************' Anti-Malware 1.50.1.1100
Database version: 6266
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
04/04/2011 05:18:02 م
mbam-log-2011-04-04 (17-18-02).txt
Scan type: Full scan (C:\|)
Objects scanned: 292033
Time elapsed: 1 hour(s), 19 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 20
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa (PUP.Wpakill) -> Not selected for removal.
HKEY_CLASSES_ROOT\CLSID\{E8CFC029-8420-4EAE-ADEF-915BDC77E1DC} (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\maowsoat_ibntaimia_02.MyNSHandler (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{A4B54069-3C67-EE69-0E0A-0D88201DF744} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rundll32.exe (Trojan.Agent) -> Value: rundll32.exe -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
c:\documents and settings\xp ascs\application data\desktopicon\ebayshortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\10000001200002h\msimn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000001900002h\iexplore.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000003300002h\klwtblfs.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000008100002h\realplay.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\البرامج\الموسوعة الرجالية الرافضية.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\البرامج6\U96.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\الفلاش\idman crack abuhemmo.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\program files\mask surf pro\check.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files\Dorar\Dorar.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191227.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191230.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191248.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP485\A0146753.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP494\A0148922.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP508\A0151533.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP527\A0187322.dll (PUP.Wpakill) -> Not selected for removal.
c:\zwga\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
c:\WINDOWS\system32\logg.dat (Malware.Trace) -> Quarantined and deleted successfully.
************' Anti-Malware 1.50.1.1100
Database version: 6266
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
04/04/2011 05:18:02 م
mbam-log-2011-04-04 (17-18-02).txt
Scan type: Full scan (C:\|)
Objects scanned: 292033
Time elapsed: 1 hour(s), 19 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 20
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa (PUP.Wpakill) -> Not selected for removal.
HKEY_CLASSES_ROOT\CLSID\{E8CFC029-8420-4EAE-ADEF-915BDC77E1DC} (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\maowsoat_ibntaimia_02.MyNSHandler (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{A4B54069-3C67-EE69-0E0A-0D88201DF744} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rundll32.exe (Trojan.Agent) -> Value: rundll32.exe -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
c:\documents and settings\xp ascs\application data\desktopicon\ebayshortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\10000001200002h\msimn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000001900002h\iexplore.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000003300002h\klwtblfs.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000008100002h\realplay.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\البرامج\الموسوعة الرجالية الرافضية.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\البرامج6\U96.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\الفلاش\idman crack abuhemmo.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\program files\mask surf pro\check.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files\Dorar\Dorar.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191227.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191230.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191248.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP485\A0146753.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP494\A0148922.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP508\A0151533.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP527\A0187322.dll (PUP.Wpakill) -> Not selected for removal.
c:\zwga\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
c:\WINDOWS\system32\logg.dat (Malware.Trace) -> Quarantined and deleted successfully.
************' Anti-Malware 1.50.1.1100
Database version: 6266
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
04/04/2011 05:18:02 م
mbam-log-2011-04-04 (17-18-02).txt
Scan type: Full scan (C:\|)
Objects scanned: 292033
Time elapsed: 1 hour(s), 19 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 20
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa (PUP.Wpakill) -> Not selected for removal.
HKEY_CLASSES_ROOT\CLSID\{E8CFC029-8420-4EAE-ADEF-915BDC77E1DC} (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\maowsoat_ibntaimia_02.MyNSHandler (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{A4B54069-3C67-EE69-0E0A-0D88201DF744} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rundll32.exe (Trojan.Agent) -> Value: rundll32.exe -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
c:\documents and settings\xp ascs\application data\desktopicon\ebayshortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\10000001200002h\msimn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000001900002h\iexplore.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000003300002h\klwtblfs.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000008100002h\realplay.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\البرامج\الموسوعة الرجالية الرافضية.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\البرامج6\U96.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\الفلاش\idman crack abuhemmo.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\program files\mask surf pro\check.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files\Dorar\Dorar.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191227.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191230.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191248.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP485\A0146753.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP494\A0148922.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP508\A0151533.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP527\A0187322.dll (PUP.Wpakill) -> Not selected for removal.
c:\zwga\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
c:\WINDOWS\system32\logg.dat (Malware.Trace) -> Quarantined and deleted successfully.
