Gebruiker
Lid geworden
19 feb 2002
Berichten
60
Mijn startpagina is elke keer mysearchnow
Hier wil ik graag vanaf en de rest van de rotzooi

Alvast heel erg bedankt voor het nakijken

Logfile of HijackThis v1.98.2
Scan saved at 21:31:56, on 4-12-2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\drivers\KodakCCS.exe
F:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
F:\Program Files\Norton AntiVirus\navapsvc.exe
F:\Program Files\Norton AntiVirus\SAVScan.exe
F:\WINDOWS\System32\ScsiAccess.EXE
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
F:\WINDOWS\System32\khooker.exe
F:\WINDOWS\system32\RunDll32.exe
F:\Program Files\Real\RealPlayer\RealPlay.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Internet Explorer\iexplore.exe
f:\progra~1\intern~1\iexplore.exe
F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Messenger\msmsgs.exe
F:\Documents and Settings\Gebruiker\Bureaublad\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.nknmfplsgqwde.uk/stQbE82e_rnZF6nAVbOlXaBWNWYvW299XPi4fRT2GHydiA8q1DweZ6HC_/y9hduC.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://web.klbzbxqjnemnvrboctarceh.com/stQbE82e_rlGFSKwixZO2vda/uGPw5LnRDJLEfkqJH4.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.home.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://minisearch.startnow.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://minisearch.startnow.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer aangeboden door @Home
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {12CA6EA3-B1C5-C8E3-D9DB-F19DCA6D6237} - F:\DOCUME~1\GEBRUI~1\APPLIC~1\INSIDE~1\TITLE NOUN.exe
O2 - BHO: (no name) - {531c0204-d872-4d62-9769-9df09724d1d8} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {56BD4A9F-C6BA-1E32-366E-A10E84BA147E} - F:\DOCUME~1\GEBRUI~1\APPLIC~1\INSIDE~1\TITLE NOUN.exe
O2 - BHO: (no name) - {5C575BAB-7D7D-B3FA-AFC8-4EFE29A59CBB} - F:\PROGRA~1\INSIDE~1\TITLE NOUN.exe (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SiS KHooker] F:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [C-Media Speaker Configuration] C:\PROGRA~1\C-Media\WIN_ME\Setup.exe /SPEAKER
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [16 slow byte soft] F:\Documents and Settings\All Users\Application Data\Fast ford 16 slow\FastWarn.exe
O4 - HKLM\..\Run: [Each Obj Sixth Upload] F:\Documents and Settings\All Users\Application Data\Internet Funk Each Obj\SEND ERROR.exe
O4 - HKLM\..\Run: [bowsbataudioreadme] F:\Documents and Settings\All Users\Application Data\FirstAcidBowsBat\recttray.exe
O4 - HKLM\..\Run: [RealTray] F:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [longslow] F:\DOCUME~1\GEBRUI~1\APPLIC~1\FLAGRE~1\GPL FIVE WARN.exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Kodak EasyShare software.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - F:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://start.home.nl/
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28177.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab30149.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://www.ea.com/downloads/rtpatch/EARTPX.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab30149.cab
O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://gto.postbank.nl/GTO/PBGNX.cab
O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://216.65.38.226/crack.CAB
O16 - DPF: {F630A6F3-F89E-4374-99CC-28A8AA003208} - http://sls.switchpoint.com/Connect/switchpoint/5.1/Starter.cab
 
Hoi Sorby,

Ga naar Deze Computer, dubbelklik daar op C. Dubbelklik op Program Files. Klik nu op "Bestand" > "Nieuw" > "Map". Noem deze map HJT of HijackThis. Plaats nu de HijackThis.exe in DIE map. Draai in het vervolg HijackThis vanuit DIE map :). Dit in verband met de backups die dit programma maakt ;)

1. Start HijackThis, en vink onderstaande regels aan:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.nknmfplsgqwde.uk/stQbE82e_rnZF6nAVbOlXaBWNWYvW299XPi4fRT2GHydiA8q1DweZ6HC_/y9hduC.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://web.klbzbxqjnemnvrboctarceh.com/stQbE82e_rlGFSKwixZO2vda/uGPw5LnRDJLEfkqJH4.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.home.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://minisearch.startnow.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://minisearch.startnow.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {12CA6EA3-B1C5-C8E3-D9DB-F19DCA6D6237} - F:\DOCUME~1\GEBRUI~1\APPLIC~1\INSIDE~1\TITLE NOUN.exe
O2 - BHO: (no name) - {531c0204-d872-4d62-9769-9df09724d1d8} - (no file)
O2 - BHO: (no name) - {56BD4A9F-C6BA-1E32-366E-A10E84BA147E} - F:\DOCUME~1\GEBRUI~1\APPLIC~1\INSIDE~1\TITLE NOUN.exe
O2 - BHO: (no name) - {5C575BAB-7D7D-B3FA-AFC8-4EFE29A59CBB} - F:\PROGRA~1\INSIDE~1\TITLE NOUN.exe (file missing)

O4 - HKLM\..\Run: [16 slow byte soft] F:\Documents and Settings\All Users\Application Data\Fast ford 16 slow\FastWarn.exe
O4 - HKLM\..\Run: [Each Obj Sixth Upload] F:\Documents and Settings\All Users\Application Data\Internet Funk Each Obj\SEND ERROR.exe
O4 - HKLM\..\Run: [bowsbataudioreadme] F:\Documents and Settings\All Users\Application Data\FirstAcidBowsBat\recttray.exe
O4 - HKCU\..\Run: [longslow] F:\DOCUME~1\GEBRUI~1\APPLIC~1\FLAGRE~1\GPL FIVE WARN.exe

O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://216.65.38.226/crack.CAB

2. Sluit alle andere vensters en browsers, en klik op de knop “Fix Checked”.

3. Start opnieuw op in veilige modus.
Zorg ervoor dat verborgen bestanden en mappen zichtbaar zijn: Verkenner > Extra > Mapopties > Tablad Weergave > scroll naar beneden en vink het vakje voor "Verborgen bestanden en mappen weergeven" aan.

4. Ga naar Windows Verkenner (Rechtsklikken op Start - Verkennen). Zoek en verwijder het volgende:
Mappen:
F:\Documents and Settings\GEBRUI~1\APPLIC~1\INSIDE...
F:\Program Files\INSIDE...
F:\Documents and Settings\All Users\Application Data\Fast ford 16 slow
F:\Documents and Settings\All Users\Application Data\Internet Funk Each Obj
F:\Documents and Settings\All Users\Application Data\FirstAcidBowsBat
F:\Documents and Settings\GEBRUI~1\APPLIC~1\FLAGRE...

5. Start opnieuw op in normale modus, maak een nieuw logje aan met HijackThis, en post dat hier :)
 
Status
Niet open voor verdere reacties.
Terug
Bovenaan Onderaan