- Ik wou een film kijken op het Internet, & op zo'n bepaald site moest ik Activerix ofzo downloaden en daar klikte is dus op.
Sindsdien krijg ik steeds een pop-up die zegt;
"Your system is infected with dangerous virus!
Note: Strongly recommend to install antispyware Proggrame to clean your sysem and avoid total crash of your computer !
Click ok to download the antispyware (Recommend)."
En ook als ik dan bij google kom staat er zo'n kadertje die zegt dat ik gehijacked ben en daardoor kon ik niet googlen en telkens op sexsites kom
Ik ben er achter gekomen dat het om Trojan.Win32.Obfuscated.gx gaat.
Hier heb ik mijn HijackThis Log
[hijack][url=http://www.niele.nl/hijackthis/index.php]
Logfile of HijackThis v1.99.1
scan saved at 18:47:30, on 26-4-2008
platform: windows xp sp2 (winnt 5.01.2600)
msie: internet explorer v6.00 sp2 (6.00.2900.2180)
browser: Internet Explorer 6.0
ColorCoder Build: 4136
Running Processes:
c:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\program files\common files\symantec shared\ccsvchst.exe
c:\program files\common files\symantec shared\appcore\appsvc32.exe
c:\windows\system32\spoolsv.exe
c:\windows\explorer.exe
c:\windows\system32\hkcmd.exe
c:\windows\system32\igfxpers.exe
c:\program files\common files\symantec shared\ccapp.exe
c:\program files\java\j2re1.4.2_03\bin\jusched.exe
c:\program files\itunes\ituneshelper.exe
c:\windows\system32\ctfmon.exe
c:\program files\windows live\messenger\msnmsgr.exe
c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
c:\program files\bonjour\mdnsresponder.exe
c:\program files\symantec\liveupdate\aluschedulersvc.exe
c:\program files\ipod\bin\ipodservice.exe
c:\windows\system32\svchost.exe
c:\windows\system32\wuauclt.exe
c:\program files\spybot - search & destroy\spybotsd.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\wuauclt.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\common files\microsoft shared\windows live\wlloginproxy.exe
c:\documents and settings\aishah\mijn documenten\nieuwe map\hijackthis.exe
R1 - hkcu\software\microsoft\internet explorer\main,search bar = http://search.msn.nl/sphome.aspx
R0 - hkcu\software\microsoft\internet explorer\main,start page = http://www.nu.nl/
R1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = *.local
R0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername = koppelingen
O2 - bho: adobe pdf reader help bij koppelingen - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll
O2 - bho: (no name) - {1e8a6170-7264-4d0f-beae-d42a53123c75} - c:\program files\common files\symantec shared\coshared\browser\1.0\nppbho.dll
O2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
O2 - bho: windows live aanmelden - help - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
O2 - bho: video - {f856bb9e-855b-498d-883e-3509c550a031} - c:\windows\wsol.dll
O3 - toolbar: norton-werkbalk weergeven - {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.0\uibho.dll
O4 - HKLM\..\Run: [igfxtray] c:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] c:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] c:\windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ccapp] "c:\program files\common files\symantec shared\ccapp.exe"
O4 - HKLM\..\Run: [oscheck] "c:\program files\norton internet security\oscheck.exe"
O4 - HKLM\..\Run: [sunjavaupdatesched] c:\program files\java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [quicktime task] "c:\program files\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ituneshelper] "c:\program files\itunes\ituneshelper.exe"
O4 - HKLM\..\Run: [adobe reader speed launcher] "c:\program files\adobe\reader 8.0\reader\reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
O8 - extra context menu item: e&xporteren naar microsoft excel - res://c:\progra~1\micros~2\office12\excel.exe/3000
O9 - extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - extra 'tools' menuitem: sun java console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - extra button: messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
O9 - extra 'tools' menuitem: windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
O10 - unknown file in winsock lsp: c:\program files\bonjour\mdnsnsp.dll
