Antivirus 2009, malwarebytes anti-malware log
Napsal: 27 říj 2008 13:16
Zdravím, přikládám log z malwarebytes anti-malware a prosím a kontrolu případně co s tím mám dál dělat:
Malwarebytes' Anti-Malware 1.30
Verze databáze: 1306
Windows 5.1.2600 Service Pack 3
27.10.2008 13:01:30
mbam-log-2008-10-27 (13-01-14).txt
Typ skenu: Rychlý sken
Objektu skenováno: 50051
Uplynulý cas: 6 minute(s), 49 second(s)
Infikované procesy pameti: 2
Infikované pametové moduly: 2
Infikované klíce registru: 7
Infikované hodnoty registru: 3
Infikované položky dat registru: 14
Infikované složky: 3
Infikované soubory: 17
Infikované procesy pameti:
C:\Program Files\Antivirus 2009\av2009.exe (Rogue.Antivirus2008) -> No action taken.
C:\Program Files\Applications\wcs.exe (Trojan.Zlob) -> No action taken.
Infikované pametové moduly:
C:\WINDOWS\system32\rgubftfo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\tuvUOEvU.dll (Trojan.Vundo.H) -> No action taken.
Infikované klíce registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a3aadd5c-8b83-4c71-9d0b-52b64eb5cfda} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a3aadd5c-8b83-4c71-9d0b-52b64eb5cfda} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Warning Center (Trojan.Zlob) -> No action taken.
HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> No action taken.
Infikované hodnoty registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\b44b299f (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\32449076910666290701020290823364 (Rogue.Antivirus2008) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\quicktimetask (Trojan.Zlob) -> No action taken.
Infikované položky dat registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\tuvuoevu -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System (Rootkit.DNSChanger.H) -> Data: kdfvo.exe -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\tuvuoevu -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{45989193-243c-4f1d-8623-692e8904028f}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{45989193-243c-4f1d-8623-692e8904028f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{cdb3f7f6-fe7d-42d5-8c2b-13865ea19aec}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{cdb3f7f6-fe7d-42d5-8c2b-13865ea19aec}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{45989193-243c-4f1d-8623-692e8904028f}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{45989193-243c-4f1d-8623-692e8904028f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{cdb3f7f6-fe7d-42d5-8c2b-13865ea19aec}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{cdb3f7f6-fe7d-42d5-8c2b-13865ea19aec}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{45989193-243c-4f1d-8623-692e8904028f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{cdb3f7f6-fe7d-42d5-8c2b-13865ea19aec}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{cdb3f7f6-fe7d-42d5-8c2b-13865ea19aec}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
Infikované složky:
C:\resycled (Trojan.DNSChanger) -> No action taken.
C:\Program Files\Antivirus 2009 (Rogue.Antivirus2008) -> No action taken.
C:\Documents and Settings\Pavel\Nabídka Start\Antivirus 2009 (Rogue.Antivirus2008) -> No action taken.
Infikované soubory:
C:\WINDOWS\system32\tuvUOEvU.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\UvEOUvut.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\UvEOUvut.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\rgubftfo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\oftfbugr.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\kdfvo.exe (Rootkit.DNSChanger.H) -> No action taken.
C:\WINDOWS\system32\scui.cpl (Rogue.XPantivirus) -> No action taken.
C:\Documents and Settings\Pavel\Local Settings\Temp\_tc\keygen.exe (Trojan.Downloader) -> No action taken.
C:\resycled\boot.com (Trojan.DNSChanger) -> No action taken.
C:\Program Files\Antivirus 2009\av2009.exe (Rogue.Antivirus2008) -> No action taken.
C:\Documents and Settings\Pavel\Nabídka Start\Antivirus 2009\Antivirus 2009.lnk (Rogue.Antivirus2008) -> No action taken.
C:\Documents and Settings\Pavel\Nabídka Start\Antivirus 2009\Uninstall Antivirus 2009.lnk (Rogue.Antivirus2008) -> No action taken.
C:\Program Files\Applications\wcs.exe (Trojan.Zlob) -> No action taken.
C:\Program Files\Applications\wcu.exe (Trojan.Zlob) -> No action taken.
C:\Documents and Settings\Pavel\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk (Rogue.Antivirus2008) -> No action taken.
C:\WINDOWS\Temp\tempo-655.tmp (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\Temp\tempo-67D.tmp (Trojan.FakeAlert) -> No action taken.
