Weergegeven resultaten: 1 t/m 3 van 3
  1. #1
    Beginner  
    Geregistreerd
    11 July 2008
    Berichten
    2
    Bedankjes
    0
    Bedankt
    0 keer in 0 posts

    Uitroep worm.win32.netsky en verdachte "internet attack" meldingen

    Hallo,

    Mijn pc geeft aan dat ik geinfecteerd ben met worm.win32.netsky (via internet explorer). Ik krijg constant pop-ups in de vorm van ' windows has detected an internet attack attempt....', 'warning: possible spyware or adware infection click here to scan your computer for spyware and adware'. Als startpagina van internet explorer krijg ik telkens uclearnet.com

    Mijn Norton geeft wel aan wanneer de infectie optreedt - bij het openen van internet explorer bv - maar toch lukt het me niet om ze definitief te verwijderen.

    Wat moet ik doen ??

  2. #2
    Minatica Moderator   Obsessed's schermafbeelding
    Geregistreerd
    14 June 2005
    Locatie
    Hagenland
    Berichten
    3.197
    Bedankjes
    15.128
    Bedankt
    15.831 keer in 6.991 posts
    HIER vind je de removal tool van Symantec.

    Anders eens een HijachThis logje plaatsen.
    * NIL VOLENTIBUS ARDUUM *

  3. #3
    Beginner  
    Geregistreerd
    11 July 2008
    Berichten
    2
    Bedankjes
    0
    Bedankt
    0 keer in 0 posts
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 23:32: VIRUS ALERT!, on 11/07/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\HiJackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sqrsoft.com.ar/en/donate.html
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost;*.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O1 - Hosts: 62.75.224.159 www.cms1.net
    O1 - Hosts: 62.75.224.159 www.cms2.net
    O1 - Hosts: 62.75.224.159 www.cms1.net
    O1 - Hosts: 62.75.224.159 www.cms2.net
    O1 - Hosts: 62.75.224.159 bns1.net
    O1 - Hosts: 62.75.224.159 bns2.net
    O1 - Hosts: 62.75.224.159 cms1.net
    O1 - Hosts: 62.75.224.159 cms2.net
    O1 - Hosts: 62.75.224.159 bns1.net
    O1 - Hosts: 62.75.224.159 bns2.net
    O1 - Hosts: 62.75.224.159 cms1.net
    O1 - Hosts: 62.75.224.159 cms2.net
    O1 - Hosts: 62.75.224.159 jbeet.cjt1.net
    O1 - Hosts: 62.75.224.159 jbigpops.cjt1.net
    O1 - Hosts: 62.75.224.159 jbouncetek.cjt1.net
    O1 - Hosts: 62.75.224.159 jbravenet.cjt1.net
    O1 - Hosts: 62.75.224.159 jcdcover.cjt1.net
    O1 - Hosts: 62.75.224.159 jclickspring.cjt1.net
    O1 - Hosts: 62.75.224.159 jcollegehumor.cjt1.net
    O1 - Hosts: 62.75.224.159 jdownloadacc.cjt1.net
    O1 - Hosts: 62.75.224.159 jedonkey.cjt1.net
    O1 - Hosts: 62.75.224.159 jeuniverse.cjt1.net
    O1 - Hosts: 62.75.224.159 jhot.cjt1.net
    O1 - Hosts: 62.75.224.159 jicmedia.cjt1.net
    O1 - Hosts: 62.75.224.159 jicq.cjt1.net
    O1 - Hosts: 62.75.224.159 jieplugin.cjt1.net
    O1 - Hosts: 62.75.224.159 jinternetoptimizer.cjt1.net
    O1 - Hosts: 62.75.224.159 jmediabuy1.cjt1.net
    O1 - Hosts: 62.75.224.159 jmediabuyad.cjt1.net
    O1 - Hosts: 62.75.224.159 jmindset.cjt1.net
    O1 - Hosts: 62.75.224.159 jmindsettest.cjt1.net
    O1 - Hosts: 62.75.224.159 jnictech.cjt1.net
    O1 - Hosts: 62.75.224.159 jnova.cjt1.net
    O1 - Hosts: 62.75.224.159 jpiolet.cjt1.net
    O1 - Hosts: 62.75.224.159 jsanboxer.cjt1.net
    O1 - Hosts: 62.75.224.159 jsercee.cjt1.net
    O1 - Hosts: 62.75.224.159 jthedelfin.cjt1.net
    O1 - Hosts: 62.75.224.159 jwarezp2p.cjt1.net
    O1 - Hosts: 62.75.224.159 jwildmedia.cjt1.net
    O1 - Hosts: 62.75.224.159 mediabuy-nic.cjt1.net
    O1 - Hosts: 62.75.224.159 www.m7z.net
    O1 - Hosts: 62.75.224.159 m7z.net
    O1 - Hosts: 62.75.224.159 jcms.cydoor.com
    O1 - Hosts: 62.75.224.159 cydoor.com
    O1 - Hosts: 62.75.224.159 www.cydoor.com
    O1 - Hosts: 62.75.224.159 jnova.cjt1.net
    O1 - Hosts: 62.75.224.159 jcontent.bns1.m7z.net
    O1 - Hosts: 62.75.224.159 j.2004CMS.com
    O1 - Hosts: 62.75.224.159 2004CMS.com
    O1 - Hosts: 62.75.224.159 bns1.m7z.net
    O1 - Hosts: 62.75.224.159 jcontent.bns1.net
    O1 - Hosts: 62.75.224.159 jbns2.cydoor.com
    O1 - Hosts: 62.75.224.159 ct.cydoor.com
    O1 - Hosts: 62.75.224.159 redirect.cydoor.com
    O1 - Hosts: 62.75.224.159 client.exeem.com
    O1 - Hosts: 62.75.224.159 exeem.com
    O1 - Hosts: 62.75.224.159 www.exeem.com
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\s wg.dll
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: nqgpedlr - {80123684-A222-4009-8220-A867294D6DE8} - C:\WINDOWS\nqgpedlr.dll
    O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System, DisableRegedit=1
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Easy-WebPrint Afdrukken - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
    O8 - Extra context menu item: Easy-WebPrint Afdrukvoorbeeld - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Toevoegen aan afdruklijst - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint Versneld afdrukken - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {A92E0798-BFA4-4FEE-BB48-8E2C69B2B0C5} (PageDive Control) - http://www.pagedive.com/pagedive5811/PageDive5.cab
    O21 - SSODL: axrfgvek - {B79ECF5E-7D7C-47E0-91BD-782FA756069A} - C:\WINDOWS\axrfgvek.dll (file missing)
    O21 - SSODL: okmdepgb - {D28E2421-BFE5-4B7A-90E6-E3FB720712E7} - C:\WINDOWS\okmdepgb.dll
    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762# # (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

