Anda di halaman 1dari 12

============================== Log File of Smadav 2011 Rev. 8.

6 ============================== Scanning Results : => Time & Date : 02:59:57, on 09-14-2011 => Finishing Time : 1 hour,15 minutes => Folder Scanned :37123 => File Scanned : 298935 => File Detected : 36 => File Cleaned : 12 => Value Scanned : 971 => Value Detected: 7 => Value Fixed: 7 => Path Scanned: 1167 => Path Hidden: 41 => Path Unhidden: 8 ============================== Before Scanning ============================== Suspected Paths : => Fine(Level 2) as : 1 Process -C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2 011_64server.exe => Fine(Level 2) as : 1 Process -C:\Program Files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3 dsmax2011_32server.exe => Fine(Level 2) as : 2 Process -C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.ex e => Maybe Virus(Level 5) as : 5 Process -C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => Fine(Level 1) as : 1 Process -C:\Windows\system32\wlanext.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\PHotkey\AsLdrSrv.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Atheros\Ath_CoexAgent.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Bonjour\mDNSResponder.exe => Fine(Level 1) as : 1 Process -C:\Program Files\Time Stamp\IBP\FsLoader.exe => Fine(Level 1) as : 1 Process -C:\Program Files\Time Stamp\IBP\VBPTask.exe => Fine(Level 1) as : 1 Process -C:\Program Files\Time Stamp\IBP\RITTray.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\PHotkey\PHotkey.exe => Fine(Level 1) as : 1 Process -C:\Windows\SysWOW64\NLSSRV32.EXE => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\PHotkey\MsgTranAgt.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.ex e => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.ex

e => Fine(Level 1) as : 1 Process, 1 Startup -C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe => Fine(Level 1) as : 1 Process, 1 Startup -C:\Program Files (x86)\Internet Download Manager\IDMan.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.e xe => Fine(Level 1) as : 1 Process, 1 Startup -C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Ap plication\nusb3mon.exe => Fine(Level 1) as : 1 Process, 1 Startup -C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\PHotkey\MsOsd.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\ CVHSVC.EXE => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.e xe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.e xe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Winamp\winamp.exe => Fine(Level 1) as : 1 Process -D:\Software\avira_antivir_personal_en.exe => Fine(Level 1) as : 1 Process -C:\Users\Far\AppData\Local\Temp\RarSFX0\presetup.exe => Fine(Level 1) as : 1 Process -C:\Users\Far\AppData\Local\Temp\RarSFX0\setup.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe => Fine(Level 1) as : 1 Process, 1 Startup -C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Avira\AntiVir Desktop\avconfig.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe => Fine(Level 1) as : 1 Process, 1 Startup -C:\Program Files (x86)\Smadav\SMRTP.exe => Fine(Level 1) as : 1 Startup -C:\Program Files\Windows Sidebar\sidebar.exe => Fine(Level 1) as : 1 Startup -C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe => Fine(Level 1) as : 1 Startup -C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\V ersionCueCS3Tray.exe => Fine(Level 1) as : 1 Startup -C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe => Fine(Level 1) as : 1 Startup

-c:\program files (x86)\Adobe\acrobat 8.0\Acrobat\adobecollabsync.exe => Fine(Level 1) as : 1 Startup -C:\..\program files (x86)\Adobe\acrobat 8.0\Acrobat\adobecollabsync.exe => Fine(Level 1) as : 1 Startup -c:\program files\SRS Labs\srs control panel\srspanel_64.exe => Fine(Level 1) as : 1 Startup -C:\..\program files\SRS Labs\srs control panel\srspanel_64.exe => Fine(Level 1) as : 1 Startup -c:\Windows\installer\{f3c66ec8-2f33-452d-9cff-e8c886b3ecc4}\newshortcut5_0ce 52f6bfc2446469e6195e88305cf85.exe => Unknown(Level 3) as : 2 Startup -c:\program files (x86)\Google\Update\googleupdate.exe Running Processes : => N/A => N/A => N/A => N/A => N/A => C:\Windows\system32\wininit.exe => N/A => N/A => N/A => N/A => C:\Windows\system32\svchost.exe => N/A => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => N/A => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => C:\Windows\system32\wlanext.exe => N/A => C:\Program Files (x86)\PHotkey\AsLdrSrv.exe => N/A => N/A => N/A => N/A => C:\Program Files (x86)\Atheros\Ath_CoexAgent.exe => N/A => C:\Program Files (x86)\Bonjour\mDNSResponder.exe => N/A => C:\Program Files\Time Stamp\IBP\FsLoader.exe => N/A => C:\Program Files\Time Stamp\IBP\VBPTask.exe => N/A => C:\Windows\explorer.exe => C:\Windows\system32\taskeng.exe => C:\Program Files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3d smax2011_32server.exe => C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax20 11_64server.exe => C:\Program Files\Time Stamp\IBP\RITTray.exe => C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe => C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe => C:\Program Files (x86)\PHotkey\PHotkey.exe => N/A

