Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6406
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
4/20/2011 9:58:36 AM
mbam-log-2011-04-20 (09-58-36).txt
Scan type: Quick scan
Objects scanned: 174052
Time elapsed: 17 minute(s), 30 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
c:\documents and settings\all users\application data\fpojeykxwu.exe (Trojan.Agent) -> 2220 -> Unloaded process successfully.
c:\documents and settings\all users\application data\20242228.exe (Trojan.FakeAlert) -> 3816 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\FpoJEykxWu (Trojan.Agent) -> Value: FpoJEykxWu -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\ActiveDesktop\NoChangingWallPap er (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\all users\application data\fpojeykxwu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\20242228.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully