Last van een virus, malware, spam of storende pop-ups tijdens het internetten? HijackThis helpt je graag verder.

Welkom op HijackThis, op dit forum kan je terecht voor gratis hulp bij het verwijderen van virussen, malware en andere schadelijke software. Als gast kan je alleen het forum bekijken en meelezen met de verschillende discussies. Klik op de onderstaande link om geheel gratis een gebruikersaccount op ons forum te registreren.

Klik hier om een gratis account te registreren!

Donaties

Ben je tevreden over de manier waarop onze medewerkers je geholpen hebben op HijackThis.nl? Of wil je HijackThis.nl een hart onder de riem steken om dit vrijwilligerswerk verder te kunnen blijven doen? Overweeg dan eens of je een (vrijblijvende) donatie aan ons forum kan doen. Met dank bij voorbaat voor de donatie die je aan HijackThis.nl hebt gedaan!

donaties

Startpagina niet meer krijgen en ongewenste reklame

Vragen over software-problemen
Forumregels
Plaats hier a.u.b. geen FRST/RSIT/DDS/HijackThis logjes!
Deze sectie is alleen bestemd voor algemene computerproblemen.
Problemen die veroorzaakt worden door infecties zullen worden behandeld in de daarvoor bestemde sectie van het forum.
mauky
Lid
Berichten: 28
Lid geworden op: 12 feb 2007 12:47
Besturingssysteem: WindowsXP
Bescherming: AVC
Locatie: Workum

Startpagina niet meer krijgen en ongewenste reklame

Bericht door mauky » 02 mar 2014 10:23

Hallo
Ik kan mijn startpagina KPN niet meer krijgen,heb last van ongewenste reklame.

Explorer is overgenomen door delta-homes.com.

Kunnen jullie me helpen?

Gebruikersavatar
Abraham54
Collega Helper
Berichten: 3165
Lid geworden op: 15 feb 2010 21:00
Besturingssysteem: Windows 10 Professional x64
Bescherming: Windows Defender
Locatie: Grootste stad vanTwente
Contacteer:

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door Abraham54 » 02 mar 2014 11:21

Graag de drie logs in één keer bijvoegen - de fix in de opgegeven volgorde afwikkelen.

Stap •1•
Download Afbeelding MalwareBytes' Anti-Malware(mirror)(website) en sla het op je bureaublad op.

Zorg dat er na de installatie een vinkje is geplaatst bij:
  • Update MalwareBytes' Anti-Malware
  • Start MalwareBytes' Anti-Malware
  • Je krijgt hier ook de keuze om de evaluatie versie van MBAM te gebruiken, indien je dit niet wilt vink dit dan uit.
Klik daarna op "Voltooien".
De databaseupdate zal gedownload en geïnstalleerd worden.

Bij problemen!!! (Lees de onderstaande instructies)
  • Zodra het programma gestart is, ga dan naar het tabblad "Instellingen".
  • Vink hier aan: "Sluit Internet Explorer tijdens verwijdering van malware".
  • Daarna: "Scanner Instellingen". Onderaan bij "PUP" kiezen voor "Weergeven in scan resultaten - selecteren voor verwijdering".
  • Ga daarna naar het tabblad "Scanner", kies hier voor "Snelle Scan".
  • Druk vervolgens op de knop "Scannen" om de scan te starten.
  • Het scannen kan een tijdje duren, wees dus geduldig.
  • Wanneer de scan voltooid is, klik op OK, daarna "Bekijk Resultaten" om de resultaten te zien.
  • Zorg ervoor dat daar alles aangevinkt is, daarna klik op: "Verwijder geselecteerde".
  • Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten.
  • Herstart de computer indien nodig en post hierna de log als bijlage in het volgende bericht.
Het log wordt automatisch bewaard door MalwareBytes' Anti-Malware en kan worden teruggevonden door op de "Logs" tab te klikken in het programma.

