Toon posts:

Verdacht bestand "ms spool.exe"

Pagina: 1
Acties:

Verwijderd

Topicstarter
Ik nam zojuist ff een kijkje in mijn task manager, en daar zag ik voor het eerst het bestand "ms spool32.exe" instaan, ik kende het niet, en vanwege de spatie erin vetrouw ik het ook niet helemaal. Toen zag ik in de windows root nog 2 andere files genaamd "ms spool32.dat" en "ms spool32k.dat", en toen keek ik zo in die files, en in de eerste dat file stond dit:
_AVPCC.EXE
_AVPM.EXE
AVP32.EXE
AVPCC.EXE
AVP.EXE
NAVAPW32.EXE
NAVW32.EXE
ICLOAD95.EXE
ICMON.EXE
ICSUPP95.EXE
ICLOADNT.EXE
ICSUPPNT.EXE
FRW.EXE
BLACKICE.EXE
BLACKD.EXE
WRCTRL.EXE
WRADMIN.EXE
WRCTRL.EXE
CLEANER3.EXE
PCFWALLICON.EXE
APLICA32.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFINET32.EXE
CFINET.EXE
TDS2-98.EXE
TDS2-NT.EXE
SAFEWEB.EXE
NVARCH16.EXE
MSSMMC32.EXE
PERSFW.EXE
LUALL.EXE
LUCOMSERVER.EXE
NAVW32.EXE
AVSYNMGR.EXE
TRJSCAN.EXE
DEFWATCH.EXE
RTVSCN95.EXE
VPC42.EXE
VPTRAY.EXE
PAVPROXY.EXE
APVXDWIN.EXE
AGENTSVR.EXE
FSAV.EXE
TASKMGR.EXE
DEFSCANGUI.EXE
SHEDAPP.EXE
AVGSERV9.EXE
CSS 1631.EXE
JAMMER.EXE
MONSYS32.EXE
AHNSD.EXE
MONSYSNT.EXE
CMGRDIAN.EXE
RULAUNCH.EXE
ALOGSERV.EXE
GBMENU.EXE
QSERVER.EXE
TAUMON.EXE
APVXDWIN.EXE
PAVPROXY.EXE
GBPOLL.EXE
VBCONS.EXE
VBCMSERV.EXE
PADMIN.EXE
NWTOOL16.EXE
NTVDM.EXE
CDP.EXE
GUARDDOG.EXE
AVGSERV9.EXE
OUTPOST.EXE
en in de tweede alles vanaf 14 december wat ik getypt heb!!!
Ik kan hem ook niet verwijderen omdat hij zegt dat het door windows beveiligd is ofzo. Erg vervelend!!! kan iemand mij hiermee helpen?

Misschien ook wel handig om te weten, ik heb Windows XP, met Norton Anti-Virus 2003 geinstalleerd.

[ Voor 5% gewijzigd door Verwijderd op 31-12-2002 09:05 ]


  • ajhaverkamp
  • Registratie: November 2001
  • Laatst online: 23:25

ajhaverkamp

gewoon Arjan

Waar zouden we zijn zonder Google:

http://securityresponse.s...ata/backdoor.assasin.html

Kostte wederom 5 seconden om te vinden...

This footer is intentionally left blank


  • blackd
  • Registratie: Februari 2001
  • Niet online
[google="ms spool32.exe"]
Ga dus maar snel virusscannen....

9000Wp o/w SolarEdge SE6K - Panasonic 5kW bi-bloc - gasloos sinds 17-7-2023


Verwijderd

Topicstarter
Dan moet je wel weten waarop je moet zoeken, bedankt! :)

edit:

Had de laatste nog niet gezien, sorry, was de "" ervoor en erachter vergeten.

[ Voor 50% gewijzigd door Verwijderd op 31-12-2002 09:09 ]


  • ajhaverkamp
  • Registratie: November 2001
  • Laatst online: 23:25

ajhaverkamp

gewoon Arjan

Verwijderd schreef op 31 december 2002 @ 09:06:
Dan moet je wel weten waarop je moet zoeken, bedankt! :)
Dit "ms spool32.exe" knippen en plakken naar Google was genoeg......

This footer is intentionally left blank


Verwijderd

Topicstarter
Norton Anti-Virus scant er gewoon overheen :? en ik kan hem nog steeds niet deleten :(

Verwijderd

verwijderen in het register:

Update to the latest virus definitions, run a full system scan, and delete all files that are detected as Backdoor.Assasin.
Delete the file C:\%Windows%\Ms spool32.dat

then go back to your registry and delete:

Delete the value Ms Spool32 & MS SPOOL32.EXE
from the registry key

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Delete the subkey key

HKEY_LOCAL_MACHINE\SOFTWARE\TVP,MGNEYU4

Run a full system scan.
If any files are detected as infected by Backdoor.Assasin, click Delete.
Using Windows Explorer, delete the file C:\%Windows%\Ms spool32.dat.

NOTE: %Windows% is a variable. You must delete the Ms Spool.dat file from the Windows folder, which is, by default, either C:\Windows or C:\Winnt. If Windows is installed to a different location on your computer, make the appropriate substitution.


To remove the value and subkey from the registry:
Click Start, and click Run. The Run dialog box appears.
Type regedit and then click OK. The Registry Editor opens.
Navigate to the following key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

In the right pane, delete the following value: Ms Spool32 & MS SPOOL32.EXE

Navigate to the following key:

HKEY_LOCAL_MACHINE\SOFTWARE

In the left pane, locate and delete the following subkey: TVP,MGNEYU4

Click Registry, and click Exit.
For more info on this and other trojans visit www.thepublicworks.com security section and link to simovits consulting, trojans by name and file.
hope this helps, all the best,
murve

zoals uiit de post van blackd al is af te leiden, wederom ben je zelf verantwoordelijk voor reg tweaks

  • blackd
  • Registratie: Februari 2001
  • Niet online
Verwijderd schreef op 31 December 2002 @ 09:22:
Norton Anti-Virus scant er gewoon overheen :? en ik kan hem nog steeds niet deleten :(

Hij is wel up to date neem ik aan? Lees anders wat removal instructies door.

9000Wp o/w SolarEdge SE6K - Panasonic 5kW bi-bloc - gasloos sinds 17-7-2023

Pagina: 1