Re: your system is infected wallpaper
[hjt]
malwarebytes' anti-malware 1.42
database versie: 3438
windows 5.1.2600 service pack 3
internet explorer 8.0.6001.18702
27/12/2009 15:54:38
mbam-log-2009-12-27 (15-54-38).txt
scan type: snelle scan
objecten gescand: 106996
verstreken tijd: 5 minute(s), 58 second(s)
geheugenprocessen genfecteerd: 1
geheugenmodulen genfecteerd: 1
registersleutels genfecteerd: 1
registerwaarden genfecteerd: 2
registerdata bestanden genfecteerd: 11
mappen genfecteerd: 3
bestanden genfecteerd: 27
geheugenprocessen genfecteerd:
c:\program files\internetsecurity2010\is2010.exe (rogue.installer) -> unloaded process successfully.
geheugenmodulen genfecteerd:
c:\windows\system32\dmband32.dll (trojan.agent) -> delete on reboot.
registersleutels genfecteerd:
hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon\notify\9866fac3724 (trojan.agent) -> delete on reboot.
registerwaarden genfecteerd:
hkey_current_user\software\microsoft\windows\currentversion\run\internet security 2010 (rogue.installer) -> quarantined and deleted successfully.
hkey_local_machine\software\microsoft\windows\currentversion\rlist (malware.trace) -> quarantined and deleted successfully.
registerdata bestanden genfecteerd:
hkey_local_machine\software\microsoft\windows nt\currentversion\windows\appinit_dlls (trojan.agent) -> data:
c:\windows\system32\dmband32.dll -> delete on reboot.
hkey_local_machine\software\microsoft\windows nt\currentversion\windows\appinit_dlls (trojan.agent) -> data: system32\dmband32.dll -> delete on reboot.
hkey_local_machine\software\microsoft\security center\firewalldisablenotify (disabled.securitycenter) -> bad: (1) good: (0) -> quarantined and deleted successfully.
hkey_local_machine\software\microsoft\security center\updatesdisablenotify (disabled.securitycenter) -> bad: (1) good: (0) -> quarantined and deleted successfully.
hkey_current_user\software\microsoft\windows\currentversion\policies\activedesktop\nochangingwallpaper (hijack.displayproperties) -> bad: (1) good: (0) -> quarantined and deleted successfully.
hkey_current_user\software\microsoft\windows\currentversion\policies\explorer\noactivedesktopchanges (hijack.displayproperties) -> bad: (1) good: (0) -> quarantined and deleted successfully.
hkey_current_user\software\microsoft\windows\currentversion\policies\explorer\nosetactivedesktop (hijack.displayproperties) -> bad: (1) good: (0) -> quarantined and deleted successfully.
hkey_local_machine\software\microsoft\windows\currentversion\policies\activedesktop\nochangingwallpaper (hijack.displayproperties) -> bad: (1) good: (0) -> quarantined and deleted successfully.
hkey_local_machine\software\microsoft\windows\currentversion\policies\explorer\noactivedesktopchanges (hijack.displayproperties) -> bad: (1) good: (0) -> quarantined and deleted successfully.
hkey_local_machine\software\microsoft\windows\currentversion\policies\explorer\nosetactivedesktop (hijack.displayproperties) -> bad: (1) good: (0) -> quarantined and deleted successfully.
hkey_current_user\software\microsoft\windows\currentversion\policies\system\disabletaskmgr (hijack.taskmanager) -> bad: (1) good: (0) -> quarantined and deleted successfully.
mappen genfecteerd:
c:\documents and settings\all users\application data\03057823 (rogue.multiple) -> quarantined and deleted successfully.
c:\windows\system32\syswow32 (worm.archive) -> quarantined and deleted successfully.
c:\program files\internetsecurity2010 (rogue.internetsecurity2010) -> quarantined and deleted successfully.
bestanden genfecteerd:
c:\windows\system32\dmband32.dll (trojan.agent) -> delete on reboot.
c:\program files\internetsecurity2010\is2010.exe (rogue.installer) -> quarantined and deleted successfully.
c:\windows\system32\winhelper86.dll (trojan.fakealert) -> quarantined and deleted successfully.
c:\documents and settings\etienne\local settings\temp\d.tmp (trojan.dropper) -> quarantined and deleted successfully.
c:\documents and settings\etienne\local settings\temporary internet files\content.ie5\9re062ga\setupis2010[1].exe (rogue.installer) -> quarantined and deleted successfully.
c:\documents and settings\etienne\local settings\temporary internet files\content.ie5\qjsnwach\dfghfghgfj[1].dll (trojan.fakealert) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\mi1111269529v4 (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\mi1111269529v4.kwd (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\mi1111269529v6 (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\mi1111269529v6.kwd (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\mi1111269529v7 (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\mi1111269529v7.kwd (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\mu1111269529v5 (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\mu1111269529v5.kwd (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\wu1111269529v0 (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\wu1111269529v0.kwd (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\wu1111269529v1 (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\wu1111269529v1.kwd (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\wu1111269529v2 (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\wu1111269529v2.kwd (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\wu1111269529v3 (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\syswow32\wu1111269529v3.kwd (worm.archive) -> quarantined and deleted successfully.
c:\windows\system32\critical_warning.html (trojan.fakealert) -> quarantined and deleted successfully.
c:\windows\gnuhashes.ini (malware.trace) -> quarantined and deleted successfully.
c:\windows\system32\winupdate86.exe (trojan.fakealert) -> quarantined and deleted successfully.
c:\windows\system32\41.exe (trojan.fakealert) -> quarantined and deleted successfully.
c:\windows\system32\winlogon86.exe (trojan.fakealert) -> quarantined and deleted successfully.
[/hjt]
ziezo
mijn achtergrond kan ik nog steeds niet veranderen :s
het is wel een andere foto maar die kan ik ook niet veranderen