O16 - dpf: {17492023-c23a-453e-a040-c7c580bbf700} (windows genuine advantage validation tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - protocol: livecall - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\window~4\messen~1\msgrap~1.dll
O18 - protocol: msnim - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\window~4\messen~1\msgrap~1.dll
O20 - winlogon notify: gotoassist - c:\program files\citrix\gotoassist\480\g2awinlogon.dll
O20 - winlogon notify: igfxcui - c:\windows\system32\igfxdev.dll
O23 - Service: apple mobile device - apple, inc. - c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
O23 - Service: bonjour-service (bonjour service) - apple inc. - c:\program files\bonjour\mdnsresponder.exe
O23 - Service: symantec event manager (ccevtmgr) - unknown owner - c:\program files\common files\symantec shared\ccsvchst.exe" /h cccommon (file missing)
O23 - Service: symantec settings manager (ccsetmgr) - unknown owner - c:\program files\common files\symantec shared\ccsvchst.exe" /h cccommon (file missing)
O23 - Service: symantec lic netconnect service (cltnetcnservice) - unknown owner - c:\program files\common files\symantec shared\ccsvchst.exe" /h cccommon (file missing)
O23 - Service: com host (comhost) - symantec corporation - c:\program files\common files\symantec shared\vascanner\comhost.exe
O23 - Service: gotoassist - unknown owner - c:\program files\citrix\gotoassist\480\g2aservice.exe" start=service (file missing)
O23 - Service: ipod-service (ipod service) - apple inc. - c:\program files\ipod\bin\ipodservice.exe
O23 - Service: wachtwoordvalidatie voor symantec is (ispwdsvc) - symantec corporation - c:\program files\norton internet security\ispwdsvc.exe
O23 - Service: liveupdate - symantec corporation - c:\progra~1\symantec\liveup~1\lucoms~1.exe
O23 - Service: planner voor automatische liveupdate - symantec corporation - c:\program files\symantec\liveupdate\aluschedulersvc.exe
O23 - Service: symantec core lc - symantec corporation - c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe
O23 - Service: symantec appcore service (symappcore) - symantec corporation - c:\program files\common files\symantec shared\appcore\appsvc32.exe[/hijack]
Sindsdien krijg ik steeds een pop-up die zegt;
"Your system is infected with dangerous virus!
Note: Strongly recommend to install antispyware Proggrame to clean your sysem and avoid total crash of your computer !
Click ok to download the antispyware (Recommend)."
En ook als ik dan bij google kom staat er zo'n kadertje die zegt dat ik gehijacked ben en daardoor kon ik niet googlen en telkens op sexsites kom
Ik ben er achter gekomen dat het om Trojan.Win32.Obfuscated.gx gaat.
Hier heb ik mijn HijackThis Log
[hijack][url=http://www.niele.nl/hijackthis/index.php]

Logfile of HijackThis v1.99.1
scan saved at 18:47:30, on 26-4-2008
platform: windows xp sp2 (winnt 5.01.2600)
msie: internet explorer v6.00 sp2 (6.00.2900.2180)
browser: Internet Explorer 6.0
ColorCoder Build: 4136
Running Processes:
c:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\program files\common files\symantec shared\ccsvchst.exe
c:\program files\common files\symantec shared\appcore\appsvc32.exe
c:\windows\system32\spoolsv.exe
c:\windows\explorer.exe
c:\windows\system32\hkcmd.exe
c:\windows\system32\igfxpers.exe
c:\program files\common files\symantec shared\ccapp.exe
c:\program files\java\j2re1.4.2_03\bin\jusched.exe
c:\program files\itunes\ituneshelper.exe
c:\windows\system32\ctfmon.exe
c:\program files\windows live\messenger\msnmsgr.exe
c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
c:\program files\bonjour\mdnsresponder.exe
c:\program files\symantec\liveupdate\aluschedulersvc.exe
c:\program files\ipod\bin\ipodservice.exe
c:\windows\system32\svchost.exe
c:\windows\system32\wuauclt.exe
c:\program files\spybot - search & destroy\spybotsd.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\wuauclt.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\common files\microsoft shared\windows live\wlloginproxy.exe
c:\documents and settings\aishah\mijn documenten\nieuwe map\hijackthis.exe
R1 - hkcu\software\microsoft\internet explorer\main,search bar = http://search.msn.nl/sphome.aspx
R0 - hkcu\software\microsoft\internet explorer\main,start page = http://www.nu.nl/
