Sinds kort heb ik last van een windows security alert
die zegt dat mijn pc is geinfecteerd en dat ik iets moet klikken om
het te downloaden.. helaas is dit er net opgekomen nadat de virusscanner
verwijderd is.. nu kan ik niets meer installeren wat met een virusscanner te maken heeft... hier meteen mij hijackthis log.
Logfile of HijackThis v1.99.1
Scan saved at 20:37:21, on 30-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\CTFMON.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\NewsLeecher\newsLeecher.exe
C:\Program Files\NewsLeecher\newsLeecher.exe
C:\WINDOWS\avp.exe
C:\WINDOWS\mgrs.exe
C:\DOCUME~1\ELISE&~1\LOCALS~1\Temp\1632.exe
C:\DOCUME~1\ELISE&~1\LOCALS~1\Temp\sysserver.exe
C:\DOCUME~1\ELISE&~1\LOCALS~1\Temp\hostsys.exe
C:\WINDOWS\lsass.exe
C:\DOCUME~1\ELISE&~1\LOCALS~1\Temp\serverhost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Elise & Kieran\Application Data\printer.exe
C:\DOCUME~1\ELISE&~1\LOCALS~1\Temp\powerserver.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\shell.exe
F3 - REG:win.ini: load=C:\WINDOWS\system32\mljgg.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvdaj.dll,startup
O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [lsass] C:\WINDOWS\lsass.exe
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\printer.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\system32\spoolvs.exe
O4 - Startup: findfast.exe
O4 - Global Startup: autorun.exe
O4 - Global Startup: msn_0712_upd292315.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5195/mcfscan.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
Bij voorbaat dank..
MvG Mister No Style
die zegt dat mijn pc is geinfecteerd en dat ik iets moet klikken om
het te downloaden.. helaas is dit er net opgekomen nadat de virusscanner
verwijderd is.. nu kan ik niets meer installeren wat met een virusscanner te maken heeft... hier meteen mij hijackthis log.
Logfile of HijackThis v1.99.1
Scan saved at 20:37:21, on 30-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\CTFMON.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\NewsLeecher\newsLeecher.exe
C:\Program Files\NewsLeecher\newsLeecher.exe
C:\WINDOWS\avp.exe
C:\WINDOWS\mgrs.exe
C:\DOCUME~1\ELISE&~1\LOCALS~1\Temp\1632.exe
C:\DOCUME~1\ELISE&~1\LOCALS~1\Temp\sysserver.exe
C:\DOCUME~1\ELISE&~1\LOCALS~1\Temp\hostsys.exe
C:\WINDOWS\lsass.exe
C:\DOCUME~1\ELISE&~1\LOCALS~1\Temp\serverhost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Elise & Kieran\Application Data\printer.exe
C:\DOCUME~1\ELISE&~1\LOCALS~1\Temp\powerserver.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\shell.exe
F3 - REG:win.ini: load=C:\WINDOWS\system32\mljgg.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvdaj.dll,startup
O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [lsass] C:\WINDOWS\lsass.exe
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\printer.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\system32\spoolvs.exe
O4 - Startup: findfast.exe
O4 - Global Startup: autorun.exe
O4 - Global Startup: msn_0712_upd292315.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5195/mcfscan.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
Bij voorbaat dank..
MvG Mister No Style
Comment