Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Databaseversie: 6528 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 7/05/2011 22:15:33 mbam-log-2011-05-07 (22-15-33).txt Scantype: Snelle scan Objecten gescand: 158976 Verstreken tijd: 18 minuut/minuten, 25 seconde(n) Geheugenprocessen geïnfecteerd: 0 Geheugenmodulen geïnfecteerd: 0 Registersleutels geïnfecteerd: 9 Registerwaarden geïnfecteerd: 0 Registerdata geïnfecteerd: 2 Mappen geïnfecteerd: 0 Bestanden geïnfecteerd: 17 Geheugenprocessen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Registersleutels geïnfecteerd: HKEY_CURRENT_USER\SOFTWARE\3FWHZQA3LT (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\6BTOP2GA8A (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\SMH2B46TDP (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\UO8KTAT1GY (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\qword.com (Adware.QWO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully. Registerwaarden geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Registerdata geïnfecteerd: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Trojan.FakeAlert) -> Bad: (mtjiocih.dll) Good: () -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.Homepage) -> Bad: (http://www.qword.com/?s=1) Good: (http://www.Google.com/) -> Quarantined and deleted successfully. Mappen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Bestanden geïnfecteerd: c:\Windows\System32\mtjiocih.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Windows\System32\winack32.rom (Trojan.Nebuler) -> Quarantined and deleted successfully. c:\Windows\System32\wineax32.rom (Trojan.Nebuler) -> Quarantined and deleted successfully. c:\Windows\System32\wingkh32.rom (Trojan.Nebuler) -> Quarantined and deleted successfully. c:\Windows\System32\winhvr32.rom (Trojan.Nebuler) -> Quarantined and deleted successfully. c:\Windows\System32\winllf32.rom (Trojan.Nebuler) -> Quarantined and deleted successfully. c:\Windows\System32\winrlw32.rom (Trojan.Nebuler) -> Quarantined and deleted successfully. c:\Windows\System32\winuvz32.rom (Trojan.Nebuler) -> Quarantined and deleted successfully. c:\Windows\System32\winxef32.rom (Trojan.Nebuler) -> Quarantined and deleted successfully. c:\Windows\System32\winyrz32.rom (Trojan.Nebuler) -> Quarantined and deleted successfully. c:\Users\Vincent\downloads\videoconvertersetup.exe (Adware.Agent) -> Quarantined and deleted successfully. c:\Users\Vincent\downloads\Keygen.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully. c:\Users\Vincent\favorites\qword search engine.url (Adware.QWO) -> Quarantined and deleted successfully. c:\Windows\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Tasks\{35dc3473-a719-4d14-b7c1-fd326ca84a0c}.job (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Tasks\{62c40aa6-4406-467a-a5a5-dfdf1b559b7a}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Windows\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.