Re: Win32/agent.sdg.gen v MBR sektoru disku - prosim o pomoc
Napsal: 14 zář 2011 15:20
A já ho dám sem.
Mimochodem - super článek, hned budu taky číst...
---------- REPORT------------------
Scan Statistics:
Scan Time: 8 506 seconds
Scan Targets: Entire computer
Counts:
Total items scanned: 869 369
- Files & Directories: 858 908
- Registry Entries: 417
- Processes & Start-up Items: 3 108
- Network & Browser Items: 6 930
- Other: 5
- Trusted Files: 1 798
- Skipped Files: 0
Total security risks detected: 34
Total items resolved: 28
Total items that require attention: 6
Resolved Threats:
3 Tracking Cookies
Type: Anomaly
Risk: Low (Low Stealth, Low Removal, Low Performance, Low Privacy)
Categories: Tracking Cookies
Status: Fully Resolved
-----------
3 Tracking Cookies
.hit.gemius.pl - Deleted
- Deleted
- Deleted
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
c:\documents and settings\marek\local settings\data aplikací\xenocode\sandbox\trueboxshot\1.9\2010.02.22t04.15\virtual\modified\@programfiles@\true boxshot\trueboxshot.exe - Deleted
1 Browser Cache
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
c:\program files\activision\call of duty 4 - modern warfare\brew-cod4.exe - Deleted
1 Browser Cache
Trojan.ADH
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
c:\program files\dvdvideosoft\free audio cd burner\icon1045.exe - Deleted
1 Browser Cache
Trojan.Gen
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
c:\program files\plasq\comic life\cl13671_crk.exe - Deleted
1 Browser Cache
WS.Viral.1
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
[cr_acds70.exe] inside of [d:\install\po_instalaci_pc\acdsee.v7.0\powerpacky\acd systems acdsee v7.0.43 powerpack winall keymaker only fixed-core\cr-x0298.zip] - Deleted
WS.Viral.1
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\install\po_instalaci_pc\acdsee.v7.0\powerpacky\acd systems acdsee v7.0.43 powerpack winall keymaker only fixed-core\cr_acds70.exe - Deleted
1 Browser Cache
Trojan Horse
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
[cr-bs136.exe] inside of [d:\install\po_instalaci_pc\bsplayer\bsplayer.pro.v1.36.825.multilingual.winall.incl.keymaker-core\cr-bs136.zip] - Deleted
Trojan.Gen
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\install\po_instalaci_pc\ahead nero 9.0.9.4b\nero 9.0.9.4b patchfix\nero9patch.exe - Deleted
1 Browser Cache
Trojan Horse
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\install\po_instalaci_pc\bsplayer\bsplayer.pro.v1.36.825.multilingual.winall.incl.keymaker-core\cr-bs136-keygen.exe - Deleted
1 Browser Cache
AsteriskLogger
Type: Compressed
Risk: Medium (Medium Stealth, Medium Removal, Medium Performance, Medium Privacy)
Categories: Security Risk
Status: Fully Resolved
-----------
1 File
[astlog.exe] inside of [d:\install\programy\odkryvac hvezdicek\astlog.zip] - Deleted
AsteriskLogger
Type: Anomaly
Risk: Medium (Medium Stealth, Medium Removal, Medium Performance, Medium Privacy)
Categories: Security Risk
Status: Fully Resolved
-----------
1 File
d:\install\programy\odkryvac hvezdicek\astlog.exe - Deleted
1 Browser Cache
Trojan.Gen.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\install\programy\_nove_zaradit\conxtdvd 4.1.7.343\keygen.exe - Deleted
1 Browser Cache
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
d:\install\programy\_nove_zaradit\multi password recovery v1.1.8 portable\hooklib.dll - Deleted
1 Browser Cache
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
d:\install\programy\_nove_zaradit\multi password recovery v1.1.8 portable\updatechecker.exe - Deleted
1 Browser Cache
Infostealer.Gampass
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Restart Required
-----------
51 Registry Entries
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoDriveTypeAutoRun:149 - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoDriveTypeAutoRun:149 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1007\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoDriveTypeAutoRun:149 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1009\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoDriveTypeAutoRun:149 - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoDriveTypeAutoRun:149 - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoDriveTypeAutoRun:149 - Restart Required
