Malwarebytes' Anti-Malware 1.40
Wersja bazy definicji: 2551
Windows 5.1.2600 Dodatek Service Pack 2
2009-09-04 18:17:00
mbam-log-2009-09-04 (18-16-54).txt
Typ skanowania: Szybkie skanowanie
Przeskanowane obiekty: 111937
Upłynęło: 7 minute(s), 50 second(s)
Zainfekowane procesy w pamięci: 1
Zainfekowane moduły pamięci: 3
Zainfekowane klucze rejestru: 8
Zainfekowane wartości rejestru: 5
Zainfekowane pliki rejestru: 6
Zainfekowane foldery: 5
Zainfekowane pliki: 57
Zainfekowane procesy w pamięci:
C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe (Rogue.Multiple)

Zainfekowane moduły pamięci:
C:\Program Files\PC_Antispyware2010\htmlayout.dll (Rogue.AntiVirusPro2009)

C:\Program Files\PC_Antispyware2010\AVEngn.dll (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\pthreadVC2.dll (Rogue.PC_Antispyware2010)

Zainfekowane klucze rejestru:
HKEY_CLASSES_ROOT\TypeLib\{d724f038-df89-4a1a-83d1-fd9164b78077} (Rogue.BulletProofSpyware)

HKEY_CLASSES_ROOT\Interface\{502f728b-67b8-409e-bceb-7ee8632f321a} (Rogue.BulletProofSpyware)

HKEY_CLASSES_ROOT\Interface\{d2cd81e5-cc37-44b3-93b7-c52cb993ba34} (Rogue.BulletProofSpyware)

HKEY_CLASSES_ROOT\Interface\{da295dae-fce7-4168-bcb8-edc3a433bd97} (Rogue.BulletProofSpyware)

HKEY_CLASSES_ROOT\Interface\{ed40af28-f03f-492a-9542-e24945cd65aa} (Rogue.BulletProofSpyware)

HKEY_CLASSES_ROOT\CLSID\{e6bb8b70-8ad2-43b6-a952-83e462ce80de} (Rogue.BulletProofSpyware)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\pc_antispyware2010 (Rogue.PC_Antispyware2010)

HKEY_LOCAL_MACHINE\SOFTWARE\PC_Antispyware2010 (Rogue.PC_Antispyware2010)

Zainfekowane wartości rejestru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pc antispyware 2010 (Rogue.Multiple)

HKEY_CURRENT_USER\Control Panel\don't load\scui.cpl (Hijack.SecurityCenter)

HKEY_CURRENT_USER\Control Panel\don't load\wscui.cpl (Hijack.SecurityCenter)

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle)

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\braviax (Trojan.Downloader)

Zainfekowane pliki rejestru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter)


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter)


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter)


HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter)


HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter)


HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter)


Zainfekowane foldery:
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013 (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Menu Start\Programy\PC_Antispyware2010 (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010 (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\data (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT (Rogue.PC_Antispyware2010)

Zainfekowane pliki:
C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe (Rogue.Multiple)

C:\Program Files\PC_Antispyware2010\htmlayout.dll (Rogue.AntiVirusPro2009)

C:\WINDOWS\cru629.dat (Trojan.FakeAlert)

C:\WINDOWS\system32\cru629.dat (Trojan.FakeAlert)

C:\WINDOWS\system32\_scui.cpl (Rogue.HomeAntiVirus)

C:\WINDOWS\system32\bpssc1.1.dll (Rogue.BulletProofSpyware)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\~TM94.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Menu Start\Programy\Autostart\ikowin32.exe (Trojan.Agent)

C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Menu Start\Programy\PC_Antispyware2010\PC_Antispyware2010.lnk (Rogue.PC_Antispyware2010)

C:\Documents and Settings\tuning.DOM-7A917528F48\Menu Start\Programy\PC_Antispyware2010\Uninstall.lnk (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\AVEngn.dll (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.cfg (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\pthreadVC2.dll (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\Uninstall.exe (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\wscui.cpl (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\data\daily.cvd (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcm80.dll (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcp80.dll (Rogue.PC_Antispyware2010)

C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcr80.dll (Rogue.PC_Antispyware2010)

C:\Documents and Settings\tuning.DOM-7A917528F48\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\PC_Antispyware2010.lnk (Rogue.PC_Antispyware2010)

C:\Documents and Settings\tuning.DOM-7A917528F48\Pulpit\PC_Antispyware2010.lnk (Rogue.PCAntispy)

C:\WINDOWS\system32\dllcache\figaro.sys (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN8.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN9.tmp (Trojan.Agent)

C:\WINDOWS\Temp\wpv291251705172.exe (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN1F.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN21.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN23.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN24.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN25.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN26.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN27.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN28.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN29.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN2A.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN2B.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN2C.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN2D.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN2E.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN2F.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN30.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN31.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN32.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN33.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN34.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN35.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\Ustawienia lokalne\Temp\BN97.tmp (Trojan.Agent)

C:\Documents and Settings\tuning.DOM-7A917528F48\delself.bat (Malware.Trace)

C:\WINDOWS\system32\drivers\beep.sys (Fake.Beep.sys)

C:\WINDOWS\system32\dllcache\beep.sys (Fake.Beep.sys)

C:\WINDOWS\braviax.exe (Trojan.Downloader)

C:\WINDOWS\system32\braviax.exe (Trojan.FakeAlert)

C:\Documents and Settings\tuning.DOM-7A917528F48\Dane aplikacji\wiaserva.log (Malware.Trace)

C:\Documents and Settings\tuning.DOM-7A917528F48\oashdihasidhasuidhiasdhiashdiuasdhasd (Trace.Pandex)

C:\WINDOWS\system32\wisdstr.exe (Trojan.FakeAlert)
