Malwarebytes' Anti-Malware 1.15 Database version: 838 19:09:03 07.06.2008 mbam-log-6-7-2008 (19-09-03).txt Scan type: Quick Scan Objects scanned: 54179 Time elapsed: 6 minute(s), 55 second(s) Memory Processes Infected: 1 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 1 Folders Infected: 2 Files Infected: 5 Memory Processes Infected: C:\Program Files\mIRC\mirc.exe (Trojan.Downloader) -> Unloaded process successfully. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Messanger Control Center (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: c:\windows\system32\ntos.exe -> Delete on reboot. Folders Infected: C:\WINDOWS\system32\wsnpoem (Trojan.Agent) -> Delete on reboot. C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\wsnpoem (Trojan.Agent) -> Quarantined and deleted successfully. Files Infected: C:\Program Files\mIRC\mirc.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wsnpoem\audio.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\wsnpoem\video.dll (Trojan.Agent) -> Delete on reboot. C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\wsnpoem\audio.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ntos.exe (Backdoor.Bot) -> Delete on reboot.