Malwarebytes Anti-Malware (PRO) 1.75.0.1300 www.malwarebytes.org Database version: v2013.08.08.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 SSSJDanny :: SSSJDANNY-PC [limited] Protection: Disabled 8/7/2013 11:24:27 PM MBAM-log-2013-08-07 (23-38-59).txt Scan type: Full scan (C:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 56903 Time elapsed: 5 minute(s), 8 second(s) [aborted] Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 24 HKCR\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} (Virus.Ramnit) -> No action taken. HKCR\CLSID\{0180E49C-13BF-46DB-9AFD-9F52292E1C22} (Virus.Ramnit) -> No action taken. HKCR\CLSID\{51A00247-40A8-4845-9F17-7DBFCC9A8783} (Virus.Ramnit) -> No action taken. HKCR\CLSID\{EB02CC0B-C3BF-4c10-859C-70F42AFCD6B6} (Virus.Ramnit) -> No action taken. HKCR\CLSID\{760A8F35-97E7-479D-AAF5-DA9EFF95D751} (Virus.Ramnit) -> No action taken. HKCR\CLSID\{53D9DE0B-FC61-4650-9773-74D13CC7E582} (Virus.Ramnit) -> No action taken. HKCR\CLSID\{B3DE7EDC-0CD4-4d07-B1C5-92219CD475CC} (Virus.Ramnit) -> No action taken. HKCR\CLSID\{DB43B405-43AA-4f01-82D8-D84D47E6019C} (Virus.Ramnit) -> No action taken. HKCR\CLSID\{B841F346-4835-4de8-AA5E-2E7CD2D4C435} (Virus.Ramnit) -> No action taken. HKCR\CLSID\{AA7E2086-CB55-11D2-8094-00104B1F9838} (Virus.Ramnit) -> No action taken. HKCR\Setup.ScriptDriverWrapper.1 (Virus.Ramnit) -> No action taken. HKCR\Setup.ScriptDriverWrapper (Virus.Ramnit) -> No action taken. HKCR\TypeLib\{27D2CF3C-D5B0-11D2-8094-00104B1F9838} (Virus.Ramnit) -> No action taken. HKCR\Interface\{6494206F-23EA-11D3-88B0-00C04F72F303} (Virus.Ramnit) -> No action taken. HKCR\CLSID\{C9CD1A93-D7B4-11D2-80C5-00104B1F6CEA} (Virus.Ramnit) -> No action taken. HKCR\Setup.User.1 (Virus.Ramnit) -> No action taken. HKCR\Setup.User (Virus.Ramnit) -> No action taken. HKCR\TypeLib\{682C25C5-D7D9-11D2-80C5-00104B1F6CEA} (Virus.Ramnit) -> No action taken. HKCR\Interface\{00345390-4F77-11D3-A908-00105A088FAC} (Virus.Ramnit) -> No action taken. HKCR\CLSID\{E7D06080-238B-11D3-80D7-00104B1F6CEA} (Virus.Ramnit) -> No action taken. HKCR\Setup.ScriptEngine.1 (Virus.Ramnit) -> No action taken. HKCR\Setup.ScriptEngine (Virus.Ramnit) -> No action taken. HKCR\TypeLib\{DED1EA29-3F89-11D3-BBB9-00105A1F0D68} (Virus.Ramnit) -> No action taken. HKCR\Interface\{067DBAA0-38DF-11D3-BBB7-00105A1F0D68} (Virus.Ramnit) -> No action taken. Registry Values Detected: 4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAM FILES (X86)\COMMON FILES\INSTALLSHIELD\ENGINE\6\INTEL 32\CTOR.DLL (Virus.Ramnit) -> Data: 9 -> No action taken. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAM FILES (X86)\COMMON FILES\INSTALLSHIELD\ENGINE\6\INTEL 32\IUSER.DLL (Virus.Ramnit) -> Data: 9 -> No action taken. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAM FILES (X86)\COMMON FILES\INSTALLSHIELD\ISCRIPT\ISCRIPT.DLL (Virus.Ramnit) -> Data: 9 -> No action taken. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\VC\MSDIA80.DLL (Virus.Ramnit) -> Data: 2 -> No action taken. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 129 C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RAYUK2P.exe (Virus.Ramnit) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RCRNK21.rar (PUP.HackTool.Agent) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RD9J8JQ.exe (Virus.Ramnit) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RHKOYSM.rar (PUP.HackTool.Agent) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RKBP0KC.rar (PUP.HackTool.Agent) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RS7QHOP.exe (Virus.Ramnit) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RUD58JH.exe (Virus.Ramnit) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RYK5HQB.ZIP (PUP.HackTool.Agent) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RZBZ3OK.exe (Virus.Ramnit) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RZQ4L8V.exe (Virus.Ramnit) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$R3RUWOL\mp3v100114+5tr.exe (PUP.HackTool.Agent) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$R58N4E4\PAYDAY 2 Beta\payday2_win32_release.exe (Virus.Ramnit) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$R5WF8GV\mp3v100114+5tr.exe (PUP.HackTool.Agent) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RAC67KP\mp3v100114+5tr.exe (PUP.HackTool.Agent) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RF8HOF4.HOG\mp3v100113+5tr.exe (PUP.HackTool.Agent) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RJRTXT5\mp3v100113+5tr.exe (PUP.HackTool.Agent) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RKKALRJ\mp3v100113+5tr.exe (PUP.HackTool.Agent) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RUJVZI5\payday2_win32_release.exe (Virus.Ramnit) -> No action taken. C:\$Recycle.Bin\S-1-5-21-1513913394-2670544784-2353012787-1000\$RXI6UGT.GCTrainer\GCTrainer.dll (Virus.Ramnit) -> No action taken. C:\Program Files\Common Files\LogiShrd\sp6_Uninstall\tools\Expr9_Dll.dll (Virus.Ramnit) -> No action taken. C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\WTSP61MS.DLL (Virus.Ramnit) -> No action taken. C:\Program Files\WinRAR\RarExt32.dll (Virus.Ramnit) -> No action taken. C:\Program Files\WinRAR\Formats\ace32loader.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvcSrv.exe (Malware.Packer) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\ACPIWMI.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\AISuite3Srv.exe (Malware.Packer) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\AsMultiLang.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\CapLogo.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\ImageHelper.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\ASUS Update\AsFtp.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\ASUS Update\AsIdxParser.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\ASUS Update\AsMultiLang.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\ASUS Update\AsZip.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\ASUS Update\COMPALINFO.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\ASUS Update\PEInfo.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Network iControl\ImageHelper.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Network iControl\NetSvcHelp\AsMultiLang.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Network iControl\NetSvcHelp\ndisapi.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Network iControl\NetSvcHelp\NetICtrlHelp.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Network iControl\NetSvcHelp\pngio.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Network iControl\NetSvcHelp\ReInsDriver\AsMultiLang.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Network iControl\NetSvcHelp\ReInsDriver\ClrFilterInf.