New
#11
Nothing new there, then! ;-)
Nothing new there, then! ;-)
Malwarebytes result
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
Malwarebytes : Free anti-malware download
Database version: v2013.06.14.04
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Luka :: MAJA-PC [administrator]
Protection: Enabled
14.6.2013 19:15:38
mbam-log-2013-06-14 (19-15-38).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 415709
Time elapsed: 1 hour(s), 3 minute(s), 48 second(s)
Memory Processes Detected: 1
C:\Windows\System32\dmwu.exe (PUP.InstallBrain) -> 1616 -> No action taken.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 4
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110111181125} (PUP.CrossRider.BCA) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111181125} (PUP.CrossRider.BCA) -> No action taken.
HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService (PUP.InstallBrain) -> No action taken.
HKCU\Software\DC3_FEXEC (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Detected: 2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Policies (Backdoor.Agent.PGen) -> Data: C:\Windows\system32\install\server.exe -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|HKLM (Backdoor.HMCPol.Gen) -> Data: C:\Windows\system32\install\server.exe -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 8
C:\Users\Luka\AppData\Roaming\dclogs (Stolen.Data) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C} (Adware.Zwangi) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C}\chrome (Adware.Zwangi) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C}\defaults (Adware.Zwangi) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C}\defaults\preferences (Adware.Zwangi) -> Quarantined and deleted successfully.
C:\Users\Luka\Local Settings\Application Data\RavenBleuSA (Adware.Hotbar.RB) -> Quarantined and deleted successfully.
C:\Users\Luka\Local Settings\Application Data\RavenBleuSA\bin (Adware.Hotbar.RB) -> Quarantined and deleted successfully.
C:\Users\Luka\Local Settings\Application Data\RavenBleuSA\bin\1.0.13.0 (Adware.Hotbar.RB) -> Quarantined and deleted successfully.
Files Detected: 16
C:\Windows\System32\dmwu.exe (PUP.InstallBrain) -> No action taken.
C:\$Recycle.Bin\S-1-5-21-1145045425-4043479808-2266054014-1001\$R86ZT86.com (Backdoor.Agent.DCRSAGen) -> Quarantined and deleted successfully.
C:\$Recycle.Bin\S-1-5-21-1145045425-4043479808-2266054014-1001\$RJMQW1O.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\$Recycle.Bin\S-1-5-21-1145045425-4043479808-2266054014-1001\$RMXHVMJ.com (Backdoor.Agent.DCRSAGen) -> Quarantined and deleted successfully.
C:\Users\Luka\AppData\Local\Temp\Fo02AbRp49.exe (PasswordStealer.MSIL) -> Quarantined and deleted successfully.
C:\Users\Luka\AppData\Local\Temp\Nd7w9YEk5g.exe (PasswordStealer.MSIL) -> Quarantined and deleted successfully.
C:\Users\Luka\AppData\Local\Temp\Wa37LxMy8k.exe (PasswordStealer.MSIL) -> Quarantined and deleted successfully.
C:\Users\Luka\AppData\Local\Temp\Bud hack\Bud hack.com (Backdoor.Agent.DCRSAGen) -> Quarantined and deleted successfully.
C:\Users\Luka\AppData\Local\Temp\Rar$EX00.353\Budspawner Tools v.2.1.4.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\Users\Luka\Desktop\Things\Bud hack.com (Backdoor.Agent.DCRSAGen) -> Quarantined and deleted successfully.
C:\Users\Luka\AppData\Roaming\dclogs\2013-06-09-1.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\Luka\AppData\Roaming\dclogs\2013-06-14-6.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C}\chrome.manifest (Adware.Zwangi) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C}\install.rdf (Adware.Zwangi) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C}\chrome\basicscan.jar (Adware.Zwangi) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C}\defaults\preferences\prefs.js (Adware.Zwangi) -> Quarantined and deleted successfully.
(end)
Hey HoelDP i did all that you said about Malwarebytes and it didnt worked
Malwarebytes Anti Malware sure worked quite well.
It found 24 items and deleted/quarantined them.
Or did I read the report incorrectly?
RevCrew1
почему вы не создание нового потока?
Translation : Why aren't you creating a new thread ?
Uredu VistaKing napravicu novu temu
translate:Ok VistaKing i will make a new thread
All of those were unticked shoud i clean them?