=> N/A => N/A => C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe => C:\Windows\SysWOW64\NLSSRV32.EXE => C:\Program Files (x86)\PHotkey\MsgTranAgt.exe => N/A => N/A => N/A => N/A => N/A => C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe => N/A => C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe => N/A => C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe => C:\Program Files (x86)\Internet Download Manager\IDMan.exe => C:\Windows\system32\svchost.exe => N/A => C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.ex e => N/A => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\App lication\nusb3mon.exe => N/A => C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe => N/A => N/A => N/A => N/A => C:\Program Files (x86)\PHotkey\MsOsd.exe => C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\C VHSVC.EXE => C:\Windows\system32\SearchIndexer.exe => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => N/A => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.ex e => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.ex e => C:\Windows\system32\svchost.exe => N/A => C:\Program Files (x86)\Winamp\winamp.exe => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => D:\Software\avira_antivir_personal_en.exe => C:\Users\Far\AppData\Local\Temp\RarSFX0\presetup.exe => C:\Users\Far\AppData\Local\Temp\RarSFX0\setup.exe => C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe => N/A => N/A => C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe => C:\Program Files (x86)\Avira\AntiVir Desktop\avconfig.exe

=> => => e => => => =>

C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe C:\Users\Far\AppData\Roaming\IDM\Smadav 2011 Rev. 8.6\Smadav 2011 Rev. 8.6.ex C:\Windows\explorer.exe C:\Windows\system32\SearchProtocolHost.exe C:\Program Files (x86)\Smadav\SMRTP.exe C:\Windows\system32\SearchFilterHost.exe

============================== After Scanning ============================== Suspected Paths : => Fine(Level 2) as : 1 Process -C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2 011_64server.exe => Fine(Level 2) as : 1 Process -C:\Program Files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3 dsmax2011_32server.exe => Fine(Level 2) as : 2 Process -C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.ex e => Maybe Virus(Level 5) as : 5 Process -C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => Fine(Level 1) as : 1 Process -C:\Windows\system32\wlanext.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\PHotkey\AsLdrSrv.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Atheros\Ath_CoexAgent.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Bonjour\mDNSResponder.exe => Fine(Level 1) as : 1 Process -C:\Program Files\Time Stamp\IBP\FsLoader.exe => Fine(Level 1) as : 1 Process -C:\Program Files\Time Stamp\IBP\VBPTask.exe => Fine(Level 1) as : 1 Process -C:\Program Files\Time Stamp\IBP\RITTray.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\PHotkey\PHotkey.exe => Fine(Level 1) as : 1 Process -C:\Windows\SysWOW64\NLSSRV32.EXE => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\PHotkey\MsgTranAgt.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.ex e => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.ex e => Fine(Level 1) as : 1 Process, 1 Startup -C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe => Fine(Level 1) as : 1 Process, 1 Startup -C:\Program Files (x86)\Internet Download Manager\IDMan.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.e