HKEY_CLASSES_ROOT\CLSID\{1DBD6574-D6D0-4782-94C3-69619E719765} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks->{1DBD6574-D6D0-4782-94C3-69619E719765} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{29EA67E0-9EE5-4D1A-A056-5B7BDAC4CF97} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{58FF3024-8A83-4B1A-88E9-302F47646EEE} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{93DEE065-EC9B-4505-ADD3-19880AD3C38F} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{950D1600-DE4A-448D-93B4-7BAE5A7A8052} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{AD794E6B-90B7-4F9D-8FD6-0C16E3298FF2} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{DA63E650-537C-4042-87BB-9D19D844680B} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{E1D19FCC-4777-4D71-B863-6A0A5B4E59BC} - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1003\avs - Restart Required
HKEY_USERS\S-1-5-19\avs - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1007\avs - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1009\avs - Restart Required
HKEY_USERS\S-1-5-20\avs - Restart Required
HKEY_USERS\.DEFAULT\avs - Restart Required
HKEY_CLASSES_ROOT\CLSID\{021F087F-4378-545F-74FA-37D345AD7A8C} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{50A8A8C4-EDC9-4ABD-A0A2-2E2418982189} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{B29583D8-033A-4B9F-8553-7C5458F3FB8E} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{F99DEFDD-200B-4410-B572-E90883D527D2} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks->{29EA67E0-9EE5-4D1A-A056-5B7BDAC4CF97} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks->{DA63E650-537C-4042-87BB-9D19D844680B} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks->{58FF3024-8A83-4B1A-88E9-302F47646EEE} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks->{950D1600-DE4A-448D-93B4-7BAE5A7A8052} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks->{93DEE065-EC9B-4505-ADD3-19880AD3C38F} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\->CheckedValue:1 - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Restart Required
1 File
d:\install\programy\_nove_zaradit\naevius.youtube.converter.2.2\keygen.exe - Deleted
1 Browser Cache
Trojan.ADH.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\install\programy\_nove_zaradit\esetlicence finder (minodlogin)3981\aln3981.exe - Deleted
1 Browser Cache
WS.Malware.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
2 Files
d:\install\programy\_nove_zaradit\fast mp3 cutter joiner 2.5.1128\patch\patch.exe - Deleted
d:\install\programy\audio-video - dvd-divx-mp3\winmpg - video convertor\fff-wm56.exe - Deleted
1 Browser Cache
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
d:\install\programy\__portable\coreldraw graphics suite x5 sp2 v15.2.0.661\corel capture x5.exe - Deleted
1 Browser Cache
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
d:\install\programy\__portable\winavi all-in-one converter v1.1.0.3916\winavi all in one converter.exe - Deleted
1 Browser Cache
WS.Malware.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
[keygen.exe] inside of [d:\install\programy\audio-video - dvd-divx-mp3\joining and splitting tools\avi-mpeg-rm-wmv_joiner_crack.zip] - Deleted
WS.Malware.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
[platorip.exe] inside of [d:\install\programy\audio-video - dvd-divx-mp3\plato.dvd.ripper.2.32.cracked-icu.zip] - Deleted
WS.Malware.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
[fff-wm56.exe] inside of [d:\install\programy\audio-video - dvd-divx-mp3\winmpg - video convertor\winmpg_videoconvert_crack.zip] - Deleted
Suspicious.Cloud.7.F
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
[keygen.exe] inside of [d:\osobni - marek\vjeci\games_vjeci\doom3\doom3 - keygen+crack.zip] - Deleted
Suspicious.Cloud.7.L
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
[pztrain.exe] inside of [d:\osobni - marek\vjeci\games_vjeci\doom3\doom3 - trainer09.zip] - Deleted
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
