Explorer start opnieuw en homepage verandert

  • hakan

    Hallo,

    Ik denk dat ik een hardnekkige virus heb.. Elke keer als ik mijn computer opnieuw start, verandert m'n homepage in dit: C:\secure32.html en de tekst die erbij is geschreven:

    Detected SPYware! System error #384

    __________________________________________________________________________

    Your IP address is 84.85.189.56. Using this address a remote computer has gained anaccess to your computer and probably is collecting the information about the sites you've visited and the files contained in the folder Temporary Internet Files. Attention! Ask for help or install the software for deleting secret information about the sites you visited.

    __________________________________________________________________________

    Your computer is full of evidences!

    ISP of transmission: PLANET

    Your IP address: 84.85.189.56

    They know you're using: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.40607; .NET CLR 1.1.4322)

    Your computer is: Windows XP

    Risk status for further investigation: VERY HIGH RISK

    To protect from the Spyware - click here

    To prevent information transmission - click here

    To delete the history of your activity, click here

    Ik weet dat dit een virus is, dus ik heb op niets geklikt wat er op die site stond.. en

    dit bestand C:\secure32.html heb ik al meerdere keren verwijderd uit C:\ , maar na een paar seconden komt ie automatisch terug…

    Maar een ernstigere probleem is dat Explorer ongeveer na 30 seconden ELKE keer afsluit en opnieuw start/laad.. Ik heb alle stappen van LEES DIT EERST gedaan..

    Dit is mijn HiJackThis loggie:

    Logfile of HijackThis v1.99.1

    Scan saved at 14:21:51, on 9-11-2005

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\AVPersonal\AVGUARD.EXE

    C:\WINDOWS\Microsoft.NET\Framework\v2.0.40607\aspnet_admin.exe

    C:\Program Files\AVPersonal\AVWUPSRV.EXE

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\AVPersonal\AVGNT.EXE

    C:\WINDOWS\System32\paytime.exe

    C:\WINDOWS\System32\scvhost.exe

    C:\WINDOWS\tool2.exe

    C:\windows\system32\mdms.exe

    C:\WINDOWS\System32\rtf32.exe

    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE

    C:\winstall.exe

    C:\WINDOWS\System32\paytime.exe

    C:\WINDOWS\tool2.exe

    C:\Program Files\SpywareGuard\sgmain.exe

    C:\Program Files\SpywareGuard\sgbhp.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\Program Files\Real\RealPlayer\RealPlay.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\WINDOWS\explorer.exe

    C:\Documents and Settings\Bilgic\Mijn documenten\Anti-Virus Actie\HiJack This\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    F2 - REG:system.ini: UserInit=userinit.exe