Stap •2•
Download de Afbeelding Junkware Removal Tool by Thisisu naar je bureaublad.
Schakel de antivirus- en antispywareprogramma's uit, mogelijk kunnen deze conflicteren met JRT
(hier of hier) kan je lezen hoe je de gebruikte beveiligingssoftware kunt uitschakelen.
  • Dubbelklik op JRT.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Het tool zal aansluitend het systeem scannen.
  • De scan kan afhankelijk van de computersysteemspecificaties soms vrij lang duren, wacht geduldig af.
  • Indien de scan gereed is, zal er een logje (JRT.txt) op het bureaublad opgeslagen worden en automatisch worden geopend.
  • Post de inhoud van deze log in je volgende bericht als bijlage.
Stap •3•
Download Afbeelding AdwCleaner by Xplode naar het bureaublad.
  • Sluit alle openstaande vensters.
  • Dubbelklik op AdwCleaner om hem te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren,
  • Door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Klik vervolgens op Scan.
  • Klik vervolgens op Clean als er items zijn gevonden.
  • Klik bij Herstarten Noodzakelijk op OK
Nadat de PC opnieuw is opgestart, opent meestal een logfile.
Anders is het hier terug te vinden C:\AdwCleaner\AdwCleaner[S0].txt.

Logbestand plaatsen
  • Voeg het logbestand met de naam C:\AdwCleaner\AdwCleaner[S0].txt als bijlage toe aan het volgende bericht.
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.
Domheid is ook een gave God's, maar men mag haar niet misbruiken.

mauky
Lid
Berichten: 28
Lid geworden op: 12 feb 2007 12:47
Besturingssysteem: WindowsXP
Bescherming: AVC
Locatie: Workum

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door mauky » 02 mar 2014 16:36

Zoals gevraagt de drie logjes.
Internet start nu al weer op met mn startpagina KPNvandaag,

Maar ik kan de anp berichten nog niet openen en ik krijg een bericht activeX disable

Gebruikersavatar
Abraham54
Collega Helper
Berichten: 3165
Lid geworden op: 15 feb 2010 21:00
Besturingssysteem: Windows 10 Professional x64
Bescherming: Windows Defender
Locatie: Grootste stad vanTwente
Contacteer:

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door Abraham54 » 02 mar 2014 16:55

Waarom heb je de logs nog niet bijgevoegd?


Download Afbeelding Security Check
Downloadlokatie: Dit programma absoluut naar het bureaublad downloaden of anders naar het bureaublad verplaatsen!
SecurityCheck.exe opstarten:
  • Windows 2000 en Windows XP: dubbelklik op SecurityCheck.exe.
  • Windows Vista, Windows 7 en Windows 8 rechtsklik op SecurityCheck.exe en kies "Als Administrator uitvoeren".
  • Let op de instrukties in het zwarte venster.
  • Een Kladblok document genaamd checkup.txt dient automatisch open te gaan; sluit dit document via opslaan op het bureaublad.
  • Indien een van je veiligheidstools rapporteert, dat DIG.EXE het internet op wil, sta dit dan toe.
  • Voeg checkup.txt toe aan het volgende bericht.
  • Hoe u dat kan doen, leest u hier
Domheid is ook een gave God's, maar men mag haar niet misbruiken.

mauky
Lid
Berichten: 28
Lid geworden op: 12 feb 2007 12:47
Besturingssysteem: WindowsXP
Bescherming: AVC
Locatie: Workum

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door mauky » 02 mar 2014 17:24

Sorry misverstand.
Ik wist niet dat deze ook nog moest

Ik ben heel blij met jullie hulp, want alleen maak ik vaak het probleem alleen maar erger,door verkeerde keuzes en onwetenheid,

Gebruikersavatar
Abraham54
Collega Helper
Berichten: 3165
Lid geworden op: 15 feb 2010 21:00
Besturingssysteem: Windows 10 Professional x64
Bescherming: Windows Defender
Locatie: Grootste stad vanTwente
Contacteer:

