Op mijn pc heb ik sinds enkele dagen erg veel last van spyware en virussen. En met geen mogelijkheid krijg ik deze eraf. hierbij doe ik even een logfile van hijackthis. Op enkele websites wel de virusomschrijving gevonden, maar niet hoe te verwijderen. Dit virus blokkeert al mijn virusscans en zonealarm suite.
Logfile of HijackThis v1.99.1
Scan saved at 1:16:23, on 6-7-2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\sucker.exe
C:\WINDOWS\System32\sucker.exe
C:\PROGRA~1\NORTON~1\PASSWO~1\AcctMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\ZoneLabs\vsmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\WINDOWS\System32\algs.exe
C:\WINDOWS\System32\spooIsv.exe
C:\Documents and Settings\Bibi Aartsen\Bureaublad\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [CleanUp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\20067601859_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINDOWS\System32\algs.exe
O4 - HKLM\..\Run: [Windows MS Update 32] sucker.exe
O4 - HKLM\..\Run: [Windows Explorer] C:\WINDOWS\System32\explorer.exe
O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINDOWS\System32\csrs.exe
O4 - HKLM\..\Run: [AcctMgr] C:\PROGRA~1\NORTON~1\PASSWO~1\AcctMgr.exe /startup
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\20067601847_mcinfo.exe /insfin
O4 - HKLM\..\Run: [Spooler SubSystem App] C:\WINDOWS\System32\spooIsv.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]hdywrpucgw^tkfp40inkrwksz_] c:\windows\system32\_zskwrkni04pfkt^wgcuprwydh].exe
O4 - HKLM\..\RunServices: [Windows MS Update 32] sucker.exe
O4 - HKLM\..\RunOnce: [Windows MS Update 32] sucker.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O16 - DPF: {04B6182D-FB75-11D4-90D2-0000B4948C7C} (cre8tiv 3Di ATL Control (Internet)) - http://www.quick-step.com/distribution/cre8tiv3dix.cab
O16 - DPF: {4C0942C1-C405-4805-B3B6-EA16F2DDD1BD} (innova-Panorama-Viewer Object) - http://www.innova-webplan...og/HOL/rundum.7.0.1.1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.c...eb_site.cab?1123436101393
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.c...eb_site.cab?1123436086181
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendm.../win32/activex/hcImpl.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://cache.hyves.nl/statics/Aurigma/ImageUploader.cab
O16 - DPF: {A92E0798-BFA4-4FEE-BB48-8E2C69B2B0C5} (PageDive Control) - http://www.pagedive.com/pagedive5700/PageDive5.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.co...an/2,1,0,4795/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4F02FB9C-A56E-47C9-AC02-E8281D3763AD}: NameServer = 195.18.114.5,4.2.2.2
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: interceptor.dll
O20 - Winlogon Notify: Control Panel - C:\WINDOWS\system32\k2pm0c71ef.dll (file missing)
O20 - Winlogon Notify: H323TSP - C:\WINDOWS\system32\o448lehu1h48.dll (file missing)
O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\n4r2le9o1h.dll (file missing)
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\fp6603jse.dll (file missing)
O20 - Winlogon Notify: RunOnceEx - C:\WINDOWS\system32\mvrul9991.dll (file missing)
O20 - Winlogon Notify: SharedDLLs - C:\WINDOWS\system32\wc2help.dll (file missing)
O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\fp6603jse.dll (file missing)
O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\system32\mvpol9731.dll (file missing)
O20 - Winlogon Notify: StillImage - C:\WINDOWS\system32\fp6603jse.dll (file missing)
O20 - Winlogon Notify: Syncmgr - C:\WINDOWS\system32\k2pm0c71ef.dll (file missing)
O20 - Winlogon Notify: Themes - C:\WINDOWS\system32\o448lehu1h48.dll (file missing)
O20 - Winlogon Notify: Unimodem - C:\WINDOWS\system32\k2pm0c71ef.dll (file missing)
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\mvpol9731.dll (file missing)
O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\mvrul9991.dll (file missing)
O20 - Winlogon Notify: WindowsUpdate - C:\WINDOWS\system32\k2pm0c71ef.dll (file missing)
O20 - Winlogon Notify: WinOpts - C:\WINDOWS\system32\mvpol9731.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\System32\ZoneLabs\isafe.exe
O23 - Service: MicroSoft Media Tools - Unknown owner - C:\WINDOWS\MSmedia.exe
O23 - Service: Creative NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Windows Protected Content Restoration Service (ProtectedContentSvc) - Unknown owner - C:\WINDOWS\etc\services.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Heeft iemand een oplossing voor mij waardoor ik deze rotzooi van mijn pc kan verwijderen?
