Tady je ten log.
Malwarebytes' Anti-Malware
www.malwarebytes.org
Verze databáze:
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
3.8.2011 13:05:54
mbam-log-2011-08-03 (13-05-54).txt
Typ: Úplná kontrola (C:\|)
Kontrolované objekty: 230163
Uplynulý čas: 49 minut, 26 sekund
Infikované procesy v paměti: 1
Infikované moduly v paměti: 0
Infikované klíče v registru: 2
Infikované hodnoty v registru: 4
Infikované datové položky v registru: 1
Infikované složky: 0
Infikované soubory: 47
Infikované procesy v paměti:
c:\documents and settings\s.langerova.kvsu\data aplikací\microsoft\conhost.exe (Trojan.Agent) -> 1564 -> Unloaded process successfully.
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ACRORD32.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\conhost (Trojan.Agent) -> Value: conhost -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Value: Load -> Delete on reboot.
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Value: Shell -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer (PUM.Bad.Proxy) -> Value: ProxyServer -> Quarantined and deleted successfully.
Infikované datové položky v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Bad: (C:\DOCUME~1\SLANGE~1.KVS\LOCALS~1\Temp\csrss.exe) Good: () -> Quarantined and deleted successfully.
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\documents and settings\s.langerova.kvsu\local settings\Temp\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\lj1010seriesprintsys\instmsiw.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\instmsia.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\hpsetup.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\hpinst.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\hpbvspst.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\hpbtpg.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\autorun.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\apps\Adobe\acrobat 5.0\Reader\AcroRd32.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\autorun\launch.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\autorun\hpcdb.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\hewlett-packard\Scrubber\Scrubber.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\hewlett-packard\Scrubber\MsiZap.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\HW\HPZipm12.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\HW\HPZinw12.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\HW\HPZid412.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\Temp\cfgtoipx.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\Temp\cfgtoip.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\webreg\webreg.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\ar\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\cs\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\da\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\de\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\el\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\en\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\es\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\fi\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\fr\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\he\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\hu\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\it\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\ja\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\ko\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\nl\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\no\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\pl\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\pt\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\ru\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\sk\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\sv\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\th\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\tr\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\zhcn\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\lj1010seriesprintsys\wu_wizard\zhtw\hpbsuwiz.exe (Trojan.Agent) -> Not selected for removal.
c:\documents and settings\s.langerova.kvsu\data aplikací\microsoft\conhost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\s.langerova.kvsu\local settings\Temp\csrss.exe (Trojan.Agent) -> Delete on reboot.
c:\WINDOWS\SVCHOST.COM (Virus.Neshta) -> Quarantined and deleted successfully.