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door Abraham54 » 02 mar 2014 18:10

Indien je nu echt geen logs gaat bijvoegen, wordt het zeer lastig/bijna onmogelijk jou te helpen.
Domheid is ook een gave God's, maar men mag haar niet misbruiken.

mauky
Lid
Berichten: 28
Lid geworden op: 12 feb 2007 12:47
Besturingssysteem: WindowsXP
Bescherming: AVC
Locatie: Workum

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door mauky » 02 mar 2014 21:57

Ik hoop dat het deze keer lukt

mauky
Lid
Berichten: 28
Lid geworden op: 12 feb 2007 12:47
Besturingssysteem: WindowsXP
Bescherming: AVC
Locatie: Workum

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door mauky » 02 mar 2014 22:02

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Microsoft Windows XP x86
Ran by Jels on zo 02-03-2014 at 15:10:48,43
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dealplylive.exe
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully deleted [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\bProtectTabs
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\sweetie.ietoolbar
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\toolbar3.sweetie
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\iminstaller
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-507921405-152049171-682003330-1003\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{dd85d6bf-4787-4a93-99a5-3f0cf0ae8834}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\apn"
Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\babylon"
Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\sweetim"
Successfully deleted: [Folder] "C:\Documents and Settings\Jels\Application Data\babylon"
Successfully deleted: [Folder] "C:\Documents and Settings\Jels\Application Data\drivercure"
Successfully deleted: [Folder] "C:\Documents and Settings\Jels\Application Data\goforfiles"
Successfully deleted: [Folder] "C:\Documents and Settings\Jels\Local Settings\Application Data\searchprotect"
Successfully deleted: [Folder] "C:\Documents and Settings\Jels\Local Settings\Application Data\webplayer"
Successfully deleted: [Folder] "C:\Program Files\dealply"
Successfully deleted: [Folder] "C:\Program Files\mypc backup"
Successfully deleted: [Folder] "C:\Program Files\sweetpacks bundle uninstaller"
Successfully deleted: [Folder] "C:\WINDOWS\system32\wnlt"



~~~ Chrome

Successfully deleted: [Folder] C:\Documents and Settings\Jels\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Successfully deleted: [Folder] C:\Documents and Settings\Jels\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ppdjnkblmcjfnlogjjhpigpdgpcgdpll
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\ppdjnkblmcjfnlogjjhpigpdgpcgdpll





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on zo 02-03-2014 at 15:19:25,48
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

mauky
Lid
Berichten: 28
Lid geworden op: 12 feb 2007 12:47
Besturingssysteem: WindowsXP
Bescherming: AVC
Locatie: Workum

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door mauky » 02 mar 2014 22:06

# AdwCleaner v3.020 - Report created 02/03/2014 at 15:38:12
# Updated 27/02/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Jels - JELS-9WIWUZEM4Z
# Running from : C:\Documents and Settings\Jels\Local Settings\Temporary Internet Files\Content.IE5\TGH5NZQ0\adwcleaner[2].exe
# Option : Clean

***** [ Services ] *****

Service Deleted : winzipersvc

***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\ParetoLogic
Folder Deleted : C:\Documents and Settings\All Users\Application Data\WPM
Folder Deleted : C:\Documents and Settings\All Users\Menu Start\Programma's\WinZipper
Folder Deleted : C:\Program Files\SoftwareUpdater
Folder Deleted : C:\Program Files\Vittalia
Folder Deleted : C:\Program Files\WinZipper
Folder Deleted : C:\Program Files\LimewirePlus
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Documents and Settings\Jels\Local Settings\Application Data\Bundled software uninstaller
Folder Deleted : C:\Documents and Settings\Jels\Local Settings\Application Data\genienext
Folder Deleted : C:\Documents and Settings\Jels\Local Settings\Application Data\Mobogenie
Folder Deleted : C:\Documents and Settings\Jels\Local Settings\Application Data\LimewirePlus
Folder Deleted : C:\Documents and Settings\Jels\Application Data\iRobinHood
Folder Deleted : C:\Documents and Settings\Jels\Application Data\ParetoLogic
Folder Deleted : C:\Documents and Settings\Jels\Application Data\SupTab
