Ha,
Ik kan de HijackThis-setup wel downloaden, maar niet openen. Dan krijg ik de melding dat de administrator het systeem zo heeft ingesteld dat de installatie onmogelijk is.
Hier het MBAM-logje (dat werkte trouwens nadat ik het nog eens installeerde in veilige modus!):
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Databaseversie: 7400
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
7-8-2011 14:36:54
mbam-log-2011-08-07 (14-36-54).txt
Scantype: Snelle scan
Objecten gescand: 188127
Verstreken tijd: 10 minuut/minuten, 25 seconde
Geheugenprocessen genfecteerd: 0
Geheugenmodulen genfecteerd: 0
Registersleutels genfecteerd: 5
Registerwaarden genfecteerd: 2
Registerdata genfecteerd: 0
Mappen genfecteerd: 2
Bestanden genfecteerd: 13
Geheugenprocessen genfecteerd:
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen genfecteerd:
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels genfecteerd:
HKEY_CURRENT_USER\Software\Microsoft\idgbn5xehg (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\MEKOMDO (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_GOOGLEUPDATEBETA (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GoogleUpdateBeta (Backdoor.IRCBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> Quarantined and deleted successfully.
Registerwaarden genfecteerd:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{7E83E48D-D9EE-7E9D-7CA3-27E3490129BC} (Spyware.Password) -> Value: {7E83E48D-D9EE-7E9D-7CA3-27E3490129BC} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\MEKOMDO\DllName (Trojan.Agent) -> Value: DllName -> Quarantined and deleted successfully.
Registerdata genfecteerd:
(Geen kwaadaardige objecten gedetecteerd)
Mappen genfecteerd:
c:\Recycle.Bin (Trojan.Spyeyes) -> Quarantined and deleted successfully.
c:\WINDOWS\$xntuninstall643$ (Adware.AdRotator) -> Quarantined and deleted successfully.
Bestanden genfecteerd:
c:\documents and settings\en solveren loven\application data\Piyl\omnae.exe (Spyware.Password) -> Quarantined and deleted successfully.
c:\documents and settings\en solveren loven\mijn documenten\downloads\installer_windows_movie_maker_14_0_8091_0730_(vista)_nederlands_dutch(2).exe (PUP.SmsPay.pns) -> Quarantined and deleted successfully.
c:\documents and settings\en solveren loven\mijn documenten\downloads\installer_windows_movie_maker_14_0_8091_0730_(vista)_nederlands_dutch.exe (PUP.SmsPay.pns) -> Quarantined and deleted successfully.
c:\documents and settings\default user\menu start\programma's\opstarten\qewy.exe (Spyware.Password) -> Quarantined and deleted successfully.
c:\documents and settings\Wijnand\menu start\programma's\opstarten\yssuu.exe (Spyware.Password) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\providorite_3.dll (Heuristics.Shuriken) -> Quarantined and deleted successfully.
c:\documents and settings\en solveren loven\local settings\Temp\jar_cache7187115504827620128.tmp (Heuristics.Shuriken) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\O3TUQO7G\load[1].htm (Spyware.Password) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{810401e2-dde0-454e-b0e2-aa89c9e5967c}.job (Trojan.FraudPack) -> Quarantined and deleted successfully.
c:\WINDOWS\$xntuninstall643$\zrpt.xml (Adware.AdRotator) -> Quarantined and deleted successfully.
c:\documents and settings\en solveren loven\mijn documenten\downloads\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.