Malwarebytes Anti-Malware
www.malwarebytes.orgDatum skenování: 19.6.2015
Čas skenování: 8:58:38
Protokol:
Správce: Ano
Verze: 2.01.6.1022
Databáze malwaru: v2015.06.19.01
Databáze rootkitů: v2015.06.15.01
Licence: Premium
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Zapnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Pepa
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 398790
Uplynulý čas: 11 min, 24 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Nenalezeny žádné škodlivé položky)
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 16
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B3F277EE-0481-42F3-A102-532629B9FEF9}, Do karantény, [cebfbefec8c2ac8a42de1d7029dc13ed],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FF171E52-320F-469E-ACF4-E19FCB8B2F06}, Do karantény, [dab358646426b383d14d226b0afb8d73],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, Do karantény, [b2db9e1ebfcbfc3a44b9eba449bc5da3],
PUP.Optional.SavePass.A, HKLM\SOFTWARE\WOW6432NODE\SavePass 1.1-nv, Do karantény, [0687c2fa0783f24470130f0c0cf8e719],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FF171E52-320F-469E-ACF4-E19FCB8B2F06}, Do karantény, [65283488eaa0a78ff628553823e227d9],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, Do karantény, [c4c98735018910260bf2583748bd9967],
PUP.Optional.SavePass.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\SavePass 1.1, Do karantény, [c7c6576593f71e181c6928f3bd478c74],
PUP.Optional.Crossrider.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, Do karantény, [29642597e0aa5fd7ae13147642c332ce],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1955E063-7137-408B-BAEA-1C3014F4B1EF}, Do karantény, [8b0207b501890a2cc557b1dc56afc739],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{22A143FF-A243-442F-89D7-2F59FCE4189F}, Do karantény, [e5a8b4082664ab8b63b94746f510ea16],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{24C586B4-8EAF-4FF9-8095-4A2151C22D76}, Do karantény, [56376458d6b474c2a379c5c8e4212bd5],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4E4EBA2F-7D2B-44EA-8F42-AD4EE6AAE6AF}, Do karantény, [018c6359dab000365fbdf8958f76dc24],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{685B1E0D-A5B9-44E6-9896-E4236C6732FF}, Do karantény, [7e0fc3f92169c274b765c5c87a8b639d],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8DDCBFA2-9CE3-4DDB-8055-6CF6D0695960}, Do karantény, [6528f0cc3456de5855c71c7146bf6c94],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CFA7E8F0-FA94-49C0-8E7B-E2FFE7A3CAFE}, Do karantény, [e0ad6a5245458caacf4db4d949bcb24e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FF171E52-320F-469E-ACF4-E19FCB8B2F06}, Do karantény, [eba21d9f36545bdbf526eda0a75eb44c],
Hodnoty registru: 13
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{b3f277ee-0481-42f3-a102-532629b9fef9}|AppName, SavePass 1.1-codedownloader.exe, Do karantény, [cebfbefec8c2ac8a42de1d7029dc13ed]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ff171e52-320f-469e-acf4-e19fcb8b2f06}|AppName, SavePass 1.1-bg.exe, Do karantény, [dab358646426b383d14d226b0afb8d73]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, Do karantény, [b2db9e1ebfcbfc3a44b9eba449bc5da3]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ff171e52-320f-469e-acf4-e19fcb8b2f06}|AppName, SavePass 1.1-bg.exe, Do karantény, [65283488eaa0a78ff628553823e227d9]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, Do karantény, [c4c98735018910260bf2583748bd9967]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1955E063-7137-408B-BAEA-1C3014F4B1EF}|AppName, 555b4a3d-523d-4293-ad78-42c893b38b52-2.exe-buttonutil.exe, Do karantény, [8b0207b501890a2cc557b1dc56afc739]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{22A143FF-A243-442F-89D7-2F59FCE4189F}|AppName, 555b4a3d-523d-4293-ad78-42c893b38b52-2.exe-buttonutil.exe, Do karantény, [e5a8b4082664ab8b63b94746f510ea16]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{24C586B4-8EAF-4FF9-8095-4A2151C22D76}|AppName, 555b4a3d-523d-4293-ad78-42c893b38b52-2.exe-buttonutil.exe, Do karantény, [56376458d6b474c2a379c5c8e4212bd5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4E4EBA2F-7D2B-44EA-8F42-AD4EE6AAE6AF}|AppName, 555b4a3d-523d-4293-ad78-42c893b38b52-2.exe-buttonutil.exe, Do karantény, [018c6359dab000365fbdf8958f76dc24]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{685B1E0D-A5B9-44E6-9896-E4236C6732FF}|AppName, 94c48dab-dea1-45f3-b60f-34ab20cece93-2.exe-buttonutil.exe, Do karantény, [7e0fc3f92169c274b765c5c87a8b639d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8DDCBFA2-9CE3-4DDB-8055-6CF6D0695960}|AppName, 9447fa55-6bf2-401e-8ee5-ba29de9f2196-2.exe-buttonutil.exe, Do karantény, [6528f0cc3456de5855c71c7146bf6c94]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CFA7E8F0-FA94-49C0-8E7B-E2FFE7A3CAFE}|AppName, 555b4a3d-523d-4293-ad78-42c893b38b52-2.exe-buttonutil.exe, Do karantény, [e0ad6a5245458caacf4db4d949bcb24e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4106156512-3336392037-3228977710-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ff171e52-320f-469e-acf4-e19fcb8b2f06}|AppName, SavePass 1.1-bg.exe, Do karantény, [eba21d9f36545bdbf526eda0a75eb44c]
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 5
Rogue.Multiple, C:\ProgramData\3872871776, Do karantény, [c5c8407cb0da00366edd78385fa4a55b],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\bitstreams, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
PUP.Optional.PodoWeb.A, C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321, Do karantény, [414cae0ee2a8a1957ec551a111f2f60a],
PUP.Optional.SnipSmart.A, C:\ProgramData\83b32e09-56dd-4d15-bbc7-350e8627ec65, Do karantény, [573647752565b284d58c4da55aa9936d],
Soubory: 14
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\diablo130302.cl, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\diakgcn121016.cl, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\libcurl-4.dll, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\libeay32.dll, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\libidn-11.dll, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\librtmp.dll, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\libssh2.dll, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\mncmmdbdy.exe, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\phatk121016.cl, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\poclbm130302.cl, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\scrypt130511.cl, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\ssleay32.dll, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\zlib1.dll, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Trojan.Agent.BCM, C:\Windows\inf\mncmmdbdy\bitstreams\fpgaminer_top_fixed7_197MHz.ncd, Do karantény, [bad368545a3092a4ca09ba07aa5932ce],
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)