Mbam Log
Heb MBAM alleen laten zoeken, verder nog geen actie ondernomen.
Zoals ik nu de log bekijk, is het hier absoluut niet veilig :shocked:
Malwarebytes' Anti-Malware 1.41
Database version: 2862
Windows 5.1.2600 Service Pack 3
9/26/2009 6:27:25 PM
mbam-log-2009-09-26 (18-27-14).txt
Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 154814
Time elapsed: 57 minute(s), 27 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 12
Registry Values Infected: 10
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 47
Memory Processes Infected:
C:\WINDOWS\system32\sofatnet.exe (Backdoor.Bot) -> No action taken.
Memory Modules Infected:
c:\WINDOWS\system32\BtwSrv.dll (Trojan.Agent) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\btwsrv (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\btwsrv (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btwsrv (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\registry helper (Rogue.Installer) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\registry helper service (Rogue.RegistryHelper) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\registry helper service (Rogue.RegistryHelper) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\registry helper service (Rogue.RegistryHelper) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sofatnet (Backdoor.Bot) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sofatnet (Backdoor.Bot) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sofatnet (Backdoor.Bot) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\RegistryHelper.exe (Rogue.RegistryHelper) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Registry Helper (Rogue.RegistryHelper) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\BuildW (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\FirstInstallFlag (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mso (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udso (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Ulrn (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Update (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateNew (Malware.Trace) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Registry Helper (Rogue.RegistryHelper) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\Programs\Registry Helper (Rogue.RegistryHelper) -> No action taken.
Files Infected:
c:\WINDOWS\system32\BtwSrv.dll (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Alex\Local Settings\Application Data\Mozilla\Firefox\Profiles\j518wyam.default\Cache\97E71A55d01 (Rogue.Installer) -> No action taken.
C:\Documents and Settings\Alex\My Documents\Downloads\RegistryHelperSetupSS.exe (Rogue.Installer) -> No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\85E8YSHM\w[1].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\U18XJQLG\w[1].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\U18XJQLG\w[2].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\U18XJQLG\w[3].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YJTGXKFW\w[1].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YJTGXKFW\w[2].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YWINEWW4\w[1].bin (Backdoor.Bot) -> No action taken.
C:\Program Files\Registry Helper\uninst.exe (Rogue.Installer) -> No action taken.
C:\System Volume Information\_restore{6255B109-431E-4E97-A1E8-6BFE0CF99D2E}\RP13\A0013463.exe (Backdoor.Bot) -> No action taken.
C:\System Volume Information\_restore{6255B109-431E-4E97-A1E8-6BFE0CF99D2E}\RP13\A0013465.exe (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\wiwow64.exe (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\wmdtc.exe (Backdoor.Bot) -> No action taken.
D:\Documents and Settings\Alex2\sys64_nov.exe (Trojan.Scar) -> No action taken.
C:\Program Files\Registry Helper\AdvisorLetters.exe (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\background.jpg (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\delete_invalid_entries_grey.jpg (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\ErrorFound.wav (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\header.gif (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\help.chm (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\IEHandler.exe (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\letter.htm (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\letter1.htm (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\letter2.htm (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\letter3.htm (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\letter4.htm (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\letter5.htm (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\logo.jpg (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\print_16.gif (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\Registry Helper.url (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\RegistryHelper.exe (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\RegistryHelperActivator.exe (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\RegistryHelperBundle.exe (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\RegistryHelperService.exe (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\RegistryHelperSetupCB.exe (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\RegistryHelperSetupTR.exe (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\Starter.exe (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\vbrun60sp5.exe (Rogue.RegistryHelper) -> No action taken.
C:\Program Files\Registry Helper\__removelinks.bat (Rogue.RegistryHelper) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\Programs\Registry Helper\Registry Helper Help.lnk (Rogue.RegistryHelper) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\Programs\Registry Helper\Registry Helper.lnk (Rogue.RegistryHelper) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\Programs\Registry Helper\Visit our Website.lnk (Rogue.RegistryHelper) -> No action taken.
C:\Documents and Settings\All Users\Desktop\Registry Helper.lnk (Rogue.RegistryHelper) -> No action taken.
C:\WINDOWS\system32\FInstall.sys (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\sofatnet.exe (Backdoor.Bot) -> No action taken.
Zoals ik al zei, ik kan ruimen wat ik wil , virus/malware komt steeds trug.. weet alleen niet hoe het gaat in bios en of ik daar mee moet klooien