Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.orgDatabase version: 7030
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/6/2011 4:47:46 AM
mbam-log-2011-07-06 (04-47-46).txt
Scan type: Full scan (C:\|)
Objects scanned: 174755
Time elapsed: 23 minute(s), 33 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 9
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\dell\application data\microsoft\jsxxqk.exe (Rogue.FakeMSE) -> Quarantined and deleted successfully.
c:\documents and settings\dell\application data\microsoft\yjogkd.exe (Rogue.FakeMSE) -> Quarantined and deleted successfully.
c:\documents and settings\dell\local settings\temporary internet files\Content.IE5\6MD4AKVC\flash_player_installer[3].exe (Rogue.FakeMSE) -> Quarantined and deleted successfully.
c:\documents and settings\dell\local settings\temporary internet files\Content.IE5\FWPRX4AA\flash_player_installer[1].exe (Rogue.FakeMSE) -> Quarantined and deleted successfully.
c:\system volume information\_restore{31df536c-a8fe-412e-8b6d-543a86796048}\RP54\A0008251.exe (Rogue.FakeMSE) -> Quarantined and deleted successfully.
c:\system volume information\_restore{31df536c-a8fe-412e-8b6d-543a86796048}\RP54\A0008266.exe (Rogue.FakeMSE) -> Quarantined and deleted successfully.
c:\documents and settings\dell\Desktop\eXplorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
c:\documents and settings\dell\Desktop\uSeRiNiT.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
c:\documents and settings\dell\Desktop\WiNlOgOn.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.