R1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = *.local
R0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername = koppelingen
O2 - bho: adobe pdf reader help bij koppelingen - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll
O2 - bho: (no name) - {1e8a6170-7264-4d0f-beae-d42a53123c75} - c:\program files\common files\symantec shared\coshared\browser\1.0\nppbho.dll
O2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
O2 - bho: windows live aanmelden - help - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
O2 - bho: video - {f856bb9e-855b-498d-883e-3509c550a031} - c:\windows\wsol.dll
O3 - toolbar: norton-werkbalk weergeven - {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.0\uibho.dll
O4 - HKLM\..\Run: [igfxtray] c:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] c:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] c:\windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ccapp] "c:\program files\common files\symantec shared\ccapp.exe"
O4 - HKLM\..\Run: [oscheck] "c:\program files\norton internet security\oscheck.exe"
O4 - HKLM\..\Run: [sunjavaupdatesched] c:\program files\java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [quicktime task] "c:\program files\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ituneshelper] "c:\program files\itunes\ituneshelper.exe"
O4 - HKLM\..\Run: [adobe reader speed launcher] "c:\program files\adobe\reader 8.0\reader\reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
O8 - extra context menu item: e&xporteren naar microsoft excel - res://c:\progra~1\micros~2\office12\excel.exe/3000
O9 - extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - extra 'tools' menuitem: sun java console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - extra button: messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
O9 - extra 'tools' menuitem: windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
O10 - unknown file in winsock lsp: c:\program files\bonjour\mdnsnsp.dll
O16 - dpf: {17492023-c23a-453e-a040-c7c580bbf700} (windows genuine advantage validation tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - protocol: livecall - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\window~4\messen~1\msgrap~1.dll
O18 - protocol: msnim - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\window~4\messen~1\msgrap~1.dll
O20 - winlogon notify: gotoassist - c:\program files\citrix\gotoassist\480\g2awinlogon.dll
O20 - winlogon notify: igfxcui - c:\windows\system32\igfxdev.dll
O23 - Service: apple mobile device - apple, inc. - c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
O23 - Service: bonjour-service (bonjour service) - apple inc. - c:\program files\bonjour\mdnsresponder.exe
O23 - Service: symantec event manager (ccevtmgr) - unknown owner - c:\program files\common files\symantec shared\ccsvchst.exe" /h cccommon (file missing)
O23 - Service: symantec settings manager (ccsetmgr) - unknown owner - c:\program files\common files\symantec shared\ccsvchst.exe" /h cccommon (file missing)
O23 - Service: symantec lic netconnect service (cltnetcnservice) - unknown owner - c:\program files\common files\symantec shared\ccsvchst.exe" /h cccommon (file missing)
O23 - Service: com host (comhost) - symantec corporation - c:\program files\common files\symantec shared\vascanner\comhost.exe
O23 - Service: gotoassist - unknown owner - c:\program files\citrix\gotoassist\480\g2aservice.exe" start=service (file missing)
O23 - Service: ipod-service (ipod service) - apple inc. - c:\program files\ipod\bin\ipodservice.exe
O23 - Service: wachtwoordvalidatie voor symantec is (ispwdsvc) - symantec corporation - c:\program files\norton internet security\ispwdsvc.exe
O23 - Service: liveupdate - symantec corporation - c:\progra~1\symantec\liveup~1\lucoms~1.exe
O23 - Service: planner voor automatische liveupdate - symantec corporation - c:\program files\symantec\liveupdate\aluschedulersvc.exe
O23 - Service: symantec core lc - symantec corporation - c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe
O23 - Service: symantec appcore service (symappcore) - symantec corporation - c:\program files\common files\symantec shared\appcore\appsvc32.exe[/hijack]
Comment