Vraag & Antwoord
ongewenste startpagina
5 antwoorden
- op 't eind van de windows opstart procedure komt er 'n website waar ik niet om gevraagd heb
tevens wordt de opstartpagina van IE steeds veranderd
ik heb het volgende geprobeerd (heb windows 98 se):
- autoexec.bat nagekeken
- via msconfig de opgestarte programma's gecheckt
- in register naam van die site verwijderd, maar komt steeds weer terug ?!
- via "extra" en "internet opties" de startpagina veranderd
geen resultaat!!
iemand 'n idee hoe dit op te lossen?
alvast bedankt - Doe dit eens:
Download StartupList
Uitpakken, erop dubbelklikken, en je krijgt een tekstbestand dat een uitgebreid overzicht geeft van alles wat er zich op jouw computer afspeelt
Ga naar Bewerken > Alles selecteren, kopiëer het, en laat de inhoud hier eens zien. - bedankt Ton
hoe kom ik aan die 2 ongevraagde websites vraag je je misschien af?
had 'n no cd-patch via KaZaA gedownload
geen no cd-patch dus, wel 2 vervelende websites
hier is de lijst
ik zie iets van Britney Spears staan (screensaver?), hoe het er komt weet ik niet, echt waar lol
maar ik zie niks van die 2 sites (gaymen sites!)
hopelijk zie jij meer
StartupList report, 12-10-02, 18:02:12
StartupList version: 1.34.0
Started from : E:\INSTALL\STARTUP LIST\STARTUPLIST\STARTUPLIST.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v5.51 SP2 (5.51.4807.2300)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\NETWORK ICE\BLACKICE\BLACKD.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVSYNMGR.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\WEBSCANX.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\DATFILES\BRITTNEY_SPEARS_NUDE_COLLECTION.EXE
F:\PROGRAMS\WINAMP273\WINAMPA.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\ALOGSERV.EXE
E:\HARDWARE\INCD\INCD.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\NETWORK ICE\BLACKICE\BLACKICE.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
E:\INSTALL\STARTUP LIST\STARTUPLIST\STARTUPLIST.EXE
————————————————–
Listing of startup folders:
Shell folders Startup:
[C:\WINDOWS\Start Menu\Programma's\Opstarten]
BlackICE Utility.lnk = C:\Program Files\Network ICE\BlackICE\blackice.exe
Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
Taakcontrole = C:\WINDOWS\taskmon.exe
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
WinampAgent = "F:\PROGRAMS\WINAMP273\WINAMPa.exe"
LoadQM = loadqm.exe
Alogserv = C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
InCD = E:\HARDWARE\InCD\InCD.exe
POINTER = point32.exe
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
LoadBlackD = C:\Program Files\Network ICE\BlackICE\blackd.exe
McAfeeVirusScanService = C:\Program Files\McAfee\McAfee VirusScan\AVSYNMGR.EXE
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MSMSGS = "C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE" /background
————————————————–
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = C:\WINDOWS\SYSTEM\IE4UINIT.EXE
[PerUser_LinkBar_URLs] *
StubPath = C:\WINDOWS\COMMAND\sulfnbk.exe /L
[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "C:\Program Files\Outlook Express\setup50.exe" /APPE /CALLER:IE50 /user /install
[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
————————————————–
Load/Run keys from C:\WINDOWS\WIN.INI:
load=
run=
————————————————–
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=explorer.exe C:\WINDOWS\DatFiles\brittney_spears_nude_collection.exe
SCRNSAVE.EXE=
drivers=mmsystem.dll power.drv
————————————————–
Checking for EXPLORER.EXE instances:
C:\WINDOWS\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
————————————————–
C:\WINDOWS\WININIT.BAK listing:
(Created 11/10/2002, 11:19:50)
[Rename]
C:\WINDOWS\SYSTEM\NVMODE.DLL=C:\WINDOWS\SYSTEM\TMP0.@@@
C:\WINDOWS\SYSTEM\NVARCH16.DLL=C:\WINDOWS\SYSTEM\TMP1.@@@
C:\WINDOWS\SYSTEM\NVARCH32.DLL=C:\WINDOWS\SYSTEM\TMP2.@@@
C:\WINDOWS\SYSTEM\NVDD32.DLL=C:\WINDOWS\SYSTEM\TMP3.@@@
————————————————–
C:\AUTOEXEC.BAT listing:
SET BLASTER=A220 I7 D1 H5 P330 T6
SET CTSYN=C:\WINDOWS
C:\PROGRA~1\CREATIVE\SBLIVE\DOSDRV\SBEINIT.COM
mode con codepage prepare=((850) C:\WINDOWS\COMMAND\ega.cpi)
mode con codepage select=850
keyb br,,C:\WINDOWS\COMMAND\keyboard.sys
C:\PROGRA~1\COMMON~1\NETWOR~1\VIRUSS~1\40~1.XX\scan.exe C:\
@IF ERRORLEVEL 1 PAUSE
————————————————–
C:\CONFIG.SYS listing:
DEVICE=C:\WINDOWS\HIMEM.SYS
DEVICE=C:\WINDOWS\EMM386.EXE
DEVICE=C:\WINDOWS\setver.exe
device=C:\WINDOWS\COMMAND\display.sys con=(ega,,1)
Country=031,850,C:\WINDOWS\COMMAND\country.sys
————————————————–
C:\WINDOWS\DOSSTART.BAT listing:
C:\PROGRA~1\CREATIVE\SBLIVE\DOSDRV\SBEINIT.COM
————————————————–
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
————————————————–
Enumerating Task Scheduler jobs:
Toepassing Optimalisatie Start.job
————————————————–
End of report, 6.565 bytes
Report generated in 0,531 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only - Iets heeft inderdaad je System.ini gehacked.
Doe dit:
Ga naar Start > Uitvoeren, en type [b:d9a376be41]system.ini[/b:d9a376be41] > 'OK'.
Je System.ini wordt nu geopend in Notepad.
Je ziet daar een regel [b:d9a376be41]Shell=explorer.exe C:\WINDOWS\DatFiles\brittney_spears_nude_collection.exe [/b:d9a376be41]
Verander die, zodat er alleen nog maar b]Shell=explorer.exe overblijft.
Sla op in 'Bestand', en sluit je System.ini.
Start even opnieuw op.
En nu? - dat was 'n makkie!!
en de sites zijn weg
fantastisch
hartstikke bedankt Ton
Beantwoord deze vraag
Dit is een gearchiveerde pagina. Antwoorden is niet meer mogelijk.