Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.orgDatabase version: v2012.08.24.02
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
User :: USER-PC [administrator]
24/08/2012 2:54:41 AM
mbam-log-2012-08-24 (02-54-41).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 231594
Time elapsed: 29 minute(s), 41 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 3
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\CLASSES\CLSID\{42AEDC87-2188-41FD-B9A3-0C966FEABEC1}\INPROCSERVER32 (Trojan.Zaccess) -> Quarantined and deleted successfully.
Registry Values Detected: 1
HKCU\SOFTWARE\CLASSES\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32| (Trojan.Zaccess) -> Data: C:\Users\User\AppData\Local\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\n. -> Quarantined and deleted successfully.
Registry Data Items Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 6
c:\users\user\appdata\roaming\xsecva\xsecva.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\$recycle.bin\s-1-5-21-825096518-3833654013-2516407325-1000\$rqcbngq\00000004.@ (Rootkit.Zaccess) -> Quarantined and deleted successfully.
c:\$recycle.bin\s-1-5-21-825096518-3833654013-2516407325-1000\$rqcbngq\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.
c:\$recycle.bin\s-1-5-21-825096518-3833654013-2516407325-1000\$rqcbngq\000000cb.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
c:\$recycle.bin\s-1-5-21-825096518-3833654013-2516407325-1000\$rqcbngq\80000000.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\$RECYCLE.BIN\S-1-5-21-825096518-3833654013-2516407325-1000\$RQCBNGQ\80000032.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
(end)