d:\osobni - marek\vjeci\games_vjeci\call of duty 4 - modern warfare\trainer\brew-cod4.exe - Deleted
1 Browser Cache
Unresolved Threats:
Risks in compressed file "acd systems acdsee v7.0.43 powerpack winall keymaker only fixed-core.rar"
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Not Attempted
-----------
1 File
[d:\install\po_instalaci_pc\acdsee.v7.0\powerpacky\acd systems acdsee v7.0.43 powerpack winall keymaker only fixed-core.rar] - Not Attempted
Risks in compressed file "comic-life-1.3.6.71.rar"
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Not Attempted
-----------
1 File
[d:\install\programy\_nove_zaradit\comic-life-1.3.6.71.rar] - Not Attempted
Risks in compressed file "ojosoft total video converter 2.7.4.0126.rar"
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Not Attempted
-----------
1 File
[d:\install\programy\_nove_zaradit\ojosoft total video converter 2.7.4.0126.rar] - Not Attempted
MultiPassRecover
Type: Anomaly
Risk: Low (Low Stealth, Low Removal, Low Performance, Low Privacy)
Categories: Security Assessment Tool
Status: Not Attempted
-----------
2 Files
d:\install\programy\_nove_zaradit\multi password recovery v1.1.8 portable\mpr.exe - No action taken
d:\install\programy\_nove_zaradit\multi password recovery v1.1.8 portable\mpr.exe.bak - No action taken
1 Browser Cache
Risks in compressed file "portable getright pro v6.5.exe"
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Not Attempted
-----------
1 File
[d:\install\programy\__portable\getright pro v6.5\portable getright pro v6.5.exe] - Not Attempted
Trojan.Alemod
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Review
-----------
1 File
d:\install\programy\audio-video - dvd-divx-mp3\replay.converter.v2.31-te\crack\replayconverterv231_crack.exe - Failed
1 Browser Cache
----------------REPORT END-----------------
Mimochodem - super článek, hned budu taky číst...
---------- REPORT------------------
Scan Statistics:
Scan Time: 8 506 seconds
Scan Targets: Entire computer
Counts:
Total items scanned: 869 369
- Files & Directories: 858 908
- Registry Entries: 417
- Processes & Start-up Items: 3 108
- Network & Browser Items: 6 930
- Other: 5
- Trusted Files: 1 798
- Skipped Files: 0
Total security risks detected: 34
Total items resolved: 28
Total items that require attention: 6
Resolved Threats:
3 Tracking Cookies
Type: Anomaly
Risk: Low (Low Stealth, Low Removal, Low Performance, Low Privacy)
Categories: Tracking Cookies
Status: Fully Resolved
-----------
3 Tracking Cookies
.hit.gemius.pl - Deleted
- Deleted
- Deleted
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
c:\documents and settings\marek\local settings\data aplikací\xenocode\sandbox\trueboxshot\1.9\2010.02.22t04.15\virtual\modified\@programfiles@\true boxshot\trueboxshot.exe - Deleted
1 Browser Cache
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
c:\program files\activision\call of duty 4 - modern warfare\brew-cod4.exe - Deleted
1 Browser Cache
Trojan.ADH
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
c:\program files\dvdvideosoft\free audio cd burner\icon1045.exe - Deleted
1 Browser Cache
Trojan.Gen
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
c:\program files\plasq\comic life\cl13671_crk.exe - Deleted
1 Browser Cache
WS.Viral.1
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
[cr_acds70.exe] inside of [d:\install\po_instalaci_pc\acdsee.v7.0\powerpacky\acd systems acdsee v7.0.43 powerpack winall keymaker only fixed-core\cr-x0298.zip] - Deleted
WS.Viral.1
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\install\po_instalaci_pc\acdsee.v7.0\powerpacky\acd systems acdsee v7.0.43 powerpack winall keymaker only fixed-core\cr_acds70.exe - Deleted
1 Browser Cache
Trojan Horse
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
[cr-bs136.exe] inside of [d:\install\po_instalaci_pc\bsplayer\bsplayer.pro.v1.36.825.multilingual.winall.incl.keymaker-core\cr-bs136.zip] - Deleted
Trojan.Gen
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\install\po_instalaci_pc\ahead nero 9.0.9.4b\nero 9.0.9.4b patchfix\nero9patch.exe - Deleted
1 Browser Cache
Trojan Horse
