Malwarebytes' Anti-Malware 1.51.2.1300
Database version: 7622
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
11/22/2011 11:36:30 PM
mbam-log-2011-11-22 (23-36-30).txt
Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|)
Objects scanned: 328533
Time elapsed: 46 minute(s), 40 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 51
Memory Processes Infected:
c:\Windows\kmservice.exe (RiskWare.Tool.CK) -> 1336 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.StartPage.Gen) -> Bad: (
) Good: (
) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Windows\kmservice.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
c:\Windows\System32\antiwpa.dll (PUP.Wpakill) -> Quarantined and deleted successfully.
d:\program files\total cma pack\plugins\wlx\17fileinfo\cadt.dll (Trojan.Constructor) -> Quarantined and deleted successfully.
d:\program files\radio master\oggenc.exe (Trojan.Ransom) -> Quarantined and deleted successfully.
d:\Windows\kmservice.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
d:\Users\Admin\AppData\Roaming\thinstall\amazing photo editor v7.0\40000054500002i\amazing photo editor.exe (Trojan.IRCBot) -> Quarantined and deleted successfully.
d:\Users\Admin\AppData\Roaming\thinstall\better file rename 5.2.5\4000002e00002i\bfr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Users\Admin\AppData\Roaming\thinstall\internet download manager 6.5.8.1\40000032400002i\IDMan.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Users\Admin\AppData\Roaming\thinstall\Opera 10.00\400000cd00002i\opera.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Users\Admin\AppData\Roaming\thinstall\pdfgrabber 4.0\40000069900002i\pdfgrabber.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Users\Admin\AppData\Roaming\thinstall\total video converter 3.20 090114\4000003d700002i\tvc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Users\Admin\AppData\Roaming\thinstall\windows live messenger\400000700002h\wlcomm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Users\Admin\Desktop\سطح المكتب 1\new folder\u997.exe (Trojan.Agent.PS) -> Quarantined and deleted successfully.
d:\Users\Admin\documents\لا تحزن.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
e:\garmin_kgen_15.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
e:\قصص الأنبياء.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
e:\كتاب الدعاء.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
e:\السيرة النبوية.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
e:\الشمائل.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
e:\Keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
e:\prt (perlovga removal tool) 2.0 -.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
e:\garmin_mobile_pc\garmin_kgen_15.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
e:\90 برامج بورتابل portable applications\apt.exe (Trojan.Agent) -> Quarantined and deleted successfully.
e:\90 برامج بورتابل portable applications\mailpassview.exe (PUP.MailPassView) -> Quarantined and deleted successfully.
e:\90 برامج بورتابل portable applications\partitionmagicv8.05.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
e:\90 برامج بورتابل portable applications\pass_IE.exe (PUP.PSW.Passview) -> Quarantined and deleted successfully.
e:\90 برامج بورتابل portable applications\strun.exe (PUP.StartUpManager) -> Quarantined and deleted successfully.
e:\90 برامج بورتابل portable applications\xp password manager.exe (Trojan.Orsam) -> Quarantined and deleted successfully.
e:\مستندات\لا تحزن.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
e:\ملفات الجوال ونوكيا\مدير المهام لجهازك للجوال\keygen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
e:\downloads75\portable_anvsoft_photo_flash_maker_pro_v5.15_2\portable anvsoft photo flash maker pro v5.15.exe (Trojan.Agent) -> Quarantined and deleted successfully.
e:\downloads75\u1006\u1006.exe (Trojan.Agent) -> Quarantined and deleted successfully.
e:\downloads75\u1006\u1008.exe (PUP.UltraSurf) -> Quarantined and deleted successfully.
e:\downloads77\للبحث عن الكراك والسيريل نمبر وتحميلهما\للبحث عن الكراك والسيريل نمبر وتحميلهما.exe (CrackTool.Agent) -> Quarantined and deleted successfully.
e:\الشبكه\wirelesskeyview v1.10\wirelesskeyview.exe (PUP.WirelessKeyView) -> Quarantined and deleted successfully.
e:\برامج\ksa.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
e:\برامج\التقويم الهجررري.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
e:\برامج\شرح برنامج hijackthis.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
e:\برامج\turbo zip cracker v1.1\Patch\Patch.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
e:\برامج\برامج بحث في الجهاز\turbo_searcher\turbo searcher\crack\turbosearcher_patch.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
e:\برامج\برامج بورتابل\portable foxit pdf editor v2.1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
e:\برامج\برنامج hijackلحذف ملفات التجسس\شرح برنامج hijackthis.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
e:\برامج\شرح نسخ الاكس بواسطة برنامج اكرونوس\zti922e5-2005-09-22\keygen.exe (Riskware.Tool.CK) -> Quarantined and deleted successfully.
e:\برامج الجوال\مدير المهام لجهازك\keygen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
e:\idm_6.03_beta_build_12\Patch\patch 6.xx.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
g:\DISK5\برامج ويندوز 7 رمضان\ultraisom\keygen.exe (Riskware.Tool.CK) -> Quarantined and deleted successfully.
g:\DISK5\برامج ويندوز 7 رمضان\افضل نسخة internet download manager\patch\استخدم هذا الباتش اولا\SnDk&p.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
g:\DISK5\برامج ويندوز 7 رمضان\افضل نسخة internet download manager\patch\ثم استخدم هذا الباتش\patch .xx 2.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
g:\DISK5\برامج ويندوز 7 رمضان\افضل نسخة internet download manager\patch\ثم استخدم هذا الباتش\patch 6.xx.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
g:\DISK5\برامج ويندوز 7 رمضان\زيادة سرعة ويندوز 7\ultimate windows tweaker.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
g:\DISK5\برامج ويندوز 7 رمضان\كراك وتعريب ويندوز سفن\removewat.exe (HackTool.Wpakill) -> Quarantined and deleted successfully.