Uiteindelijk zijn ere 34 geïnfecteerde bestanden gevonden. Logbestand:
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org
Databaseversie: 4034
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
20-6-2010 22:11:37
mbam-log-2010-06-20 (22-11-37).txt
Scantype: Volledige scan (C:\|E:\|G:\|H:\|)
Objecten gescand: 257712
Verstreken tijd: 3 uur/uren, 51 minuut/minuten, 0 seconde(n)
Geheugenprocessen geïnfecteerd: 0
Geheugenmodulen geïnfecteerd: 1
Registersleutels geïnfecteerd: 3
Registerwaarden geïnfecteerd: 1
Registerdata geïnfecteerd: 3
Mappen geïnfecteerd: 1
Bestanden geïnfecteerd: 25
Geheugenprocessen geïnfecteerd:
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen geïnfecteerd:
C:\WINDOWS\system32\diskcopy32.dll (Trojan.Agent) -> Delete on reboot.
Registersleutels geïnfecteerd:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.fsharproj (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\9cbc4dd1957 (Trojan.Agent) -> Delete on reboot.
Registerwaarden geïnfecteerd:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run\firewall administrating (Backdoor.IRCBot) -> Quarantined and deleted successfully.
Registerdata geïnfecteerd:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: c:\windows\system32\diskcopy32.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: system32\diskcopy32.dll -> Delete on reboot.
Mappen geïnfecteerd:
C:\WINDOWS\system32\SysWoW32 (Worm.Archive) -> Quarantined and deleted successfully.
Bestanden geïnfecteerd:
C:\Documents and Settings\Fabian\Bureaublad\bureaublad pl\Pinnacle.Studio.Ultimate.12.0.0.6163.Only.Keygen-AGAiN\KEYGEN.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
E:\Program Files\Cheat Engine\Systemcallretriever.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
E:\Mijn documenten\LimeWire\Saved\Keygen Pinnacle Studio 12.exe (P2P.Dropper.A) -> Quarantined and deleted successfully.
E:\Mijn documenten\LimeWire\Saved\LimeWire.Pro.5.4.6_(diMi)\setup.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\mu1189484427v4 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\mu1189484427v4.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\mu1189484427v5 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\mu1189484427v5.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\mu1189484427v6 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\mu1189484427v6.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\mu1189484427v7 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\mu1189484427v7.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1189484427v0 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1189484427v0.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1189484427v1 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1189484427v1.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1189484427v2 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1189484427v2.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1189484427v3 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1189484427v3.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\diskcopy32.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\dmdlgs32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\DOCPROP32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\GnuHashes.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eapphost32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
Nog steeds meldingen van Avast. Er stond dat ik de computer opnieuw moest opstarten. Ik zet hem nu dus uit.