Folder Deleted : C:\Documents and Settings\Jels\Application Data\WinZipper
Folder Deleted : C:\Documents and Settings\Jels\Application Data\LimewirePlus
Folder Deleted : C:\Documents and Settings\groentje.1\Application Data\Systweak
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\ffxtlbr@babylon.com
File Deleted : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\1dlwil2j.default\Extensions\firefox@browsefox.com.xpi
File Deleted : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\1dlwil2j.default\Extensions\irobinhood@irobinhood.org.xpi
File Deleted : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\tyh3lv6j.default\Extensions\irobinhood@irobinhood.org.xpi
File Deleted : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\1dlwil2j.default\invalidprefs.js
File Deleted : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\1dlwil2j.default\searchplugins\Babylon.xml
File Deleted : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\1dlwil2j.default\user.js
File Deleted : C:\Documents and Settings\Jels\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Documents and Settings\All Users\Bureaublad\Google Chrome.lnk
Shortcut Disinfected : C:\Documents and Settings\Jels\Bureaublad\Snelkoppeling naar iexplore.lnk
Shortcut Disinfected : C:\Documents and Settings\All Users\Menu Start\Programma's\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Documents and Settings\Jels\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKCU\Software\a6d78bb735be42
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35D-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{47E161A0-F4BA-41DD-A17B-D2EB26AD6A02}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{47E161A0-F4BA-41DD-A17B-D2EB26AD6A02}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{47E161A0-F4BA-41DD-A17B-D2EB26AD6A02}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EEE6C35D-6118-11DC-9C72-001320C79847}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{47E161A0-F4BA-41DD-A17B-D2EB26AD6A02}]
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\chrome.exe\shell\open\command
Key Deleted : HKCU\Software\BrowseFox
Key Deleted : HKCU\Software\GoforFiles
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\LimewirePlus
Key Deleted : HKLM\Software\BrowseFox
Key Deleted : HKLM\Software\GoforFiles
Key Deleted : HKLM\Software\hdcode
Key Deleted : HKLM\Software\ParetoLogic
Key Deleted : HKLM\Software\supTab
Key Deleted : HKLM\Software\supWPM
Key Deleted : HKLM\Software\V9
Key Deleted : HKLM\Software\Vittalia
Key Deleted : HKLM\Software\winzipersvc
Key Deleted : HKLM\Software\Wpm
Key Deleted : HKLM\Software\LimewirePlus
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vittalia
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winzipper
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LimewirePlus Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DealPly
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\FLV Player
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\IePlugins
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\supTab
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Vittalia
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\winzipper
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wpm
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\LimewirePlus Toolbar
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [CustomizeSearch]

-\\ Mozilla Firefox v

[ File : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\1dlwil2j.default\prefs.js ]

Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.dfltLng", "nl");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.id", "a09b39b3000000000000000cf67b3043");
Line Deleted : user_pref("extensions.delta.instlDay", "15989");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");# AdwCleaner v3.020 - Report created 02/03/2014 at 15:38:12
# Updated 27/02/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Jels - JELS-9WIWUZEM4Z
# Running from : C:\Documents and Settings\Jels\Local Settings\Temporary Internet Files\Content.IE5\TGH5NZQ0\adwcleaner[2].exe
# Option : Clean

***** [ Services ] *****

Service Deleted : winzipersvc

***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\ParetoLogic
Folder Deleted : C:\Documents and Settings\All Users\Application Data\WPM
Folder Deleted : C:\Documents and Settings\All Users\Menu Start\Programma's\WinZipper
Folder Deleted : C:\Program Files\SoftwareUpdater