/antivirus 2009 přidán do názvu topicu. mem.
Malwarebytes' Anti-Malware 1.30
Verze databáze: 1306
Windows 5.1.2600 Service Pack 3
27.10.2008 13:01:30
mbam-log-2008-10-27 (13-01-14).txt
Typ skenu: Rychlý sken
Objektu skenováno: 50051
Uplynulý cas: 6 minute(s), 49 second(s)
Infikované procesy pameti: 2
Infikované pametové moduly: 2
Infikované klíce registru: 7
Infikované hodnoty registru: 3
Infikované položky dat registru: 14
Infikované složky: 3
Infikované soubory: 17
Infikované procesy pameti:
C:\Program Files\Antivirus 2009\av2009.exe (Rogue.Antivirus2008) -> No action taken.
C:\Program Files\Applications\wcs.exe (Trojan.Zlob) -> No action taken.
Infikované pametové moduly:
C:\WINDOWS\system32\rgubftfo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\tuvUOEvU.dll (Trojan.Vundo.H) -> No action taken.
Infikované klíce registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a3aadd5c-8b83-4c71-9d0b-52b64eb5cfda} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a3aadd5c-8b83-4c71-9d0b-52b64eb5cfda} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Warning Center (Trojan.Zlob) -> No action taken.
HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> No action taken.
Infikované hodnoty registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\b44b299f (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\32449076910666290701020290823364 (Rogue.Antivirus2008) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\quicktimetask (Trojan.Zlob) -> No action taken.
Infikované položky dat registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\tuvuoevu -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System (Rootkit.DNSChanger.H) -> Data: kdfvo.exe -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\tuvuoevu -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{45989193-243c-4f1d-8623-692e8904028f}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{45989193-243c-4f1d-8623-692e8904028f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{cdb3f7f6-fe7d-42d5-8c2b-13865ea19aec}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{cdb3f7f6-fe7d-42d5-8c2b-13865ea19aec}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{45989193-243c-4f1d-8623-692e8904028f}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{45989193-243c-4f1d-8623-692e8904028f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{cdb3f7f6-fe7d-42d5-8c2b-13865ea19aec}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{cdb3f7f6-fe7d-42d5-8c2b-13865ea19aec}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{45989193-243c-4f1d-8623-692e8904028f}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{cdb3f7f6-fe7d-42d5-8c2b-13865ea19aec}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{cdb3f7f6-fe7d-42d5-8c2b-13865ea19aec}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.150,85.255.112.148 -> No action taken.
Infikované složky:
C:\resycled (Trojan.DNSChanger) -> No action taken.
C:\Program Files\Antivirus 2009 (Rogue.Antivirus2008) -> No action taken.
C:\Documents and Settings\Pavel\Nabídka Start\Antivirus 2009 (Rogue.Antivirus2008) -> No action taken.
Infikované soubory:
C:\WINDOWS\system32\tuvUOEvU.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\UvEOUvut.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\UvEOUvut.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\rgubftfo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\oftfbugr.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\kdfvo.exe (Rootkit.DNSChanger.H) -> No action taken.
C:\WINDOWS\system32\scui.cpl (Rogue.XPantivirus) -> No action taken.
C:\Documents and Settings\Pavel\Local Settings\Temp\_tc\keygen.exe (Trojan.Downloader) -> No action taken.
C:\resycled\boot.com (Trojan.DNSChanger) -> No action taken.
C:\Program Files\Antivirus 2009\av2009.exe (Rogue.Antivirus2008) -> No action taken.
C:\Documents and Settings\Pavel\Nabídka Start\Antivirus 2009\Antivirus 2009.lnk (Rogue.Antivirus2008) -> No action taken.
C:\Documents and Settings\Pavel\Nabídka Start\Antivirus 2009\Uninstall Antivirus 2009.lnk (Rogue.Antivirus2008) -> No action taken.
C:\Program Files\Applications\wcs.exe (Trojan.Zlob) -> No action taken.
C:\Program Files\Applications\wcu.exe (Trojan.Zlob) -> No action taken.
C:\Documents and Settings\Pavel\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk (Rogue.Antivirus2008) -> No action taken.
C:\WINDOWS\Temp\tempo-655.tmp (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\Temp\tempo-67D.tmp (Trojan.FakeAlert) -> No action taken.
/antivirus 2009 přidán do názvu topicu. mem.