Malwarebytes Anti-Malware 1.65.0.1400 www.malwarebytes.org Database version: v2012.09.24.10 Windows 7 x64 NTFS (Safe Mode) Internet Explorer 9.0.8112.16421 **** :: **** [administrator] 07.10.2012 13:05:51 mbam-log-2012-10-07 (13-05-51).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 240995 Time elapsed: 55 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCR\CLSID\{312BFDCE-A901-4203-B4F2-ADCB957D1887} (Trojan.FakeMS) -> Quarantined and deleted successfully. Registry Values Detected: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce|43C8D8E418AE66C500E543C7F483CD8A (Trojan.FakeAlert.SSGen) -> Data: C:\ProgramData\43C8D8E418AE66C500E543C7F483CD8A\43C8D8E418AE66C500E543C7F483CD8A.exe -> Quarantined and deleted successfully. Registry Data Items Detected: 3 HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. Folders Detected: 1 C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Progressive Protection (Rogue.SystemProgressiveProtection) -> Quarantined and deleted successfully. Files Detected: 9 C:\ProgramData\Windows\msseedir.dll (Trojan.FakeMS) -> Quarantined and deleted successfully. C:\$Recycle.Bin\S-1-5-18\$88a646d5fd2805145f75812bdb29044d\n (Trojan.0Access) -> Delete on reboot. C:\$Recycle.Bin\S-1-5-21-3717389207-4108201374-1437328139-1001\$88a646d5fd2805145f75812bdb29044d\n (Trojan.0Access) -> Delete on reboot. C:\ProgramData\Windows\ccdxmmde.dat (Malware.Trace) -> Quarantined and deleted successfully. C:\ProgramData\Windows\drss.dat (Malware.Trace) -> Quarantined and deleted successfully. C:\ProgramData\Windows\xessmsxe.dat (Malware.Trace) -> Quarantined and deleted successfully. C:\Users\****\Desktop\System Progressive Protection.lnk (Rogue.SystemProgressiveProtection) -> Quarantined and deleted successfully. C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Progressive Protection\System Progressive Protection.lnk (Rogue.SystemProgressiveProtection) -> Quarantined and deleted successfully. C:\ProgramData\43C8D8E418AE66C500E543C7F483CD8A\43C8D8E418AE66C500E543C7F483CD8A.exe (Trojan.FakeAlert.SSGen) -> Quarantined and deleted successfully. (end)