Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.orgDatabase version: v2012.12.05.01
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
Kolby :: KOLBY-PC [administrator]
12/4/2012 7:20:22 PM
mbam-log-2012-12-05 (01-01-33).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 498346
Time elapsed: 5 hour(s), 17 minute(s), 14 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 1
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command| (Hijack.StartMenuInternet) -> Bad: ("C:\Windows\system32\config\systemprofile\AppData\Local\npy.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> No action taken.
Folders Detected: 0
(No malicious items detected)
Files Detected: 35
C:\Program Files\Vuze\VuzeFW.exe (Trojan.Agent) -> No action taken.
C:\Program Files\TabletPlugins\ieUninstall.exe (Trojan.Agent) -> No action taken.
C:\Program Files\TabletPlugins\npUninstall.exe (Trojan.Agent) -> No action taken.
C:\ProgramData\AWUTRIMUGB.del (Rogue.FakeHDD) -> No action taken.
C:\ProgramData\ODLHVHV6.del (Trojan.Downloader) -> No action taken.
C:\ProgramData\UBXENVVXOG.del (Rogue.FakeHDD) -> No action taken.
C:\ProgramData\UICSR.del (Trojan.Agent.UAGen) -> No action taken.
C:\ProgramData\Microsoft\Windows\DRM\1D27.tmp (Trojan.Agent) -> No action taken.
C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> No action taken.
C:\Windows\Installer\{fc43dfe1-5ec6-c399-2be7-ac09d84a2d3c}\n (Trojan.Zaccess) -> No action taken.
C:\Windows\Installer\{fc43dfe1-5ec6-c399-2be7-ac09d84a2d3c}\U\00000004.@ (Rootkit.Zaccess) -> No action taken.
C:\Windows\Installer\{fc43dfe1-5ec6-c399-2be7-ac09d84a2d3c}\U\00000008.@ (Trojan.Dropper.BCMiner) -> No action taken.
C:\Windows\Installer\{fc43dfe1-5ec6-c399-2be7-ac09d84a2d3c}\U\000000cb.@ (Rootkit.0Access) -> No action taken.
C:\Windows\System32\SVC2DLL.del (Trojan.Cridex) -> No action taken.
C:\Windows\System32\config\systemprofile\0.03530300178772805.exe (Trojan.Agent) -> No action taken.
C:\Windows\System32\config\systemprofile\wgsdgsdgdsgsd.exe (Trojan.Ransom) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\Local\aowfkfyd.exe (Trojan.FakeAlert) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\Local\{fc43dfe1-5ec6-c399-2be7-ac09d84a2d3c}\n (Trojan.Zaccess) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\629d366f-77baf331 (Rogue.FakeHDD) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\Roaming\IRDCOM.del (Trojan.Agent.UAGen) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\Roaming\Adobe\SP.del (Trojan.Proxy) -> No action taken.
C:\Users\Kolby\AppData\Roaming\ISECURITY.del (Trojan.Agent) -> No action taken.
C:\Users\Kolby\AppData\Roaming\Toew\REUMN.del (Spyware.Zbot) -> No action taken.
C:\Users\Kolby\AppData\Roaming\Voetw\ERYN.del (Trojan.Agent) -> No action taken.
C:\System Volume Information\SystemRestore\FRStaging\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\SystemRestore\FRStaging\Windows\Installer\{fc43dfe1-5ec6-c399-2be7-ac09d84a2d3c}\n (Rootkit.0Access) -> No action taken.
C:\System Volume Information\SystemRestore\FRStaging\Windows\Installer\{fc43dfe1-5ec6-c399-2be7-ac09d84a2d3c}\U\00000008.@ (Trojan.Dropper.BCMiner) -> No action taken.
C:\System Volume Information\SystemRestore\FRStaging\Windows\Installer\{fc43dfe1-5ec6-c399-2be7-ac09d84a2d3c}\U\80000000.@ (Trojan.Sirefef) -> No action taken.
C:\System Volume Information\SystemRestore\FRStaging\Windows\System32\FastUserSwitchingCompatibilityex.dll (Trojan.Agent) -> No action taken.
C:\System Volume Information\SystemRestore\FRStaging\Windows\System32\mdhcp32.dll (Spyware.Agent) -> No action taken.
C:\System Volume Information\SystemRestore\FRStaging\Windows\System32\sname (Spyware.Agent) -> No action taken.
C:\Users\Kolby\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bbjciahceamgodcoidkjpchnokgfpphh_0.localstorage (PUP.Funmoods) -> No action taken.
C:\Users\Kolby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bbjciahceamgodcoidkjpchnokgfpphh_0.localstorage (PUP.Funmoods) -> No action taken.
C:\Windows\System32\svc2dll.dat (Malware.Trace) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\Roaming\Ms_dir_\msvcrt.exe (Backdoor.Agent) -> No action taken.
(end)