Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Databaseversjon: 5005 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 31.10.2010 13:14:40 mbam-log-2010-10-31 (13-14-40).txt Skanntype: Hurtigsøk Objekter skannet: 214701 Tid tilbakelagt: 9 minutt(er), 46 sekund(er) Minneprosesser infisert: 2 Minnemoduler infisert: 0 Registernøkler infisert: 0 Registerverdier infisert: 3 Registerfiler infisert: 3 Mapper infisert: 0 Filer infisert 3 Minneprosesser infisert: C:\Documents and Settings\trond.magne.storstad\Programdata\Microsoft\svchost.exe (Trojan.Agent) -> Unloaded process successfully. C:\Documents and Settings\trond.magne.storstad\Programdata\Microsoft\Windows\shell.exe (Trojan.Shell) -> Unloaded process successfully. Minnemoduler infisert: (Ingen skadelige objekter funnet) Registernøkler infisert: (Ingen skadelige objekter funnet) Registerverdier infisert: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\microsoft xml parser driver (Trojan.Clicker) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Trojan.Agent) -> Quarantined and deleted successfully. Registerfiler infisert: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (explorer.exe,C:\Documents and Settings\trond.magne.storstad\Programdata\Microsoft\Windows\shell.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully. Mapper infisert: (Ingen skadelige objekter funnet) Filer infisert C:\Documents and Settings\trond.magne.storstad\Programdata\Microsoft\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\trond.magne.storstad\Programdata\Microsoft\Windows\shell.exe (Trojan.Shell) -> Quarantined and deleted successfully. C:\WINDOWS\system32\a.exe (Backdoor.Bot) -> Quarantined and deleted successfully.