[2014.11.04 19:38:24.612] - Begin
[2014.11.04 19:38:24.612] -
[2014.11.04 19:38:24.612] - ....................................
[2014.11.04 19:38:24.612] - ..::::::::::::::::::....................
[2014.11.04 19:38:24.612] - .::EEEEEE:::SSSSSS::..EEEEEE..TTTTTTTT.. Win32/Poweliks
[2014.11.04 19:38:24.628] - .::EE::::EE:SS:::::::.EE....EE....TT...... Version: 1.0.0.1
[2014.11.04 19:38:24.628] - .::EEEEEEEE::SSSSSS::.EEEEEEEE....TT...... Built: Oct 15 2014
[2014.11.04 19:38:24.628] - .::EE:::::::::::::SS:.EE..........TT......
[2014.11.04 19:38:24.628] - .::EEEEEE:::SSSSSS::..EEEEEE.....TT..... Copyright (c) ESET, spol. s r.o.
[2014.11.04 19:38:24.628] - ..::::::::::::::::::.................... 1992-2013. All rights reserved.
[2014.11.04 19:38:24.628] - ....................................
[2014.11.04 19:38:24.628] -
[2014.11.04 19:38:24.628] - --------------------------------------------------------------------------------
[2014.11.04 19:38:24.628] -
[2014.11.04 19:38:24.628] - INFO: OS: 6.1.7601 SP1
[2014.11.04 19:38:24.628] - INFO: Product Type: Workstation
[2014.11.04 19:38:24.628] - INFO: WoW64: False
[2014.11.04 19:38:24.628] - INFO: Machine guid: 5F2EDDFD-8FAD-42BF-B824-D1D940424289
[2014.11.04 19:38:24.628] -
[2014.11.04 19:38:24.628] - INFO: Scanning for system infection...
[2014.11.04 19:38:24.628] - --------------------------------------------------------------------------------
[2014.11.04 19:38:24.628] -
[2014.11.04 19:38:24.628] - INFO: Processing [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]...
[2014.11.04 19:38:24.628] - WARNING: Found infected value [ a] = 'rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write("\74script language=jscript.encode>"+(new%20ActiveXObject("WScript.Shell")).RegRead("HKCU\\software\\microsoft\\windows\\currentversion\\run\\")+"\74/script>")'
[2014.11.04 19:38:24.628] - WARNING: Found infected value [ a] = 'rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write("\74script language=jscript.encode>"+(new%20ActiveXObject("WScript.Shell")).RegRead("HKCU\\software\\microsoft\\windows\\currentversion\\run\\")+"\74/script>")'
[2014.11.04 19:38:24.628] - INFO: Processing [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]...
[2014.11.04 19:38:24.628] - INFO: Processing [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]...
[2014.11.04 19:38:24.628] - INFO: Processing [HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce]...
[2014.11.04 19:38:24.628] - INFO: Processing classes...
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{11CD84A3-A5E0-43CB-B3DF-92C623C0E0E0}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{22756E83-8EBC-4B16-A4A4-0AA73BE497B1}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{2A235D7E-0358-40E2-B51A-DE22F8F5C50D}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{56C94D6A-7370-4885-A04E-7097FE4E0BAF}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{672CDBDB-0270-4EB9-83EC-216377522D21}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{841BFDCA-6A9A-4EBC-BC7E-194AA5DCE428}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{94330D48-EB33-49BB-87F1-AD8C0352C010}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{BE13040F-26A4-4DC4-A537-5C8C1D76FEDD}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{F7CA46A9-ACA5-45A6-967E-03FF5A282D01}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{11CD84A3-A5E0-43CB-B3DF-92C623C0E0E0}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{22756E83-8EBC-4B16-A4A4-0AA73BE497B1}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{2A235D7E-0358-40E2-B51A-DE22F8F5C50D}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{56C94D6A-7370-4885-A04E-7097FE4E0BAF}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{672CDBDB-0270-4EB9-83EC-216377522D21}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{841BFDCA-6A9A-4EBC-BC7E-194AA5DCE428}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{94330D48-EB33-49BB-87F1-AD8C0352C010}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{BE13040F-26A4-4DC4-A537-5C8C1D76FEDD}]
[2014.11.04 19:38:24.628] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{F7CA46A9-ACA5-45A6-967E-03FF5A282D01}]
[2014.11.04 19:38:24.628] - INFO: Processing [HKLM\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32]...
[2014.11.04 19:38:24.628] - INFO: Processing value [] = [%systemroot%\system32\wbem\wmiprvse.exe]
[2014.11.04 19:38:24.628] - INFO: Processing value [] = [%systemroot%\system32\wbem\wmiprvse.exe]
[2014.11.04 19:38:24.628] - INFO: Processing invalid values in [HKLM\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32]...
