Malwarebytes' Anti-Malware 1.51.2.1300
Database version: 7622
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
07/06/2012 04:16:23 م
mbam-log-2012-06-07 (16-16-23).txt
Scan type: Full scan (C:\|D:\|G:\|)
Objects scanned: 258855
Time elapsed: 1 hour(s), 2 minute(s), 56 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 34
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{S0XWBYGC-F087-NP4L-063W-Y217GQ56HESI} (Backdoor.Agent.PGen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{S0XWBYGC-F087-NP4L-063W-Y217GQ56HESI} (Backdoor.Agent.PGen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{S0XWBYGC-F087-NP4L-063W-Y217GQ56HESI} (Backdoor.Agent.PGen) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies (Backdoor.Agent.PGen) -> Value: Policies -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies (Backdoor.Agent.PGen) -> Value: Policies -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\HKCU (Backdoor.Agent.PGen) -> Value: HKCU -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\bs\سطح المكتب\برامج\برنامج يقوي صوت الحاسوب 10 اضعاف وينقي الصوت الي اخر نقاوة إن لم تدخل فأنت الخاسر\myegy.com.dfx.by.vibration\dfx.for.foobar2000.v10.008.incl.keymaker-core\CORE10k.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully.
c:\documents and settings\bs\سطح المكتب\برامج\برنامج يقوي صوت الحاسوب 10 اضعاف وينقي الصوت الي اخر نقاوة إن لم تدخل فأنت الخاسر\myegy.com.dfx.by.vibration\dfx.for.gom.player.v10.008.incl.keymaker-core\CORE10k.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully.
c:\documents and settings\bs\سطح المكتب\برامج\برنامج يقوي صوت الحاسوب 10 اضعاف وينقي الصوت الي اخر نقاوة إن لم تدخل فأنت الخاسر\myegy.com.dfx.by.vibration\dfx.for.j.river.media.center.v10.008.incl.keymaker-core\CORE10k.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully.
c:\documents and settings\bs\سطح المكتب\برامج\برنامج يقوي صوت الحاسوب 10 اضعاف وينقي الصوت الي اخر نقاوة إن لم تدخل فأنت الخاسر\myegy.com.dfx.by.vibration\dfx.for.jetaudio.v10.008.incl.keymaker-core\CORE10k.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully.
c:\documents and settings\bs\سطح المكتب\برامج\برنامج يقوي صوت الحاسوب 10 اضعاف وينقي الصوت الي اخر نقاوة إن لم تدخل فأنت الخاسر\myegy.com.dfx.by.vibration\dfx.for.mediamonkey.v10.008.incl.keymaker-core\CORE10k.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully.
c:\documents and settings\bs\سطح المكتب\برامج\برنامج يقوي صوت الحاسوب 10 اضعاف وينقي الصوت الي اخر نقاوة إن لم تدخل فأنت الخاسر\myegy.com.dfx.by.vibration\dfx.for.winamp.v10.008.incl.keymaker-core\CORE10k.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully.
c:\documents and settings\bs\سطح المكتب\برامج\برنامج يقوي صوت الحاسوب 10 اضعاف وينقي الصوت الي اخر نقاوة إن لم تدخل فأنت الخاسر\myegy.com.dfx.by.vibration\dfx.for.windows.media.player.v10.008.incl.keymaker-core\CORE10k.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully.
c:\documents and settings\bs\سطح المكتب\برامج\خرائط\garmin ^30\Keygen 2.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
c:\program files\internet download manager\PATCH a.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
c:\program files\internet download manager\patch 6.xx.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
c:\program files\internet download manager\patch .xx 2.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
c:\program files\internet download manager\SnDk&p.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
c:\program files\internet download manager\patch\patch\استخدم هذا الباتش اولا\SnDk&p.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
c:\program files\internet download manager\patch\patch\ثم استخدم هذا الباتش\patch .xx 2.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
c:\program files\internet download manager\patch\patch\ثم استخدم هذا الباتش\patch 6.xx.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
c:\program files\internet download manager\patch\patch\ثم استخدم هذا الباتش\SnDk&p.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
d:\البرامج\برامج الجوال\garmin ^30\garmin ^30\Keygen 2.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
d:\البرامج\برامج انترنت\internet download manager\لتنزيل الملفات\لتسريع ومعاودة التحميل مع الكراك\PATCH a.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
d:\البرامج\برامج انترنت\internet download manager\لتنزيل الملفات\لتسريع ومعاودة التحميل مع الكراك\patch\استخدم هذا الباتش اولا\SnDk&p.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
d:\البرامج\برامج انترنت\internet download manager\لتنزيل الملفات\لتسريع ومعاودة التحميل مع الكراك\patch\ثم استخدم هذا الباتش\patch .xx 2.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
d:\البرامج\برامج انترنت\internet download manager\لتنزيل الملفات\لتسريع ومعاودة التحميل مع الكراك\patch\ثم استخدم هذا الباتش\patch 6.xx.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
d:\البرامج\برامج انترنت\internet download manager\لتنزيل الملفات\لتسريع ومعاودة التحميل مع الكراك\patch\patch\استخدم هذا الباتش اولا\SnDk&p.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
d:\البرامج\برامج انترنت\internet download manager\لتنزيل الملفات\لتسريع ومعاودة التحميل مع الكراك\patch\patch\ثم استخدم هذا الباتش\patch .xx 2.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
d:\البرامج\برامج انترنت\internet download manager\لتنزيل الملفات\لتسريع ومعاودة التحميل مع الكراك\patch\patch\ثم استخدم هذا الباتش\patch 6.xx.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
g:\مكتبة\ramadan\الكبائر.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
g:\مكتبة\ramadan\المواعظ لابن الجوزي.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
g:\مكتبة\ramadan\تمام المنة في التعليق على فقه السنة.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
g:\مكتبة\ramadan\رياض الصالحين.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
g:\مكتبة\ramadan\فقه السنه.exe (Spyware.AdaEbook) -> Quarantined and deleted successfully.
c:\documents and settings\bs\application data\logs.dat (Bifrose.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\test\Flash.exe (Backdoor.Agent.PGen) -> Quarantined and deleted successfully.
c:\WINDOWS\2535171.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\4728828.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\8927437.exe (Rootkit.Agent) -> Quarantined and deleted successfully.