xe => Fine(Level 1) as : 1 Process, 1 Startup -C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Ap plication\nusb3mon.exe => Fine(Level 1) as : 1 Process, 1 Startup -C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\PHotkey\MsOsd.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\ CVHSVC.EXE => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.e xe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.e xe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Winamp\winamp.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe => Fine(Level 1) as : 1 Process, 1 Startup -C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe => Fine(Level 1) as : 1 Process, 1 Startup -C:\Program Files (x86)\Smadav\SMRTP.exe => Fine(Level 1) as : 1 Process -C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe => Fine(Level 1) as : 1 Process -C:\Windows\SysWOW64\rundll32.exe => Fine(Level 1) as : 1 Startup -C:\Program Files\Windows Sidebar\sidebar.exe => Fine(Level 1) as : 1 Startup -C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe => Fine(Level 1) as : 1 Startup -C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\V ersionCueCS3Tray.exe => Fine(Level 1) as : 1 Startup -C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe => Fine(Level 1) as : 1 Startup -c:\program files (x86)\Adobe\acrobat 8.0\Acrobat\adobecollabsync.exe => Fine(Level 1) as : 1 Startup -C:\..\program files (x86)\Adobe\acrobat 8.0\Acrobat\adobecollabsync.exe => Fine(Level 1) as : 1 Startup -c:\program files\SRS Labs\srs control panel\srspanel_64.exe => Fine(Level 1) as : 1 Startup -C:\..\program files\SRS Labs\srs control panel\srspanel_64.exe => Fine(Level 1) as : 1 Startup -c:\Windows\installer\{f3c66ec8-2f33-452d-9cff-e8c886b3ecc4}\newshortcut5_0ce 52f6bfc2446469e6195e88305cf85.exe => Unknown(Level 3) as : 2 Startup -c:\program files (x86)\Google\Update\googleupdate.exe Running Processes : => N/A => N/A => N/A => N/A => N/A

=> C:\Windows\system32\wininit.exe => N/A => N/A => N/A => N/A => C:\Windows\system32\svchost.exe => N/A => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => N/A => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => C:\Windows\system32\wlanext.exe => N/A => C:\Program Files (x86)\PHotkey\AsLdrSrv.exe => N/A => N/A => N/A => N/A => C:\Program Files (x86)\Atheros\Ath_CoexAgent.exe => N/A => C:\Program Files (x86)\Bonjour\mDNSResponder.exe => N/A => C:\Program Files\Time Stamp\IBP\FsLoader.exe => N/A => C:\Program Files\Time Stamp\IBP\VBPTask.exe => N/A => C:\Windows\explorer.exe => C:\Windows\system32\taskeng.exe => C:\Program Files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3d smax2011_32server.exe => C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax20 11_64server.exe => C:\Program Files\Time Stamp\IBP\RITTray.exe => C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe => C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe => C:\Program Files (x86)\PHotkey\PHotkey.exe => N/A => N/A => N/A => C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe => C:\Windows\SysWOW64\NLSSRV32.EXE => C:\Program Files (x86)\PHotkey\MsgTranAgt.exe => N/A => N/A => N/A => N/A => N/A => C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe => N/A => C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe => N/A => C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe => C:\Program Files (x86)\Internet Download Manager\IDMan.exe => C:\Windows\system32\svchost.exe => N/A

=> C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.ex e => N/A => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\App lication\nusb3mon.exe => N/A => C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe => N/A => N/A => N/A => N/A => C:\Program Files (x86)\PHotkey\MsOsd.exe => C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\C VHSVC.EXE => C:\Windows\system32\SearchIndexer.exe => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => C:\Windows\system32\svchost.exe => N/A => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.ex e => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.ex e => C:\Windows\system32\svchost.exe => N/A => C:\Program Files (x86)\Winamp\winamp.exe => C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe => C:\Users\Far\AppData\Roaming\IDM\Smadav 2011 Rev. 8.6\Smadav 2011 Rev. 8.6.ex e => C:\Program Files (x86)\Smadav\SMRTP.exe => C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe => N/A => N/A => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => C:\Windows\SysWOW64\rundll32.exe => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => C:\Windows\explorer.exe Detected Virus : => Sality -Infected Registry -C:\Program Files (x86)\Adobe\Adobe => Sality -Infected Registry -C:\Program Files (x86)\Adobe\Adobe => Sality -Infected Registry -C:\Program Files (x86)\Adobe\Adobe ndows\Illustrator.exe => New Heur.Packed(14) -Infected Registry -C:\Program Files\WinRAR\WinRAR.exe => Sality -Injected Exe -C:\Program Files (x86)\Adobe\Adobe

Dreamweaver CS3\dreamweaver.exe Flash CS3\Flash.exe Illustrator CS3\Support Files\Contents\Wi

