Malwarebytes' Anti-Malware
www.malwarebytes.org
Verze databáze:
Windows 5.1.2600 Service Pack 1 (Safe Mode)
Internet Explorer 6.0.2800.1106
21.9.2011 22:37:50
mbam-log-2011-09-21 (22-37-50).txt
Typ: Úplná kontrola (A:\|C:\|D:\|)
Kontrolované objekty: 289240
Uplynulý čas: 29 minut, 45 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 3
Infikované hodnoty v registru: 3
Infikované datové položky v registru: 2
Infikované složky: 0
Infikované soubory: 17
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VMwareService (Malware.Packer.Krunchy) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_WINSPOOLSVC (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSpoolSvc (Trojan.Agent) -> Quarantined and deleted successfully.
Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows LoL Layer (Backdoor.Bot) -> Value: Windows LoL Layer -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Windows LoL Layer (Backdoor.Bot) -> Value: Windows LoL Layer -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows LoL Layer (Backdoor.Bot) -> Value: Windows LoL Layer -> Quarantined and deleted successfully.
Infikované datové položky v registru:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\System32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Delete on reboot.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Delete on reboot.
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\WINDOWS\system\vmwareservice.exe (Malware.Packer.Krunchy) -> Quarantined and deleted successfully.
c:\system volume information\_restore{5a02d41f-8332-493c-9036-a95593bd9a5d}\RP8\A0003758.exe (CrypTool.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{5a02d41f-8332-493c-9036-a95593bd9a5d}\RP8\A0003784.exe (CrypTool.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{5a02d41f-8332-493c-9036-a95593bd9a5d}\RP8\A0003807.exe (Malware.Packer.u64) -> Quarantined and deleted successfully.
c:\system volume information\_restore{5a02d41f-8332-493c-9036-a95593bd9a5d}\RP8\A0006808.dll (Trojan.CryptVI) -> Quarantined and deleted successfully.
c:\system volume information\_restore{5a02d41f-8332-493c-9036-a95593bd9a5d}\RP8\A0008106.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{5a02d41f-8332-493c-9036-a95593bd9a5d}\RP8\A0008108.exe (CrypTool.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{5a02d41f-8332-493c-9036-a95593bd9a5d}\RP8\A0008110.exe (Malware.Packer.u64) -> Quarantined and deleted successfully.
c:\system volume information\_restore{5a02d41f-8332-493c-9036-a95593bd9a5d}\RP8\A0008111.exe (Malware.Packer.u64) -> Quarantined and deleted successfully.
c:\system volume information\_restore{5a02d41f-8332-493c-9036-a95593bd9a5d}\RP9\A0008768.exe (Malware.Packer.Krunchy) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\config\systemprofile\local settings\temporary internet files\Content.IE5\94MQSIB8\tyf[1].jpg (Extension.Mismatch) -> Quarantined and deleted successfully.
c:\_OTL\movedfiles\09182011_195226\c_windows\system32\csrsc.exe (Malware.Packer.u64) -> Quarantined and deleted successfully.
c:\_OTL\movedfiles\09182011_195226\c_windows\system32\globalpatch.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\_OTL\movedfiles\09182011_195226\c_windows\system32\svchots.exe (CrypTool.Agent) -> Quarantined and deleted successfully.
c:\_OTL\movedfiles\09182011_195226\c_windows\system32\x (Worm.Conficker) -> Quarantined and deleted successfully.
c:\_OTL\movedfiles\09182011_195226\c_windows\system32\x.exe (Malware.Packer.u64) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\rmvxuxj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.