Malwarebytes’ Anti-Malware 1.44
Database version: 3601
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/19/2010 9:31:31 PM
mbam-log-2010-01-19 (21-31-31).txt
Scan type: Quick Scan
Objects scanned: 146144
Time elapsed: 11 minute(s), 25 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 22
Memory Processes Infected:
C:\WINDOWS\freddy81.exe (Trojan.Dropper) → Unloaded process successfully.
C:\WINDOWS\pp14.exe (Worm.KoobFace) → Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fio32 (Worm.KoobFace) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_FIO32 (Worm.KoobFace) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_FIOO32 (Worm.KoobFace) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SfX (Rootkit.Agent) → Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysfbtray (Trojan.Dropper) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pp (Worm.KoobFace) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtray (Worm.KoobFace) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\fioo32 (Worm.KoobFace) → Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\freddy81.exe (Trojan.Dropper) → Quarantined and deleted successfully.
C:\WINDOWS\pp14.exe (Worm.KoobFace) → Quarantined and deleted successfully.
C:\WINDOWS\ld16.exe (Worm.KoobFace) → Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\fio32.sys (Worm.Koobface) → Quarantined and deleted successfully.
C:\Documents and Settings\Cindy\Local Settings\Temporary Internet Files\Content.IE5\JFV41PPB\win_protection_update[1].exe (Rogue.Installer) → Quarantined and deleted successfully.
C:\Documents and Settings\Cindy\Local Settings\Temporary Internet Files\Content.IE5\JFV41PPB\win_protection_update[2].exe (Rogue.Installer) → Quarantined and deleted successfully.
C:\Documents and Settings\Cindy\Local Settings\Temporary Internet Files\Content.IE5\JFV41PPB\setup[1].exe (Worm.KoobFace) → Quarantined and deleted successfully.
C:\Documents and Settings\Cindy\Local Settings\Temporary Internet Files\Content.IE5\KO13RQRV\setup[1].exe (Worm.KoobFace) → Quarantined and deleted successfully.
C:\WINDOWS\rdr_1263940198.exe (Worm.KoobFace) → Quarantined and deleted successfully.
C:\WINDOWS\rdr_1263940198.exe.exe (Worm.KoobFace) → Quarantined and deleted successfully.
C:\WINDOWS\bk20856.dat (KoobFace.Trace) → Quarantined and deleted successfully.
C:\WINDOWS\010112010146114101.xxe (KoobFace.Trace) → Quarantined and deleted successfully.
C:\WINDOWS\bk23567.dat (KoobFace.Trace) → Quarantined and deleted successfully.
C:\WINDOWS\fdgg34353edfgdfdf (KoobFace.Trace) → Quarantined and deleted successfully.
C:\WINDOWS\010112010146101105.rx (Malware.Trace) → Quarantined and deleted successfully.
C:\WINDOWS\fs1235.dat (KoobFace.Trace) → Quarantined and deleted successfully.
C:\WINDOWS\rdr_1263945042.exe (Worm.Koobface) → Quarantined and deleted successfully.
C:\WINDOWS\rdr_1263945043.exe (Worm.Koobface) → Quarantined and deleted successfully.
C:\WINDOWS\rdr_1263945044.exe (Worm.Koobface) → Quarantined and deleted successfully.
C:\WINDOWS\rdr_1263945045.exe (Worm.Koobface) → Quarantined and deleted successfully.
C:\WINDOWS\rdr_1263950922.exe (Worm.Koobface) → Quarantined and deleted successfully.
C:\WINDOWS\rdr_1263950924.exe (Worm.Koobface) → Quarantined and deleted successfully.