Probeer ook eens cw shredder, ik weet niet of je dat al gedaan hebt?
(gooi je temp & temporarly internet files map ook eens leeg, voordat je begint)
en tussendoor GEEN explorer vensters openen!
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://0cj.net/cat
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\BASVAN~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\BASVAN~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://0cj.net/cat
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://0cj.net/cat
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\BASVAN~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\BASVAN~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\BASVAN~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://0cj.net/srchasst.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = http://0cj.net/srchasst.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\BASVAN~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://0cj.net/srchasst.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://0cj.net/srchasst.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://0cj.net/cat |
code:
1
| R3 - URLSearchHook: (no name) - {30192F8D-0958-44E6-B54D-331FD39AC959} - (no file) |
ken ik niet, scan ze even met bijv.
jotti scan
code:
1
2
3
4
| O2 - BHO: (no name) - {4AB79670-4678-49D7-8952-2A6E1930CC1C} - C:\WINDOWS\System32\kjalb.dll
O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\System32\services\2.01.00.dll
O2 - BHO: (no name) - {82E8FF5B-20DA-4F43-9787-09FA534B7627} - C:\WINDOWS\System32\vehaheo.dll
O2 - BHO: (no name) - {DE3BEBDB-AEE7-4277-8B6E-4EEFFA9508AE} - C:\WINDOWS\System32\oibohi.dll |
ook erg verdacht
code:
1
2
| O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Windows Shell Library Loader] load shell32.dll /c /set |
dit is een virus
code:
1
2
| O4 - HKLM\..\Run: [xpsystem] C:\WINDOWS\system32\services\msxmidi.exe
O4 - HKCU\..\Run: [xpsystem] C:\WINDOWS\system32\services\msxmidi.exe |
spyware
code:
1
| O4 - HKCU\..\RunOnce: [DeleteSlotchBar] rundll32.exe advpack.dll,DelNodeRunDLL32 "C:\Program Files\ISTbar\istbar.dll" |
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
| O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.xxxtoolbar.com
O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://66.98.176.62/EPlugin_NL.cab
O18 - Filter: text/html - {9024C0D8-5D83-4670-A505-AA0F4C8A389A} - C:\WINDOWS\System32\kjalb.dll
O18 - Filter: text/plain - {9024C0D8-5D83-4670-A505-AA0F4C8A389A} - C:\WINDOWS\System32\kjalb.dll |
bestand ontbreekt, geeft ie aan, dus kan waarschijnlijk ook weg
code:
1
| O21 - SSODL: System - {4B2C09B5-8F2F-49A9-B765-683130E55037} - C:\WINDOWS\system32\system32.dll (file missing) |
dit had je zelf ook wel kunnen doen, m.b.v. google
scan je pc nog even op virussen (mcafee online scan bijv)
scan, in veilige modus, met ad-aware, spybot:S&D, spysweeper, cw shredder
en zit na dit alles hier nog even een nieuw hijack log neer!
[
Voor 105% gewijzigd door
Pendaco op 03-08-2004 17:55
]