Chalani tak sme to skusili uz mu aj ten facebook ide v pohode.Ale je tu stale ten problem s tou Avirou.Aku je dat prec.Chcem tam nainstalovat Toho KAsperskeho ale hlasi ze ju musim unistall ale nikde ju nemozem najst robo to od vtedy ako tam chytil ten virus s facebooku odvtedy Tu Aviru odpisalo...posielam ten log...
odstránene hrozby...
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Verzia databázy: 7641
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
3. 9. 2011 11:34:22
mbam-log-2011-09-03 (11-34-22).txt
Typ kontroly: Rýchla kontrola
Objektov kontrolovaných: 190688
Uplynutý čas: 1 min, 57 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 6
Infikované registračné hodnoty: 1
Infikované položky registračných dát: 3
Infikované priečinky: 1
Infikované súbory: 14
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
HKEY_LOCAL_MACHINE\SOFTWARE\sysdriver32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\systeminfog (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\SERVICES32.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\wxpdrivers (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvsysdriver32 (Trojan.Agent) -> Quarantined and deleted successfully.
Infikované registračné hodnoty:
HKEY_LOCAL_MACHINE\SOFTWARE\Services32.exe\close (Trojan.Agent) -> Value: close -> Quarantined and deleted successfully.
Infikované položky registračných dát:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Infikované priečinky:
c:\Windows\rpcminer (Trojan.BCMiner) -> Quarantined and deleted successfully.
Infikované súbory:
c:\Windows\rpcminer\bitcoinmineropencl.cl (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinminercuda_10.cubin (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinminercuda_11.cubin (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinminercuda_20.cubin (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\cudart32_32_16.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\curllib.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\libeay32.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\libsasl.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\openldap.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-4way.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-cpu.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-cuda.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-opencl.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\ssleay32.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
ComboFix
ComboFix 11-09-02.04 - shark . 09. 2011 12:48:03.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.4094.2790 [GMT 2:00]
Running from: c:\users\shark\AppData\Local\Temp\Rar$EX00.523\ComboFix\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\users\shark\AppData\Roaming\inst.exe
c:\windows\btc_client_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\proc_list1.log
c:\windows\rpcminer.rar
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\SysWow64\simdpp.dll
c:\windows\update.1
c:\windows\update.2
c:\windows\update.5.0
c:\windows\update.7.1
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
c:\windows\winsetupapi.log
.
.
((((((((((((((((((((((((( Files Created from 2011-08-03 to 2011-09-03 )))))))))))))))))))))))))))))))
.
.
2011-09-03 10:51 . 2011-09-03 10:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-09-02 15:00 . 2011-09-02 15:00 -------- d-----w- c:\users\shark\AppData\Roaming\Malwarebytes
2011-09-02 14:59 . 2011-07-06 17:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-09-02 14:59 . 2011-09-02 14:59 -------- d-----w- c:\programdata\Malwarebytes
2011-09-02 14:59 . 2011-09-02 14:59 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-09-02 14:59 . 2011-07-06 17:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-29 14:24 . 2011-08-29 14:25 -------- d-----w- c:\users\Guest