[2014.11.04 19:38:24.628] - INFO: Processing value [] = [%systemroot%\system32\wbem\wmiprvse.exe]
[2014.11.04 19:38:24.628] - INFO: Processing value [ServerExecutable] = [%systemroot%\system32\wbem\wmiprvse.exe]
[2014.11.04 19:38:24.628] - INFO: Processing value [] = [%systemroot%\system32\wbem\wmiprvse.exe]
[2014.11.04 19:38:24.628] - INFO: Processing value [ServerExecutable] = [%systemroot%\system32\wbem\wmiprvse.exe]
[2014.11.04 19:38:24.628] - INFO: Processing invalid subkeys in [HKLM\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32]...
[2014.11.04 19:38:24.628] - INFO: Processing [HKLM\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}]...
[2014.11.04 19:38:24.628] - INFO: Processing subkey [\Registry\Machine\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32]
[2014.11.04 19:38:24.628] - INFO: Processing subkey [\Registry\Machine\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32]
[2014.11.04 19:38:24.628] - INFO: Win32/Poweliks found
[2014.11.04 19:38:28.372] - INFO: process: dllhost.exe, pid 1020, parent 2340
[2014.11.04 19:38:28.372] - INFO: Terminated process pid = 1020
[2014.11.04 19:38:28.372] - INFO: process: dllhost.exe, pid 3588, parent 580
[2014.11.04 19:38:28.372] - INFO: process: dllhost.exe, pid 2128, parent 580
[2014.11.04 19:38:28.372] - INFO: Processing [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]...
[2014.11.04 19:38:28.372] - INFO: Deleted infected value [ a] = 'rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write("\74script language=jscript.encode>"+(new%20ActiveXObject("WScript.Shell")).RegRead("HKCU\\software\\microsoft\\windows\\currentversion\\run\\")+"\74/script>")'
[2014.11.04 19:38:28.372] - INFO: Processing [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]...
[2014.11.04 19:38:28.388] - INFO: Processing [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]...
[2014.11.04 19:38:28.388] - INFO: Processing [HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce]...
[2014.11.04 19:38:28.388] - INFO: Processing classes...
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{11CD84A3-A5E0-43CB-B3DF-92C623C0E0E0}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{22756E83-8EBC-4B16-A4A4-0AA73BE497B1}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{2A235D7E-0358-40E2-B51A-DE22F8F5C50D}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{56C94D6A-7370-4885-A04E-7097FE4E0BAF}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{672CDBDB-0270-4EB9-83EC-216377522D21}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{841BFDCA-6A9A-4EBC-BC7E-194AA5DCE428}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{94330D48-EB33-49BB-87F1-AD8C0352C010}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{BE13040F-26A4-4DC4-A537-5C8C1D76FEDD}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{F7CA46A9-ACA5-45A6-967E-03FF5A282D01}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{11CD84A3-A5E0-43CB-B3DF-92C623C0E0E0}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{22756E83-8EBC-4B16-A4A4-0AA73BE497B1}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{2A235D7E-0358-40E2-B51A-DE22F8F5C50D}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{56C94D6A-7370-4885-A04E-7097FE4E0BAF}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{672CDBDB-0270-4EB9-83EC-216377522D21}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{841BFDCA-6A9A-4EBC-BC7E-194AA5DCE428}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{94330D48-EB33-49BB-87F1-AD8C0352C010}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{BE13040F-26A4-4DC4-A537-5C8C1D76FEDD}]
[2014.11.04 19:38:28.388] - INFO: Processing clsid [\Registry\User\S-1-5-21-2119087973-2260802398-3012002660-1000\SOFTWARE\Classes\CLSID\{F7CA46A9-ACA5-45A6-967E-03FF5A282D01}]
[2014.11.04 19:38:28.388] - INFO: Processing [HKLM\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32]...
[2014.11.04 19:38:28.388] - INFO: Processing value [] = [%systemroot%\system32\wbem\wmiprvse.exe]
[2014.11.04 19:38:28.388] - INFO: Processing value [] = [%systemroot%\system32\wbem\wmiprvse.exe]
[2014.11.04 19:38:28.388] - INFO: Processing invalid values in [HKLM\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32]...
[2014.11.04 19:38:28.388] - INFO: Processing value [] = [%systemroot%\system32\wbem\wmiprvse.exe]
[2014.11.04 19:38:28.388] - INFO: Processing value [ServerExecutable] = [%systemroot%\system32\wbem\wmiprvse.exe]
[2014.11.04 19:38:28.388] - INFO: Processing value [] = [%systemroot%\system32\wbem\wmiprvse.exe]
[2014.11.04 19:38:28.388] - INFO: Processing value [ServerExecutable] = [%systemroot%\system32\wbem\wmiprvse.exe]
[2014.11.04 19:38:28.388] - INFO: Processing invalid subkeys in [HKLM\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32]...
[2014.11.04 19:38:28.388] - INFO: Processing [HKLM\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}]...
[2014.11.04 19:38:28.388] - INFO: Processing subkey [\Registry\Machine\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32]
[2014.11.04 19:38:28.388] - INFO: Processing subkey [\Registry\Machine\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32]
[2014.11.04 19:38:28.388] - INFO: Cleaning status: 0
[2014.11.04 19:38:30.837] - End