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Network iControl\NetSvcHelp\ReInsDriver\pngio.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AsMultiLang.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\ImageHelper.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\OpenDlgHelper.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\AWTouchInjection.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\IsSupported.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\S5WOW_App\BRCM\wl.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\S5WOW_App\x86\S5wow_2005.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\WiFile\AsMultiLang.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\WiFile\WiFileTransferSrv.exe (Malware.Packer) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\System Information\AsMultiLang.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Thermal Radar 2\AsAcpi.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\Thermal Radar 2\DIPAwayMode\DipAwayModeSrv.exe (Malware.Packer) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\CheckDevice.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\EnumDevice.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\InsDriver.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\MCCI.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvrSrv.exe (Malware.Packer) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\USBEnum.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\WMIInfo.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB BIOS Flashback\EnumDevice.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB BIOS Flashback\WMIInfo.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB Charger+\AsAcpi.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB Charger+\AsCheck.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AI Suite III\USB Charger+\USBEnum.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\ASUS\AsusFanControlService\1.02.22\Setup.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\ApexFramework_x86.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\APEX_Clothing_Legacy_x86.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\APEX_Clothing_x86.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\APEX_Destructible_Legacy_x86.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\APEX_Destructible_x86.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\cudart32_41_22.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\EasyHook32.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\fbxsdk_20113_1.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\NxCharacter.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\PhysXCooking.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\PhysXDevice.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\PhysXExtensions.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Borderlands 2\Binaries\Win32\PhysXLoader.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Cheat Engine 6.3\plugins\example-c\example-c-32bit.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\VSFilter.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\avi.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\avs.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\avss.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\dsmux.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\dxr.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\gdsmux.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\mkv2vfr.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\mkx.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\mkzlib.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\mp4.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\ogm.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\ts.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Combined Community Codec Pack\MPC\mpc-hc.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Common Files\InstallShield\IScript\iscript.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Common Files\microsoft shared\VC\msdia80.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Corsair\CorsairLINK2\CorsairLINK_HardwareMonitorSrv.exe (Malware.Packer) -> No action taken. C:\Program Files (x86)\Eidos\Batman Arkham Asylum\Binaries\BmStartApp.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\EVGA Precision X\EVGAPrecisionSrv.exe (Malware.Packer) -> No action taken. C:\Program Files (x86)\InstallShield Installation Information\{104BE4B8-D1DB-4170-977B-364960893DC8}\CloudAPI\DropboxAPI.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\InstallShield Installation Information\{104BE4B8-D1DB-4170-977B-364960893DC8}\CloudAPI\GoogleDriveAPI.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\InstallShield Installation Information\{915726DF-7891-444A-AA03-0DF1D64F561A}\ISSetup.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\InstallShield Installation Information\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}\ISSetup.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin\libcurl.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin\libeay32.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin\QtCore4.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin\legacyPM\QtCore4.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin Games\Battlefield 3\Core\libeay32.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin Games\Battlefield 3\Core\QtCore4.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin Games\Battlefield 3\pb\pbag.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin Games\Battlefield 3\pb\pbags.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin Games\Battlefield 3\pb\pbsv.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin Games\Battlefield 3\pb\dll\wa001386.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin Games\Battlefield 3\pb\dll\ws001867.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin Games\SimCity\SimCity\Core\libeay32.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin Games\SimCity\SimCity\Core\QtCore4.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin Games\SimCity\SimCityRecovery\Core\libeay32.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Origin Games\SimCity\SimCityRecovery\Core\QtCore4.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\PAYDAY 2 Beta\payday2_win32_release.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader.exe (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\RivaTuner Statistics Server\Codec\rtvcvfw32.dll (Virus.Ramnit) -> No action taken. C:\Program Files (x86)\Rockstar Games\L.A. Noire\fmodex.dll (Virus.Ramnit) -> No action taken. (end)