Flash CS3 Video Encoder\Flash Video Encod

er.exe => Sality -Infected Shortcut -C:\Program Files (x86)\Adobe\Adobe Illustrator CS3\Adobe Illustrator CS3.lnk => Sality -Infected Shortcut -C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Design Premium CS 3\Adobe Dreamweaver CS3.lnk => Sality -Injected Exe -C:\..\program files (x86)\Adobe\adobe dreamweaver cs3\dreamweaver.exe => Sality -Infected Shortcut -C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Design Premium CS 3\Adobe Flash CS3 Professional.lnk => Sality -Injected Exe -C:\..\program files (x86)\Adobe\adobe flash cs3\Flash.exe => Sality -Infected Shortcut -C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Design Premium CS 3\Adobe Flash CS3 Video Encoder.lnk => Sality -Injected Exe -C:\..\program files (x86)\Adobe\adobe flash cs3 video encoder\flash video en coder.exe => Sality -Infected Shortcut -C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Design Premium CS 3\Adobe Illustrator CS3.lnk => Sality -Injected Exe -C:\..\program files (x86)\Adobe\adobe illustrator cs3\support files\Contents \Windows\illustrator.exe => New Heur.Packed(14) -Infected Shortcut -C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk => New Heur.Packed(14) -Infected File -C:\..\program files\WinRAR\WinRAR.exe => Sality -Infected Shortcut -C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Adobe Design Premiu m CS3\Adobe Dreamweaver CS3.lnk => Sality -Infected Shortcut -C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Adobe Design Premiu m CS3\Adobe Flash CS3 Professional.lnk => Sality -Infected Shortcut -C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Adobe Design Premiu m CS3\Adobe Flash CS3 Video Encoder.lnk => Sality -Infected Shortcut -C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Adobe Design Premiu m CS3\Adobe Illustrator CS3.lnk => New Heur.Packed(14) -Infected Shortcut -C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk => New Heur.Packed(14)

-Infected Shortcut -C:\Users\Far\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Wi nRAR.lnk => New Heur.Packed(14) -Infected File -C:\..\..\..\..\program files\WinRAR\WinRAR.exe => Sality -Injected Exe -D:\Software\Design\picasa38-setup.exe => Sality -Injected Exe -D:\Software\Design\Adobe Design Premium\Setup.exe => Sality -Injected Exe -D:\Software\Design\Adobe Design Premium\redist\WindowsServer2003-KB898715-ia 64-enu.exe => Sality -Injected Exe -D:\Software\Design\Adobe Design Premium\redist\WindowsServer2003-KB898715-x6 4-enu.exe => Sality -Injected Exe -D:\Software\Design\Adobe Design Premium\redist\WindowsServer2003-KB898715-x8 6-enu.exe => Sality -Injected Exe -D:\Software\Design\Adobe Design Premium\redist\WindowsXP-KB898715-x64-enu.ex e => Sality -Injected Exe -D:\Software\Design\Adobe Design Premium\_Crack\Dreamweaver.exe => Sality -Injected Exe -D:\Software\Design\Adobe Design Premium\_Crack\Flash Video Encoder.exe => Sality -Injected Exe -D:\Software\Design\Adobe Design Premium\_Crack\Flash.exe => Sality -Injected Exe -D:\Software\Design\Adobe Design Premium\_Crack\Illustrator.exe => Sality -Injected Exe -D:\Software\Internet\Messangger\googletalk-setup.exe => Sality -Injected Exe -D:\Software\Pelengkap\jre-6u23-windows-i586-s.exe => Sality -Injected Exe -D:\Software\Work\pdfeditor.exe Infected Registry Values : => (Default) -HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\dream weaver.exe -Sality Injected Virus Value -Value was deleted => (Default) -HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\Flash .exe -Sality Injected Virus Value