Folder Deleted : C:\Program Files\Vittalia
Folder Deleted : C:\Program Files\WinZipper
Folder Deleted : C:\Program Files\LimewirePlus
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Documents and Settings\Jels\Local Settings\Application Data\Bundled software uninstaller
Folder Deleted : C:\Documents and Settings\Jels\Local Settings\Application Data\genienext
Folder Deleted : C:\Documents and Settings\Jels\Local Settings\Application Data\Mobogenie
Folder Deleted : C:\Documents and Settings\Jels\Local Settings\Application Data\LimewirePlus
Folder Deleted : C:\Documents and Settings\Jels\Application Data\iRobinHood
Folder Deleted : C:\Documents and Settings\Jels\Application Data\ParetoLogic
Folder Deleted : C:\Documents and Settings\Jels\Application Data\SupTab
Folder Deleted : C:\Documents and Settings\Jels\Application Data\WinZipper
Folder Deleted : C:\Documents and Settings\Jels\Application Data\LimewirePlus
Folder Deleted : C:\Documents and Settings\groentje.1\Application Data\Systweak
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\ffxtlbr@babylon.com
File Deleted : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\1dlwil2j.default\Extensions\firefox@browsefox.com.xpi
File Deleted : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\1dlwil2j.default\Extensions\irobinhood@irobinhood.org.xpi
File Deleted : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\tyh3lv6j.default\Extensions\irobinhood@irobinhood.org.xpi
File Deleted : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\1dlwil2j.default\invalidprefs.js
File Deleted : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\1dlwil2j.default\searchplugins\Babylon.xml
File Deleted : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\1dlwil2j.default\user.js
File Deleted : C:\Documents and Settings\Jels\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Documents and Settings\All Users\Bureaublad\Google Chrome.lnk
Shortcut Disinfected : C:\Documents and Settings\Jels\Bureaublad\Snelkoppeling naar iexplore.lnk
Shortcut Disinfected : C:\Documents and Settings\All Users\Menu Start\Programma's\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Documents and Settings\Jels\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKCU\Software\a6d78bb735be42
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35D-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{47E161A0-F4BA-41DD-A17B-D2EB26AD6A02}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{47E161A0-F4BA-41DD-A17B-D2EB26AD6A02}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{47E161A0-F4BA-41DD-A17B-D2EB26AD6A02}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EEE6C35D-6118-11DC-9C72-001320C79847}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{47E161A0-F4BA-41DD-A17B-D2EB26AD6A02}]
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\chrome.exe\shell\open\command
Key Deleted : HKCU\Software\BrowseFox
Key Deleted : HKCU\Software\GoforFiles
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\LimewirePlus
Key Deleted : HKLM\Software\BrowseFox
Key Deleted : HKLM\Software\GoforFiles
Key Deleted : HKLM\Software\hdcode
Key Deleted : HKLM\Software\ParetoLogic
Key Deleted : HKLM\Software\supTab
Key Deleted : HKLM\Software\supWPM
Key Deleted : HKLM\Software\V9
Key Deleted : HKLM\Software\Vittalia
Key Deleted : HKLM\Software\winzipersvc
Key Deleted : HKLM\Software\Wpm
Key Deleted : HKLM\Software\LimewirePlus
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vittalia
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winzipper
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LimewirePlus Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DealPly
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\FLV Player
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\IePlugins
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\supTab
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Vittalia
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\winzipper
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wpm
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\LimewirePlus Toolbar
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [CustomizeSearch]

-\\ Mozilla Firefox v

[ File : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\1dlwil2j.default\prefs.js ]

Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.dfltLng", "nl");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.id", "a09b39b3000000000000000cf67b3043");