2011-08-29 14:02 . 2011-08-29 14:02 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-08-29 07:34 . 2011-08-29 07:34 -------- d-----w- c:\program files (x86)\AVG
2011-08-26 17:05 . 2011-08-26 17:05 -------- d-----w- C:\$AVG
2011-08-26 16:30 . 2011-08-26 16:30 -------- d-----w- c:\users\shark\AppData\Roaming\AVG10
2011-08-26 16:28 . 2011-09-03 10:14 -------- d-----w- c:\programdata\AVG10
2011-08-26 16:28 . 2011-09-03 10:13 -------- d-----w- c:\windows\system32\drivers\AVG
2011-08-26 16:06 . 2011-08-26 16:22 -------- d-----w- c:\programdata\AVAST Software
2011-08-26 16:06 . 2011-08-26 16:06 -------- d-----w- c:\program files\AVAST Software
2011-08-26 15:57 . 2011-08-16 06:48 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A2FF79A4-71DB-4034-8A51-AD43AB539929}\mpengine.dll
2011-08-25 18:23 . 2011-08-25 18:23 22567 ----a-w- c:\programdata\1314296490.bdinstall.bin
2011-08-25 18:21 . 2011-08-25 18:21 -------- d-----w- c:\program files\Common Files\Bitdefender
2011-08-25 18:21 . 2011-08-25 18:21 -------- d-----w- c:\program files (x86)\Common Files\Bitdefender
2011-08-25 18:19 . 2011-08-27 15:37 -------- d-----w- c:\users\shark\AppData\Roaming\QuickScan
2011-08-25 17:47 . 2011-08-15 11:19 34624 ----a-w- c:\windows\system32\TURegOpt.exe
2011-08-25 17:47 . 2011-08-15 11:13 25920 ----a-w- c:\windows\system32\authuitu.dll
2011-08-25 17:47 . 2011-08-15 11:13 21312 ----a-w- c:\windows\SysWow64\authuitu.dll
2011-08-25 17:47 . 2011-08-15 11:13 36160 ----a-w- c:\windows\system32\uxtuneup.dll
2011-08-25 17:47 . 2011-08-15 11:13 29504 ----a-w- c:\windows\SysWow64\uxtuneup.dll
2011-08-25 17:47 . 2011-08-25 17:47 -------- d-----w- c:\program files (x86)\TuneUp Utilities 2011
2011-08-25 17:46 . 2011-08-25 17:47 -------- d-----w- c:\programdata\TuneUp Software
2011-08-25 17:46 . 2011-08-25 17:46 -------- d-sh--w- c:\programdata\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-08-25 17:34 . 2011-08-25 19:14 -------- d--h--w- c:\windows\update.tray-7-0
2011-08-25 17:34 . 2011-08-25 19:14 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-08-25 17:32 . 2011-07-04 11:43 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-08-25 17:09 . 2011-08-25 17:09 -------- d--h--w- c:\windows\update.8.1
2011-08-25 17:08 . 2011-08-25 17:08 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2011-08-24 15:56 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-24 15:56 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-23 14:13 . 2011-08-25 16:53 -------- d-----w- c:\programdata\PC Tools
2011-08-20 11:55 . 2011-08-20 11:55 -------- d-----w- c:\windows\1C4551A64743409391E41477CD655043.TMP
2011-08-20 09:40 . 2011-08-20 09:40 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-20 09:31 . 2011-08-20 09:31 -------- d--h--w- c:\programdata\Common Files
2011-08-20 09:22 . 2011-08-25 19:14 -------- d--h--w- c:\windows\update.tray-12-0
2011-08-20 09:22 . 2011-08-25 19:14 -------- d--h--w- c:\windows\update.tray-12-0-lnk
2011-08-20 09:16 . 2011-09-03 10:13 -------- d-----w- c:\programdata\MFAData
2011-08-19 18:23 . 2011-08-25 18:07 -------- d-----w- c:\windows\ufa
2011-08-19 18:14 . 2011-08-25 17:38 246272 ----a-w- c:\windows\unrar.exe
2011-08-19 18:12 . 2011-08-25 17:36 -------- d-----w- c:\windows\av_ico
2011-08-19 18:11 . 2011-08-25 19:14 -------- d--h--w- c:\windows\update.tray-8-0-lnk
2011-08-19 18:11 . 2011-08-25 19:14 -------- d--h--w- c:\windows\update.tray-8-0
2011-08-16 15:50 . 2011-08-08 08:00 74752 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2011-08-16 15:50 . 2011-07-16 14:17 151552 ----a-w- c:\windows\SysWow64\ac3acm.acm
2011-08-16 15:50 . 2011-06-24 14:44 243200 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2011-08-16 15:50 . 2011-06-24 14:28 650752 ----a-w- c:\windows\SysWow64\xvidcore.dll
2011-08-16 15:50 . 2010-11-03 18:08 237568 ----a-w- c:\windows\SysWow64\yv12vfw.dll
2011-08-16 15:50 . 2006-10-18 18:05 232448 ----a-w- c:\windows\SysWow64\mp3fhg.acm
