ik heb zo geexpirimenteerd en nu ben ik weer online ...maar hoelang nog
kijk wat microsoft aangeeft als fout
STOP 0x000000EA THREAD_STUCK_IN_DEVICE_DRIVER
lSTOP: 0x100000EA THREAD_STUCK_IN_DEVICE_DRIVER_M
en dit is de hijack
ik heb het een en ander gedownload en dan op sites met crack keycode geweest
daar pakte ik een virus trojan binnen
ik zal toch voorzichtiger zijn in de toekomst
bedankt
Logfile of HijackThis v1.97.7
Scan saved at 23:47:38, on 21-7-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C

rogram FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSsystem32spoolsv.exe
C

rogram FilesNorton AntiVirusnavapsvc.exe
C

rogram FilesNorton AntiVirusAdvToolsNPROTECT.EXE
C:WINDOWSsystem32ZoneLabsvsmon.exe
C:WINDOWSExplorer.EXE
C

rogram FilesWindUpdatesWinUpdt.exe
C

rogram FilesZone LabsZoneAlarmzlclient.exe
C

rogram FilesCommon FilesRealUpdate_OBrealsched.exe
C:WINDOWSkdxKHost.exe
C

rogram FilesInternet Exploreriexplore.exe
C

rogram FilesiTunesiTunesHelper.exe
C

rogram FilesCommon FilesSymantec SharedccApp.exe
C:WINDOWSSystem32ctfmon.exe
C

rogram FilesiPodbiniPodService.exe
C

rogram FilesSpy Cleaner GoldSpyWatcher.exe
C

rogram FilesMessengermsmsgs.exe
C

ocuments and SettingsantiguaLocal SettingsTempTemporary Directory 1 for hijackthis[1].zipHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.google.be/
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Telenet Internet
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) =
http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,AutoConfigURL =
http://pac.telenet.be:8080
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WINDOWSPCHEALTHHELPCTRSystempanelsblank.htm
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WINDOWSPCHEALTHHELPCTRSystempanelsblank.htm
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak =
http://www.google.be/
R3 - URLSearchHook: (no name) - _{707E6F76-9FFB-4920-A976-EA101271BC25} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C

rogram FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C

ROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c

rogram filesgooglegoogletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C

rogram FilesNorton AntiVirusNavShExt.dll
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c

rogram filesgooglegoogletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C

rogram FilesNorton AntiVirusNavShExt.dll
O4 - HKLM..Run: [WindUpdates] C

rogram FilesWindUpdatesWinUpdt.exe
O4 - HKLM..Run: [Zone Labs Client] "C

rogram FilesZone LabsZoneAlarmzlclient.exe"
O4 - HKLM..Run: [TkBellExe] "C

rogram FilesCommon FilesRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [kdx] C:WINDOWSkdxKHost.exe
O4 - HKLM..Run: [iTunesHelper] C

rogram FilesiTunesiTunesHelper.exe
O4 - HKLM..Run: [ccRegVfy] "C

rogram FilesCommon FilesSymantec SharedccRegVfy.exe"
O4 - HKLM..Run: [ccApp] "C

rogram FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [Advanced Tools Check] C

ROGRA~1NORTON~1AdvToolsADVCHK.EXE
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSSystem32ctfmon.exe
O4 - HKCU..Run: [Spy Watcher] "C

rogram FilesSpy Cleaner GoldSpyWatcher.exe" -S
O4 - HKCU..Run: [MSMSGS] "C

rogram FilesMessengermsmsgs.exe" /background
O8 - Extra context menu item: &Google Search - res://C

rogram FilesGoogleGoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C

rogram FilesGoogleGoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C

rogram FilesGoogleGoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C

rogram FilesGoogleGoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: Descarregas (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} -
http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://public.windupdates.com/get_file.php...42c5c6546c7d1fb
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwa...director/sw.cab
O16 - DPF: {34A44FCF-50E3-63A5-A8DA-7835752B9571} -
http://www.captaincode.com/ccbar/ccbar.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) -
http://office.microsoft.com/officeupdate/c...ontent/opuc.cab
O16 - DPF: {8F24DE00-0D66-4F93-9405-3F21E97AEE99} (TestingCtl Control) -
http://esb.alcena.com/ESBAdultInstaller.ocx
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) -
http://www.stopzilla.com/_download/Auto_In...ller/dwnldr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwa...ash/swflash.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
http://www.gamespot.com/KDX22/download/kdx.cab