************' Anti-Malware 1.50.1.1100
Database version: 6266
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
04/04/2011 05:18:02 م
mbam-log-2011-04-04 (17-18-02).txt
Scan type: Full scan (C:\|)
Objects scanned: 292033
Time elapsed: 1 hour(s), 19 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 20
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa (PUP.Wpakill) -> Not selected for removal.
HKEY_CLASSES_ROOT\CLSID\{E8CFC029-8420-4EAE-ADEF-915BDC77E1DC} (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\maowsoat_ibntaimia_02.MyNSHandler (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{A4B54069-3C67-EE69-0E0A-0D88201DF744} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rundll32.exe (Trojan.Agent) -> Value: rundll32.exe -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
c:\documents and settings\xp ascs\application data\desktopicon\ebayshortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\10000001200002h\msimn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000001900002h\iexplore.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000003300002h\klwtblfs.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000008100002h\realplay.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\البرامج\الموسوعة الرجالية الرافضية.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\البرامج6\U96.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\الفلاش\idman crack abuhemmo.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\program files\mask surf pro\check.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files\Dorar\Dorar.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191227.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191230.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191248.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP485\A0146753.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP494\A0148922.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP508\A0151533.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP527\A0187322.dll (PUP.Wpakill) -> Not selected for removal.
c:\zwga\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
c:\WINDOWS\system32\logg.dat (Malware.Trace) -> Quarantined and deleted successfully.
************' Anti-Malware 1.50.1.1100
Database version: 6266
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
04/04/2011 05:18:02 م
mbam-log-2011-04-04 (17-18-02).txt
Scan type: Full scan (C:\|)
Objects scanned: 292033
Time elapsed: 1 hour(s), 19 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 20
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa (PUP.Wpakill) -> Not selected for removal.
HKEY_CLASSES_ROOT\CLSID\{E8CFC029-8420-4EAE-ADEF-915BDC77E1DC} (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\maowsoat_ibntaimia_02.MyNSHandler (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{A4B54069-3C67-EE69-0E0A-0D88201DF744} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rundll32.exe (Trojan.Agent) -> Value: rundll32.exe -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
c:\documents and settings\xp ascs\application data\desktopicon\ebayshortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\10000001200002h\msimn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000001900002h\iexplore.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000003300002h\klwtblfs.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000008100002h\realplay.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\البرامج\الموسوعة الرجالية الرافضية.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\البرامج6\U96.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\الفلاش\idman crack abuhemmo.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\program files\mask surf pro\check.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files\Dorar\Dorar.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191227.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191230.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191248.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP485\A0146753.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP494\A0148922.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP508\A0151533.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP527\A0187322.dll (PUP.Wpakill) -> Not selected for removal.
c:\zwga\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
c:\WINDOWS\system32\logg.dat (Malware.Trace) -> Quarantined and deleted successfully.
************' Anti-Malware 1.50.1.1100
Database version: 6266
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
04/04/2011 05:18:02 م
mbam-log-2011-04-04 (17-18-02).txt
Scan type: Full scan (C:\|)
Objects scanned: 292033
Time elapsed: 1 hour(s), 19 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 20
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa (PUP.Wpakill) -> Not selected for removal.
HKEY_CLASSES_ROOT\CLSID\{E8CFC029-8420-4EAE-ADEF-915BDC77E1DC} (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\maowsoat_ibntaimia_02.MyNSHandler (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{A4B54069-3C67-EE69-0E0A-0D88201DF744} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rundll32.exe (Trojan.Agent) -> Value: rundll32.exe -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
c:\documents and settings\xp ascs\application data\desktopicon\ebayshortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\10000001200002h\msimn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000001900002h\iexplore.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000003300002h\klwtblfs.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\application data\thinstall\Ava Find\4000008100002h\realplay.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\البرامج\الموسوعة الرجالية الرافضية.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\البرامج6\U96.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\xp ascs\سطح المكتب\الفلاش\idman crack abuhemmo.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\program files\mask surf pro\check.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files\Dorar\Dorar.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191227.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191230.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP553\A0191248.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP485\A0146753.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP494\A0148922.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP508\A0151533.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0d1f2d46-4aba-4a9b-83c9-dd5fd05ed68d}\RP527\A0187322.dll (PUP.Wpakill) -> Not selected for removal.
c:\zwga\antiwpa.dll (PUP.Wpakill) -> Not selected for removal.
c:\WINDOWS\system32\logg.dat (Malware.Trace) -> Quarantined and deleted successfully.