alvast bedankt
Logfile of HijackThis v1.99.1
Scan saved at 1:16:23, on 6-7-2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\sucker.exe
C:\WINDOWS\System32\sucker.exe
C:\PROGRA~1\NORTON~1\PASSWO~1\AcctMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\ZoneLabs\vsmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\WINDOWS\System32\algs.exe
C:\WINDOWS\System32\spooIsv.exe
C:\Documents and Settings\Bibi Aartsen\Bureaublad\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [CleanUp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\20067601859_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINDOWS\System32\algs.exe
O4 - HKLM\..\Run: [Windows MS Update 32] sucker.exe
O4 - HKLM\..\Run: [Windows Explorer] C:\WINDOWS\System32\explorer.exe
O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINDOWS\System32\csrs.exe
O4 - HKLM\..\Run: [AcctMgr] C:\PROGRA~1\NORTON~1\PASSWO~1\AcctMgr.exe /startup
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\20067601847_mcinfo.exe /insfin
O4 - HKLM\..\Run: [Spooler SubSystem App] C:\WINDOWS\System32\spooIsv.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]hdywrpucgw^tkfp40inkrwksz_] c:\windows\system32\_zskwrkni04pfkt^wgcuprwydh].exe
O4 - HKLM\..\RunServices: [Windows MS Update 32] sucker.exe
O4 - HKLM\..\RunOnce: [Windows MS Update 32] sucker.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O16 - DPF: {04B6182D-FB75-11D4-90D2-0000B4948C7C} (cre8tiv 3Di ATL Control (Internet)) - http://www.quick-step.com/distribution/cre8tiv3dix.cab
O16 - DPF: {4C0942C1-C405-4805-B3B6-EA16F2DDD1BD} (innova-Panorama-Viewer Object) - http://www.innova-webplan...og/HOL/rundum.7.0.1.1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.c...eb_site.cab?1123436101393
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.c...eb_site.cab?1123436086181
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendm.../win32/activex/hcImpl.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://cache.hyves.nl/statics/Aurigma/ImageUploader.cab
O16 - DPF: {A92E0798-BFA4-4FEE-BB48-8E2C69B2B0C5} (PageDive Control) - http://www.pagedive.com/pagedive5700/PageDive5.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.co...an/2,1,0,4795/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4F02FB9C-A56E-47C9-AC02-E8281D3763AD}: NameServer = 195.18.114.5,4.2.2.2
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: interceptor.dll
O20 - Winlogon Notify: Control Panel - C:\WINDOWS\system32\k2pm0c71ef.dll (file missing)
O20 - Winlogon Notify: H323TSP - C:\WINDOWS\system32\o448lehu1h48.dll (file missing)
O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\n4r2le9o1h.dll (file missing)
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\fp6603jse.dll (file missing)
O20 - Winlogon Notify: RunOnceEx - C:\WINDOWS\system32\mvrul9991.dll (file missing)
O20 - Winlogon Notify: SharedDLLs - C:\WINDOWS\system32\wc2help.dll (file missing)
O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\fp6603jse.dll (file missing)
O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\system32\mvpol9731.dll (file missing)
O20 - Winlogon Notify: StillImage - C:\WINDOWS\system32\fp6603jse.dll (file missing)
O20 - Winlogon Notify: Syncmgr - C:\WINDOWS\system32\k2pm0c71ef.dll (file missing)
O20 - Winlogon Notify: Themes - C:\WINDOWS\system32\o448lehu1h48.dll (file missing)
O20 - Winlogon Notify: Unimodem - C:\WINDOWS\system32\k2pm0c71ef.dll (file missing)
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\mvpol9731.dll (file missing)
O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\mvrul9991.dll (file missing)
O20 - Winlogon Notify: WindowsUpdate - C:\WINDOWS\system32\k2pm0c71ef.dll (file missing)
O20 - Winlogon Notify: WinOpts - C:\WINDOWS\system32\mvpol9731.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\System32\ZoneLabs\isafe.exe
O23 - Service: MicroSoft Media Tools - Unknown owner - C:\WINDOWS\MSmedia.exe
O23 - Service: Creative NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Windows Protected Content Restoration Service (ProtectedContentSvc) - Unknown owner - C:\WINDOWS\etc\services.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Heeft iemand een oplossing voor mij waardoor ik deze rotzooi van mijn pc kan verwijderen?
alvast bedankt