Line Deleted : user_pref("extensions.delta.instlDay", "15989");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.smplGrp", "none");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.24.6");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.24.623:14:58");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.24.6");
Line Deleted : user_pref("extensions.delta_i.babExt", "");
Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=120684&tt=02102013_ctrl1&tsp=5032");
Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");

[ File : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\tyh3lv6j.default\prefs.js ]


-\\ Google Chrome v33.0.1750.117

[ File : C:\Documents and Settings\Jels\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : search_url
Deleted : keyword

*************************

AdwCleaner[R0].txt - [12893 octets] - [02/03/2014 15:36:41]
AdwCleaner[S0].txt - [11666 octets] - [02/03/2014 15:38:12]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11727 octets] ##########

Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.smplGrp", "none");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.24.6");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.24.623:14:58");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.24.6");
Line Deleted : user_pref("extensions.delta_i.babExt", "");
Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=120684&tt=02102013_ctrl1&tsp=5032");
Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");

[ File : C:\Documents and Settings\Jels\Application Data\Mozilla\Firefox\Profiles\tyh3lv6j.default\prefs.js ]


-\\ Google Chrome v33.0.1750.117

[ File : C:\Documents and Settings\Jels\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : search_url
Deleted : keyword

*************************

AdwCleaner[R0].txt - [12893 octets] - [02/03/2014 15:36:41]
AdwCleaner[S0].txt - [11666 octets] - [02/03/2014 15:38:12]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11727 octets] ##########

Gebruikersavatar
Abraham54
Collega Helper
Berichten: 3165
Lid geworden op: 15 feb 2010 21:00
Besturingssysteem: Windows 10 Professional x64
Bescherming: Windows Defender
Locatie: Grootste stad vanTwente
Contacteer:

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door Abraham54 » 02 mar 2014 22:16

En het MBAM log?
Het log wordt automatisch bewaard door Malwarebytes MBAM en dat kan je terugvinden door in het hoofdmenu van Malwarebytes MBAM op de tab 'Logbestanden' te klikken.
Domheid is ook een gave God's, maar men mag haar niet misbruiken.

mauky
Lid
Berichten: 28
Lid geworden op: 12 feb 2007 12:47
Besturingssysteem: WindowsXP
Bescherming: AVC
Locatie: Workum

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door mauky » 02 mar 2014 22:46

Ik hoop dat het deze keer goed is.

het gaat een beetje moeizaam,maar beetje bij beetje zal het wel lukken.

Ik doe mijn best.

Gebruikersavatar
Abraham54
Collega Helper
Berichten: 3165
Lid geworden op: 15 feb 2010 21:00
Besturingssysteem: Windows 10 Professional x64
Bescherming: Windows Defender
Locatie: Grootste stad vanTwente
Contacteer:

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door Abraham54 » 02 mar 2014 23:16

Ik zie helemaal niks behalve wat jij zelf geschreven hebt.
Domheid is ook een gave God's, maar men mag haar niet misbruiken.

mauky
Lid
Berichten: 28
Lid geworden op: 12 feb 2007 12:47
Besturingssysteem: WindowsXP
Bescherming: AVC
Locatie: Workum

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door mauky » 03 mar 2014 20:36

Ik probeer nu een logje van malwareBytes te versturen.
MBAM-log-2014-03-02 (12-54-09).txt

mauky
Lid
Berichten: 28
Lid geworden op: 12 feb 2007 12:47
Besturingssysteem: WindowsXP
Bescherming: AVC
Locatie: Workum

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door mauky » 03 mar 2014 20:46

Hebt u helemaal geen logje van mij ontvangen?

Hoe kan ik zien of een logje ook te groot is?

Gebruikersavatar
Abraham54
Collega Helper
Berichten: 3165
Lid geworden op: 15 feb 2010 21:00
Besturingssysteem: Windows 10 Professional x64
Bescherming: Windows Defender
Locatie: Grootste stad vanTwente
Contacteer:

Re: Startpagina niet meer krijgen en ongewenste reklame

Bericht door Abraham54 » 03 mar 2014 20:49

Waarom heb je niks laten verwijderen door MBAM.
Want je nogal wat rotzooi in jouw Windows zitten.
Dus start MBAM weer en laat nu alles verwijderen wat MBAM vindt.
Domheid is ook een gave God's, maar men mag haar niet misbruiken.

Plaats reactie