voor de HTPC .
VundoFix V6.4.2
Checking Java version...
Sun Java not detected
Scan started at 20:14:42 7-6-2007
Listing files found while scanning....
C:\WINDOWS\system32\byxywwt.dll
C:\WINDOWS\system32\daktcyqu.ini
C:\WINDOWS\system32\iifdaax.dll
C:\WINDOWS\system32\iiffcyw.dll
C:\WINDOWS\system32\khfgfcd.dll
C:\WINDOWS\system32\ljjgfcb.dll
C:\WINDOWS\system32\lmllm.bak1
C:\WINDOWS\system32\lmllm.bak2
C:\WINDOWS\system32\lmllm.ini
C:\WINDOWS\system32\mljhijk.dll
C:\WINDOWS\system32\mllml.dll
C:\WINDOWS\system32\ssqqqrs.dll
C:\WINDOWS\system32\ssqronk.dll
C:\WINDOWS\system32\uqyctkad.dll
C:\WINDOWS\system32\urqqnnl.dll
C:\WINDOWS\system32\wvusrqr.dll
C:\WINDOWS\system32\wvutrop.dll
C:\WINDOWS\system32\wvuvuuv.dll
C:\WINDOWS\system32\yaywurs.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\byxywwt.dll
C:\WINDOWS\system32\byxywwt.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\daktcyqu.ini
C:\WINDOWS\system32\daktcyqu.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\iifdaax.dll
C:\WINDOWS\system32\iifdaax.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\iiffcyw.dll
C:\WINDOWS\system32\iiffcyw.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\khfgfcd.dll
C:\WINDOWS\system32\khfgfcd.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ljjgfcb.dll
C:\WINDOWS\system32\ljjgfcb.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\lmllm.bak1
C:\WINDOWS\system32\lmllm.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\lmllm.bak2
C:\WINDOWS\system32\lmllm.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\lmllm.ini
C:\WINDOWS\system32\lmllm.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\mljhijk.dll
C:\WINDOWS\system32\mljhijk.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\mllml.dll
C:\WINDOWS\system32\mllml.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ssqqqrs.dll
C:\WINDOWS\system32\ssqqqrs.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ssqronk.dll
C:\WINDOWS\system32\ssqronk.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\uqyctkad.dll
C:\WINDOWS\system32\uqyctkad.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\urqqnnl.dll
C:\WINDOWS\system32\urqqnnl.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\wvusrqr.dll
C:\WINDOWS\system32\wvusrqr.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\wvutrop.dll
C:\WINDOWS\system32\wvutrop.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\wvuvuuv.dll
C:\WINDOWS\system32\wvuvuuv.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\yaywurs.dll
C:\WINDOWS\system32\yaywurs.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\mljhijk.dll
C:\WINDOWS\system32\mljhijk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
VundoFix V6.4.2
Checking Java version...
Sun Java not detected
Scan started at 20:27:13 7-6-2007
Listing files found while scanning....
C:\WINDOWS\system32\mljhijk.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\mljhijk.dll
C:\WINDOWS\system32\mljhijk.dll Has been deleted!
Performing Repairs to the registry.
Done!
Logfile of HijackThis v1.99.1
Scan saved at 20:43:35, on 7-6-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\iexplore32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Program Files\TeamViewer\TeamViewer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\DynGate\DynGate.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\BART~1.MED\LOCALS~1\Temp\Rar$EX00.094\ HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TeamViewer] "C:\Program Files\TeamViewer\TeamViewer.exe" -servicehelper
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [InternetExplorer32] C:\WINDOWS\system32\iexplore32.exe
O4 - HKLM\..\Run: [system] C:\WINDOWS\system32\system.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\uqyctkad.dll",realset
O4 - HKLM\..\Run: [j3231039] rundll32 C:\WINDOWS\system32\j3231039.dll sook
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunServices: [InternetExplorer32] C:\WINDOWS\system32\iexplore32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Microsoft System Management - Unknown owner - C:\WINDOWS\system32\system.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: TeamViewer Remote Control (TeamViewer) - Unknown owner - C:\Program Files\TeamViewer\TeamViewer.exe" -service (file missing)
DrWeb :
awtsr.dll;c:\windows\system32;Trojan.Virtumod;Will be cured after reboot.;
lmfjaphi.dll;c:\windows\system32;Trojan.Virtumod;W ill be cured after reboot.;
PowerISO37.exe;C:\Documents and Settings\All Users.WINDOWS\Documenten;Trojan.MulDrop.5980;Delet ed.;
lo1[1];C:\Documents and Settings\Bart.MEDIACENTER\Local Settings\Temporary Internet Files\Content.IE5\59729YNL;Trojan.Virtumod;Deleted .;
lo1[1];C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\RE6ZWR0D;Trojan.Virtumod;Deleted .;
A0016444.dll;C:\System Volume Information\_restore{FEED4DFF-D203-45BB-AEC3-F923DDADF58B}\RP45;Trojan.Virtumod;Deleted.;
A0016447.dll;C:\System Volume Information\_restore{FEED4DFF-D203-45BB-AEC3-F923DDADF58B}\RP45;Trojan.Virtumod;Deleted.;
A0016485.exe;C:\System Volume Information\_restore{FEED4DFF-D203-45BB-AEC3-F923DDADF58B}\RP45;Trojan.MulDrop.5980;Deleted.;
mllml.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Deleted.;
uqyctkad.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Deleted.;
awtsr.dll;C:\WINDOWS\system32;Trojan.Virtumod;Will be cured after reboot.;
knvyyihp.exe;C:\WINDOWS\system32;Trojan.Click.2485 ;Deleted.;
lmfjaphi.dll;C:\WINDOWS\system32;Trojan.Virtumod;W ill be cured after reboot.;
Favorieten/bladwijzers