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\install\po_instalaci_pc\bsplayer\bsplayer.pro.v1.36.825.multilingual.winall.incl.keymaker-core\cr-bs136-keygen.exe - Deleted
1 Browser Cache
AsteriskLogger
Type: Compressed
Risk: Medium (Medium Stealth, Medium Removal, Medium Performance, Medium Privacy)
Categories: Security Risk
Status: Fully Resolved
-----------
1 File
[astlog.exe] inside of [d:\install\programy\odkryvac hvezdicek\astlog.zip] - Deleted
AsteriskLogger
Type: Anomaly
Risk: Medium (Medium Stealth, Medium Removal, Medium Performance, Medium Privacy)
Categories: Security Risk
Status: Fully Resolved
-----------
1 File
d:\install\programy\odkryvac hvezdicek\astlog.exe - Deleted
1 Browser Cache
Trojan.Gen.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\install\programy\_nove_zaradit\conxtdvd 4.1.7.343\keygen.exe - Deleted
1 Browser Cache
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
d:\install\programy\_nove_zaradit\multi password recovery v1.1.8 portable\hooklib.dll - Deleted
1 Browser Cache
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
d:\install\programy\_nove_zaradit\multi password recovery v1.1.8 portable\updatechecker.exe - Deleted
1 Browser Cache
Infostealer.Gampass
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Restart Required
-----------
51 Registry Entries
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoDriveTypeAutoRun:149 - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoDriveTypeAutoRun:149 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1007\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoDriveTypeAutoRun:149 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1009\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoDriveTypeAutoRun:149 - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoDriveTypeAutoRun:149 - Restart Required
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoDriveTypeAutoRun:149 - Restart Required
HKEY_CLASSES_ROOT\CLSID\{1DBD6574-D6D0-4782-94C3-69619E719765} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks->{1DBD6574-D6D0-4782-94C3-69619E719765} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{29EA67E0-9EE5-4D1A-A056-5B7BDAC4CF97} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{58FF3024-8A83-4B1A-88E9-302F47646EEE} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{93DEE065-EC9B-4505-ADD3-19880AD3C38F} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{950D1600-DE4A-448D-93B4-7BAE5A7A8052} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{AD794E6B-90B7-4F9D-8FD6-0C16E3298FF2} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{DA63E650-537C-4042-87BB-9D19D844680B} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{E1D19FCC-4777-4D71-B863-6A0A5B4E59BC} - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1003\avs - Restart Required
HKEY_USERS\S-1-5-19\avs - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1007\avs - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1009\avs - Restart Required
HKEY_USERS\S-1-5-20\avs - Restart Required
HKEY_USERS\.DEFAULT\avs - Restart Required
HKEY_CLASSES_ROOT\CLSID\{021F087F-4378-545F-74FA-37D345AD7A8C} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{50A8A8C4-EDC9-4ABD-A0A2-2E2418982189} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{B29583D8-033A-4B9F-8553-7C5458F3FB8E} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC} - Restart Required
HKEY_CLASSES_ROOT\CLSID\{F99DEFDD-200B-4410-B572-E90883D527D2} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks->{29EA67E0-9EE5-4D1A-A056-5B7BDAC4CF97} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks->{DA63E650-537C-4042-87BB-9D19D844680B} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks->{58FF3024-8A83-4B1A-88E9-302F47646EEE} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks->{950D1600-DE4A-448D-93B4-7BAE5A7A8052} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks->{93DEE065-EC9B-4505-ADD3-19880AD3C38F} - Restart Required
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\->CheckedValue:1 - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Restart Required
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Restart Required
