Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Verzia databázy: 5363
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
28.12.2010 14:50:05
mbam-log-2010-12-28 (14-50-01).txt
Typ kontroly: Úplná kontrola (C:\|)
Objektov kontrolovaných: 133363
Uplynutý čas: 8 min, 29 sek
Infikované služby pamäte: 2
Infikované moduly pamäte: 2
Infikované registračné kľúče: 4
Infikované registračné hodnoty: 4
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 11
Infikované služby pamäte:
c:\WINDOWS\Temp\mfp3lr9.exe (Trojan.Downloader) -> 3032 -> No action taken.
c:\WINDOWS\Temp\mfp3lr9.exe (Trojan.Downloader) -> 3884 -> No action taken.
Infikované moduly pamäte:
c:\WINDOWS\system32\nwcwks.dll (Trojan.Inject) -> No action taken.
c:\documents and settings\all users\data aplikací\Bandoo\sp.DLL (TrojanProxy.Agent) -> No action taken.
Infikované registračné kľúče:
HKEY_CLASSES_ROOT\CLSID\{96AFBE69-C3B0-4b00-8578-D933D2896EE2} (TrojanProxy.Agent) -> No action taken.
HKEY_CLASSES_ROOT\sp (TrojanProxy.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\sp (TrojanProxy.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SPService (TrojanProxy.Agent) -> No action taken.
Infikované registračné hodnoty:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{96AFBE69-C3B0-4B00-8578-D933D2896EE2} (TrojanProxy.Agent) -> Value: {96AFBE69-C3B0-4B00-8578-D933D2896EE2} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{96AFBE69-C3B0-4b00-8578-D933D2896EE2} (TrojanProxy.Agent) -> Value: {96AFBE69-C3B0-4b00-8578-D933D2896EE2} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvc (TrojanProxy.Agent) -> Value: netsvc -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\xho9y (Trojan.Downloader) -> Value: xho9y -> No action taken.
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
c:\WINDOWS\system32\nwcwks.dll (Trojan.Inject) -> No action taken.
c:\documents and settings\all users\data aplikací\Bandoo\sp.DLL (TrojanProxy.Agent) -> No action taken.
c:\documents and settings\Dusan\data aplikací\windows desktop search\drvvcldll81\msftcore.dll (Trojan.Proxy) -> No action taken.
c:\documents and settings\Dusan\data aplikací\windows desktop search\drvvcldll81\msftdm.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\Dusan\data aplikací\windows desktop search\drvvcldll81\msftdm32.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\Dusan\data aplikací\windows desktop search\drvvcldll81\msfteml.dll (Spam.Bot) -> No action taken.
c:\documents and settings\Dusan\data aplikací\windows desktop search\drvvcldll81\msftstp.exe (Trojan.Dropper) -> No action taken.
c:\documents and settings\Dusan\data aplikací\windows desktop search\drvvcldll81\msfttcp.dll (Trojan.Downloader) -> No action taken.
c:\WINDOWS\system32\calc.exe (Trojan.Agent.Gen) -> No action taken.
c:\documents and settings\Dusan\nabídka start\Programy\po spuštění\winupdate.lnk (Trojan.Downloader) -> No action taken.
c:\WINDOWS\Temp\mfp3lr9.exe (Trojan.Downloader) -> No action taken.