Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5762 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 14.02.11 19:49:16 mbam-log-2011-02-14 (19-49-16).txt Scan type: Quick scan Objects scanned: 168346 Time elapsed: 17 minute(s), 55 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 6 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: c:\WINDOWS\system32\clhordei.dll (Trojan.Agent) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{24C138AC-50A2-4F96-B3FD-BB76CAA25AB7} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{6B5631B8-788D-4496-96EA-C634A44E39B4} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{4FA06538-D0E3-4000-980A-15D8150AE347} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\ClhordeiAtk.cClhordei (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{5F94FD38-1F4E-465F-92BA-AD15D8B066A3} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\ClhordeiAtk.Clhordei (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{5F94FD38-1F4E-465F-92BA-AD15D8B066A3} (Trojan.Agent) -> Value: {5F94FD38-1F4E-465F-92BA-AD15D8B066A3} -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5F94FD38-1F4E-465F-92BA-AD15D8B066A3} (Trojan.Agent) -> Value: {5F94FD38-1F4E-465F-92BA-AD15D8B066A3} -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\program files\microsoft common (Trojan.Agent) -> Quarantined and deleted successfully. Files Infected: c:\WINDOWS\system32\clhordei.dll (Trojan.Agent) -> Delete on reboot.