Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.05.23.03 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 jos :: JOS-PC [administrator] Protection: Enabled 23/05/2012 9:55:07 mbam-log-2012-05-23 (09-55-07).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 357188 Time elapsed: 54 minute(s), 36 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{QbUUmTWv-vB5o-PUu5-6nzJ-qFZqif61VYcq} (Backdoor.Agent) -> Quarantined and deleted successfully. Registry Values Detected: 2 HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Shell (Backdoor.Agent) -> Data: I:\Documents and Settings\jos\Application Data\BSI.bund.exe -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Userinit (Backdoor.Agent) -> Data: I:\Documents and Settings\jos\Application Data\BSI.bund.exe,C:\WINDOWS\System32\userinit.exe, -> Quarantined and deleted successfully. Registry Data Items Detected: 3 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoDesktop (PUM.Hidden.Desktop) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools (PUM.Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)