HKEY_USERS\S-1-5-21-507921405-616249376-839522115-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Restart Required
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->ShowSuperHidden:1 - Restart Required
1 File
d:\install\programy\_nove_zaradit\naevius.youtube.converter.2.2\keygen.exe - Deleted
1 Browser Cache
Trojan.ADH.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
1 File
d:\install\programy\_nove_zaradit\esetlicence finder (minodlogin)3981\aln3981.exe - Deleted
1 Browser Cache
WS.Malware.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Fully Resolved
-----------
2 Files
d:\install\programy\_nove_zaradit\fast mp3 cutter joiner 2.5.1128\patch\patch.exe - Deleted
d:\install\programy\audio-video - dvd-divx-mp3\winmpg - video convertor\fff-wm56.exe - Deleted
1 Browser Cache
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
d:\install\programy\__portable\coreldraw graphics suite x5 sp2 v15.2.0.661\corel capture x5.exe - Deleted
1 Browser Cache
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
d:\install\programy\__portable\winavi all-in-one converter v1.1.0.3916\winavi all in one converter.exe - Deleted
1 Browser Cache
WS.Malware.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
[keygen.exe] inside of [d:\install\programy\audio-video - dvd-divx-mp3\joining and splitting tools\avi-mpeg-rm-wmv_joiner_crack.zip] - Deleted
WS.Malware.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
[platorip.exe] inside of [d:\install\programy\audio-video - dvd-divx-mp3\plato.dvd.ripper.2.32.cracked-icu.zip] - Deleted
WS.Malware.2
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
[fff-wm56.exe] inside of [d:\install\programy\audio-video - dvd-divx-mp3\winmpg - video convertor\winmpg_videoconvert_crack.zip] - Deleted
Suspicious.Cloud.7.F
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
[keygen.exe] inside of [d:\osobni - marek\vjeci\games_vjeci\doom3\doom3 - keygen+crack.zip] - Deleted
Suspicious.Cloud.7.L
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
[pztrain.exe] inside of [d:\osobni - marek\vjeci\games_vjeci\doom3\doom3 - trainer09.zip] - Deleted
Suspicious.Cloud.2
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Fully Resolved
-----------
1 File
d:\osobni - marek\vjeci\games_vjeci\call of duty 4 - modern warfare\trainer\brew-cod4.exe - Deleted
1 Browser Cache
Unresolved Threats:
Risks in compressed file "acd systems acdsee v7.0.43 powerpack winall keymaker only fixed-core.rar"
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Not Attempted
-----------
1 File
[d:\install\po_instalaci_pc\acdsee.v7.0\powerpacky\acd systems acdsee v7.0.43 powerpack winall keymaker only fixed-core.rar] - Not Attempted
Risks in compressed file "comic-life-1.3.6.71.rar"
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Not Attempted
-----------
1 File
[d:\install\programy\_nove_zaradit\comic-life-1.3.6.71.rar] - Not Attempted
Risks in compressed file "ojosoft total video converter 2.7.4.0126.rar"
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Not Attempted
-----------
1 File
[d:\install\programy\_nove_zaradit\ojosoft total video converter 2.7.4.0126.rar] - Not Attempted
MultiPassRecover
Type: Anomaly
Risk: Low (Low Stealth, Low Removal, Low Performance, Low Privacy)
Categories: Security Assessment Tool
Status: Not Attempted
-----------
2 Files
d:\install\programy\_nove_zaradit\multi password recovery v1.1.8 portable\mpr.exe - No action taken
d:\install\programy\_nove_zaradit\multi password recovery v1.1.8 portable\mpr.exe.bak - No action taken
1 Browser Cache
Risks in compressed file "portable getright pro v6.5.exe"
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Heuristic Virus
Status: Not Attempted
-----------
1 File
[d:\install\programy\__portable\getright pro v6.5\portable getright pro v6.5.exe] - Not Attempted
Trojan.Alemod
Type: Anomaly
Risk: High (High Stealth, High Removal, High Performance, High Privacy)
Categories: Virus
Status: Review
-----------
1 File
d:\install\programy\audio-video - dvd-divx-mp3\replay.converter.v2.31-te\crack\replayconverterv231_crack.exe - Failed
1 Browser Cache
----------------REPORT END-----------------