2011-08-16 15:50 . 2002-08-22 04:00 413760 ----a-w- c:\windows\SysWow64\DivXc32f.dll
2011-08-16 15:50 . 2002-08-01 09:03 413760 ----a-w- c:\windows\SysWow64\DivXc32.dll
2011-08-16 15:50 . 2001-02-25 01:19 287744 ----a-w- c:\windows\SysWow64\divxa32.acm
2011-08-14 12:47 . 2005-06-24 14:24 438272 ----a-r- c:\windows\SysWow64\vp6vfw.dll
2011-08-14 12:47 . 2004-12-10 07:06 327680 ----a-w- c:\windows\SysWow64\vp6dec.ax
2011-08-14 12:47 . 2005-11-13 21:22 757760 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2011-08-14 12:47 . 2005-11-13 21:22 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2011-08-14 12:47 . 2005-11-13 21:21 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2011-08-14 12:47 . 2005-11-13 21:20 204800 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2011-08-14 12:47 . 2005-11-13 21:19 65024 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2011-08-14 12:47 . 2005-11-13 21:19 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2011-08-14 12:47 . 2005-11-13 21:16 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2011-08-14 12:47 . 2011-08-14 12:47 331908 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2011-08-14 12:47 . 2011-08-14 12:47 200836 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2011-08-12 16:17 . 2011-09-02 16:43 -------- d-----w- c:\program files (x86)\JDownloader
2011-08-10 16:06 . 2011-06-23 05:43 5561216 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-10 16:06 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-08-10 16:06 . 2011-06-23 04:33 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-20 09:30 . 2011-04-22 12:11 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-07-20 09:30 . 2011-04-22 12:11 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-07-19 03:05 . 2010-09-28 06:21 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-16 04:26 . 2011-08-10 16:07 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-06-11 03:07 . 2011-07-13 16:23 3137536 ----a-w- c:\windows\system32\win32k.sys
2011-06-07 14:56 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-06-07 14:56 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-06-05 15:10 . 2011-06-05 15:10 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-06-15 15141768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-10-28 2763776]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-05-04 102400]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 AntiVirWebService;Avira AntiVir WebGuard;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [x]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-01-27 2253688]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-08-15 2027840]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-06-06 11856]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://start.facemoods.com/?a=ddrnw
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\shark\AppData\Roaming\Mozilla\Firefox\Profiles\fl1zbh1l.default\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0b,51,48,9c,f7,95,29,41,a7,3f,49,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0b,51,48,9c,f7,95,29,41,a7,3f,49,\
.
[HKEY_USERS\S-1-5-21-3898257279-3220266764-3061120529-1000\Software\SecuROM\License information*]
"datasecu"=hex:be,55,3e,53,f3,41,92,c4,75,8b,14,2c,ad,b1,3d,1e,b3,4d,d3,69,cd,
0d,e3,72,42,1f,1f,28,af,2c,41,29,1e,ba,ba,4e,d4,ff,dd,c4,8d,29,b6,e7,30,dc,\
"rkeysecu"=hex:b2,ce,31,15,b2,ac,40,2e,d7,2e,22,89,fe,50,38,18
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
c:\program files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
.
**************************************************************************
.
Completion time: 2011-09-03 12:55:58 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-03 10:55
.
Pre-Run: 185 374 838 784 bytes free
Post-Run: 184 838 348 800 bytes free
.
- - End Of File - - 542447C851510E3A749A275AD1E5F7A2