    O1 - Hosts: 127.0.0.5 n-glx.s-redirect.com

    O1 - Hosts: 127.0.0.5 x.full-tgp.net

    O1 - Hosts: 127.0.0.5 counter.sexmaniack.com

    O1 - Hosts: 127.0.0.5 autoescrowpay.com

    O1 - Hosts: 127.0.0.5 www.autoescrowpay.com

    O1 - Hosts: 127.0.0.5 www.awmdabest.com

    O1 - Hosts: 127.0.0.5 www.sexfiles.nu

    O1 - Hosts: 127.0.0.5 awmdabest.com

    O1 - Hosts: 127.0.0.5 sexfiles.nu

    O1 - Hosts: 127.0.0.5 allforadult.com

    O1 - Hosts: 127.0.0.5 www.allforadult.com

    O1 - Hosts: 127.0.0.5 www.iframe.biz

    O1 - Hosts: 127.0.0.5 iframe.biz

    O1 - Hosts: 127.0.0.5 www.newiframe.biz

    O1 - Hosts: 127.0.0.5 newiframe.biz

    O1 - Hosts: 127.0.0.5 www.vesbiz.biz

    O1 - Hosts: 127.0.0.5 vesbiz.biz

    O1 - Hosts: 127.0.0.5 www.pizdato.biz

    O1 - Hosts: 127.0.0.5 pizdato.biz

    O1 - Hosts: 127.0.0.5 www.awmcash.biz

    O1 - Hosts: 127.0.0.5 awmcash.biz

    O1 - Hosts: 127.0.0.5 buldog-stats.com

    O1 - Hosts: 127.0.0.5 www.buldog-stats.com

    O1 - Hosts: 127.0.0.5 fregat.drocherway.com

    O1 - Hosts: 127.0.0.5 slutmania.biz

    O1 - Hosts: 127.0.0.5 www.slutmania.biz

    O1 - Hosts: 127.0.0.5 toolbarpartner.com

    O1 - Hosts: 127.0.0.5 www.toolbarpartner.com

    O1 - Hosts: 127.0.0.5 www.megapornix.com

    O1 - Hosts: 127.0.0.5 megapornix.com

    O1 - Hosts: 127.0.0.5 www.sp2fucked.biz

    O1 - Hosts: 127.0.0.5 sp2fucked.biz

    O1 - Hosts: 127.0.0.5 greg-tut.com

    O1 - Hosts: 127.0.0.5 www.greg-tut.com

    O1 - Hosts: 127.0.0.5 nylonsexy.com

    O1 - Hosts: 127.0.0.5 www.nylonsexy.com

    O1 - Hosts: 127.0.0.5 vparivalka.com

    O1 - Hosts: 127.0.0.5 www.vparivalka.com

    O1 - Hosts: 127.0.0.5 iframeprofit.com

    O1 - Hosts: 127.0.0.5 www.iframeprofit.com

    O1 - Hosts: 127.0.0.5 topsearch10.com

    O1 - Hosts: 127.0.0.5 www.topsearch10.com

    O1 - Hosts: 127.0.0.5 statscash.biz

    O1 - Hosts: 127.0.0.5 www.statscash.biz

    O1 - Hosts: 127.0.0.5 vxiframe.biz

    O1 - Hosts: 127.0.0.5 www.vxiframe.biz

    O1 - Hosts: 127.0.0.5 crazy-toolbar.com

    O1 - Hosts: 127.0.0.5 www.crazy-toolbar.com

    O1 - Hosts: 127.0.0.5 topcash.biz

    O1 - Hosts: 127.0.0.5 www.topcash.biz

    O1 - Hosts: 127.0.0.5 loadcash.biz

    O1 - Hosts: 127.0.0.5 www.loadcash.biz

    O1 - Hosts: 127.0.0.5 txiframe.biz

    O1 - Hosts: 127.0.0.5 www.txiframe.biz

    O1 - Hosts: 127.0.0.5 procounter.biz

    O1 - Hosts: 127.0.0.5 www.procounter.biz

    O1 - Hosts: 127.0.0.5 advadmin.biz

    O1 - Hosts: 127.0.0.5 www.advadmin.biz

    O1 - Hosts: 127.0.0.5 trafficbest.net

    O1 - Hosts: 127.0.0.5 www.trafficbest.net

    O1 - Hosts: 127.0.0.5 besthvac.com

    O1 - Hosts: 127.0.0.5 www.besthvac.com

    O1 - Hosts: 127.0.0.5 traff4.com

    O1 - Hosts: 127.0.0.5 www.traff4.com

    O1 - Hosts: 127.0.0.5 ambush-script.com

    O1 - Hosts: 127.0.0.5 www.ambush-script.com

    O1 - Hosts: 127.0.0.5 beehappyy.biz

    O1 - Hosts: 127.0.0.5 www.beehappyy.biz

    O1 - Hosts: 127.0.0.5 tracktraff.cc

    O1 - Hosts: 127.0.0.5 www.tracktraff.cc

    O1 - Hosts: 127.0.0.5 allcount.net

    O1 - Hosts: 127.0.0.5 www.allcount.net

    O1 - Hosts: 127.0.0.5 onedayoffer.biz

    O1 - Hosts: 127.0.0.5 www.onedayoffer.biz

    O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O4 - HKLM\..\Run: “C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe” /icon

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: C:\Program Files\AVPersonal\AVGNT.EXE /min