    --
    End of file - 11524 bytes

Discussie informatie

Users Browsing this Thread

Momenteel bekijken 1 gebruikers deze discussie. (0 leden en 1 gasten)

Soortgelijke discussies

  1. naam van kind "voor" foto ipv "erachter
    Door creature2you in forum Grafisch algemeen
    Reacties: 15
    Laatste bericht: 3 April 2006, 18:15
  2. Internet explorer "extra"
    Door 2B's in forum Internet
    Reacties: 2
    Laatste bericht: 4 March 2006, 09:52
  3. Creative Muvo "tx Se" Of "v200" 1gb
    Door vampie in forum PC-randapparatuur en andere PC-hardware
    Reacties: 0
    Laatste bericht: 3 December 2005, 16:25
  4. "Neovo F417BS 17"" TFT zw/zil (12ms) - 3 j on-site - BESTE KOOP PC Magazine!"
    Door eventure in forum PC-randapparatuur en andere PC-hardware
    Reacties: 1
    Laatste bericht: 24 November 2005, 12:45

Favorieten/bladwijzers

Favorieten/bladwijzers

Regels voor berichten

  • Je mag geen nieuwe discussies starten
  • Je mag niet reageren op berichten
  • Je mag geen bijlagen versturen
  • Je mag niet je berichten bewerken
  •