-Value was deleted => (Default) -HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\Illus trator.exe -Sality Injected Virus Value -Value was deleted => (Default) -HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\WinRA R.exe -New Heur.Packed(14) Suspected Virus Value -Value was deleted => Userinit -HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon -Different String Value -String value was fixed => (Default) -HKEY_CLASSES_ROOT\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InProcServer3 2 -Different String Value -String value was fixed => (Default) -HKEY_CLASSES_ROOT\Winrar\shell\Open\Command -New Heur.Packed(14) Suspected Virus Value -String value was fixed Hidden Files/Folders => C:\Windows -Folder => D:\Music\AlbumArtSmall.jpg -Hidden, System => D:\Music\AlbumArt_{009826E2-0AB3-4A44-8C46-F04D5F37BA6A}_Large.jpg -Hidden, System => D:\Music\AlbumArt_{009826E2-0AB3-4A44-8C46-F04D5F37BA6A}_Small.jpg -Hidden, System => D:\Music\AlbumArt_{0AEC460D-5290-4353-B894-949F61668BC8}_Large.jpg -Hidden, System => D:\Music\AlbumArt_{0AEC460D-5290-4353-B894-949F61668BC8}_Small.jpg -Hidden, System => D:\Music\AlbumArt_{0C64167E-1931-4F0E-9D15-F3BAE5F96D04}_Large.jpg -Hidden, System => D:\Music\AlbumArt_{0C64167E-1931-4F0E-9D15-F3BAE5F96D04}_Small.jpg -Hidden, System => D:\Music\AlbumArt_{1BAA9E61-22AA-4FA1-9CD4-0975E0627D20}_Large.jpg -Hidden, System => D:\Music\AlbumArt_{1BAA9E61-22AA-4FA1-9CD4-0975E0627D20}_Small.jpg -Hidden, System => D:\Music\AlbumArt_{27F3D26E-205E-436C-A582-90E1C7941DED}_Large.jpg -Hidden, System => D:\Music\AlbumArt_{27F3D26E-205E-436C-A582-90E1C7941DED}_Small.jpg -Hidden, System => D:\Music\AlbumArt_{30A639A3-79C2-4F09-A774-7AB00504FC96}_Large.jpg -Hidden, System => D:\Music\AlbumArt_{30A639A3-79C2-4F09-A774-7AB00504FC96}_Small.jpg -Hidden, System => D:\Music\AlbumArt_{7CC48B2E-25CC-411F-822F-22FC59199272}_Large.jpg -Hidden, System => D:\Music\AlbumArt_{7CC48B2E-25CC-411F-822F-22FC59199272}_Small.jpg -Hidden, System => D:\Music\AlbumArt_{9DF46E34-773A-456F-BECC-A5D99251483A}_Large.jpg -Hidden, System

=> D:\Music\AlbumArt_{9DF46E34-773A-456F-BECC-A5D99251483A}_Small.jpg -Hidden, System => D:\Music\AlbumArt_{CBD815B6-5184-44BB-8C75-12FD6FEE8A53}_Large.jpg -Hidden, System => D:\Music\AlbumArt_{CBD815B6-5184-44BB-8C75-12FD6FEE8A53}_Small.jpg -Hidden, System => D:\Music\AlbumArt_{ED247A31-3CEB-4366-9C43-BC9786E42448}_Large.jpg -Hidden, System => D:\Music\AlbumArt_{ED247A31-3CEB-4366-9C43-BC9786E42448}_Small.jpg -Hidden, System => D:\Music\Folder.jpg -Hidden, System => D:\Music\Maliq\AlbumArtSmall.jpg -Hidden, System => D:\Music\Maliq\AlbumArt_{170FE880-0D0A-45AD-8A05-564FBDAC1E5F}_Large.jpg -Hidden, System => D:\Music\Maliq\AlbumArt_{170FE880-0D0A-45AD-8A05-564FBDAC1E5F}_Small.jpg -Hidden, System => D:\Music\Maliq\AlbumArt_{536CD245-3A1F-40EA-8353-03C36F657ED9}_Large.jpg -Hidden, System => D:\Music\Maliq\AlbumArt_{536CD245-3A1F-40EA-8353-03C36F657ED9}_Small.jpg -Hidden, System => D:\Music\Maliq\AlbumArt_{D2FC53C5-3F2B-493E-841D-7C0C07B3F7B2}_Large.jpg -Hidden, System => D:\Music\Maliq\AlbumArt_{D2FC53C5-3F2B-493E-841D-7C0C07B3F7B2}_Small.jpg -Hidden, System => D:\Music\Maliq\Folder.jpg -Hidden, System => D:\Photo\Screen Munches\munch_2011_02_27_202159.jpg -Normal => D:\Photo\Screen Munches\munch_2011_03_04_001814.jpg -Normal => D:\Photo\Screen Munches\munch_2011_04_01_100404.jpg -Normal => D:\Photo\Screen Munches\munch_2011_04_02_094648.jpg -Normal => D:\Photo\Screen Munches\munch_2011_04_02_094759.jpg -Normal => D:\Photo\Screen Munches\munch_2011_04_02_094814.jpg -Normal => D:\Photo\Screen Munches\munch_2011_04_28_223002.jpg -Normal => D:\Video\ajib -Folder, Archive, Hidden => D:\Video\ajib\123 -Folder, Hidden => D:\Video\ajib\123\456 -Folder, Hidden

Anda mungkin juga menyukai