    O4 - HKLM\..\Run: scvhost.exe

    O4 - HKLM\..\Run: C:\WINDOWS\System32\paytime.exe

    O4 - HKLM\..\Run: c:\windows\system32\mdms.exe

    O4 - HKLM\..\Run: rtf32.exe

    O4 - HKLM\..\RunServices: scvhost.exe

    O4 - HKCU\..\Run: “C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE”

    O4 - HKCU\..\Run: C:\winstall.exe

    O4 - HKCU\..\Run: C:\WINDOWS\System32\paytime.exe

    O4 - HKCU\..\Run: “C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00003.exe”

    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll

    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL

    O9 - Extra ‘Tools’ menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra ‘Tools’ menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)

    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab

    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab

    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll

    O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab

    O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab

    O16 - DPF: {33331111-1111-1111-1111-622221193458} - file://c:\ex.cab

    O16 - DPF: {43331111-1111-1111-1111-611111195622} - file://c:\ex.cab

    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23.hotmail.msn.com/resources/MsnPUpld.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131541720893

    O16 - DPF: {64311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab

    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

    O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab

    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab

    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab

    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab

    O17 - HKLM\System\CCS\Services\Tcpip\..\{FF39EFE6-AE7A-40E3-B660-4538026DBE45}: NameServer = 195.121.1.34 195.121.1.66

    O20 - Winlogon Notify: msctl32.dll - C:\WINDOWS\System32\msctl32.dll

    O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - (no file)

    O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE

    O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE

    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    Ik ben niet de enige die deze computer gebruikt, dus ik heb geen idee of de virus/spyware via welke site of proggie binnen is gekomen…

    alvast bedankt voor het lezen ;)

  • hakan

    PS, die homepage verandert alleen voor Internet Explorer, dus niet op Mozilla Firefox..

  • MANONNA

    Nu zie je gelijk dat Firefox een betere browser is ;)

    Schakel in taakbeheer de scvhost.exe uit.

    let op..dus NIET svchost.exe!

    Let op de lettervolgorde.

    Dat is trouwens een oudje?

    Heb je al eens online gescand?

  • hakan

    hmm, ik was die al ergens tegengekomen, maar ik dacht dat het svchost.exe was, dus had ik het niet verwijderd.. :| maar ik zal het nu doen :) en ik zit nu een online scan te doen..

    Scanning progress: 50% Elapsed time: 00:32:30

    File scanned: 10498 Number of infections: 9

    Maar ik zie geen svchost.exe in taakbeheer..

  • hakan

    ik bedoel scvchost.exe.. exuceer me:)

  • MANONNA

    Ja pas op dus he ;)

    Ik snap het niet..normaal ziet je antivirusscanner die wel..

    daarom dus ff online scannen…en hij ziet er al wat zie ik ;)

  • hakan

    Scanning progress: 71% Elapsed time: 00:38:40

    File scanned: 15167 Number of infections: 9

    Bij ad-aware heeft ie totaal ongeveer 110.000 bestanden gescand.. gaat ie nu ook 110.000 bestanden scannen? :| dan zal het meer dan 7 uur duren :|

  • MANONNA

    Zolang?

    Lijkt me stug:(

    Je kan op de site altijd aangecven WAT ie moet scannen he…je mappen met je eigen foto's kun je al uitvinken ..en je muziek van cd enzo…

  • hakan

    Er is ook een rtf32.exe actief in taakbeheer, maar hij is maar 0,1 seconden ofzo zichtbaar, hij verdwijnt, kom ie na 1 seconde ofzo weer terug, zie je weer 0,1 sec ofzo enzovoort… misschien dat dit jullie helpt :) ik heb de rtf32.exe kunnen lezen door een screenshot te maken, zo snel ging het :|

  • MANONNA

    Deze?

    Rtfixm32 RtFixM32.exe

    (Cybermedia Inc, now McAfee) Part of First Aid 98. Read FA_GD32 for more details.

    Recommendation :

    RTFIXM32 is often the cause of shutdown problems and freezes. If after reading FA_GD32 you decide to keep First Aid 98, you should at least disable RTFIXM32 with The Ultimate Troubleshooter.