Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 22-8-2014 Scan Time: 6:47:11 Logfile: mbam scanlog.txt Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.08.22.01 Rootkit Database: v2014.08.21.01 License: Trial Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: van Elswijk Scan Type: Threat Scan Result: Completed Objects Scanned: 322428 Time Elapsed: 9 min, 0 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 4 Trojan.Agent, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SYSHOST32, Quarantined, [7a1f8742bbc0ad892b18d62ba262a25e], PUP.Optional.DataMngr.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Datamngr, Quarantined, [9efb79501665b68035242efc897b12ee], PUP.Optional.iMeshMusicBoxTB.A, HKU\S-1-5-21-2261932897-653746225-4216270450-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\imeshmusicboxtoolbar, Quarantined, [a9f02c9d86f51026b2535abd52b11be5], Malware.Trace, HKU\S-1-5-21-2261932897-653746225-4216270450-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\VB AND VBA PROGRAM SETTINGS\SrvID, Quarantined, [7e1b6168f487a690f68d5b33b74cd12f], Registry Values: 1 Trojan.Agent, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SYSHOST32|ImagePath, "C:\Windows\Installer\{44D0BD3B-51BA-830E-D9A2-222CB96A8A52}\syshost.exe" /service, Quarantined, [7a1f8742bbc0ad892b18d62ba262a25e] Registry Data: 1 Trojan.0Access, HKLM\SOFTWARE\CLASSES\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\INPROCSERVER32, C:\$Recycle.Bin\S-1-5-18\$e681cee208a0685550033e4fed106be1\n., Good: (fastprox.dll), Bad: (C:\$Recycle.Bin\S-1-5-18\$e681cee208a0685550033e4fed106be1\n.),Replaced,[85142e9bb1caa294e9b432a7a064ef11] Folders: 2 Trojan.PWS, C:\directory\CyberGate, Quarantined, [dfba6762a1da2c0a003df3c3c63c3ec2], Trojan.PWS, C:\directory\CyberGate\install, Quarantined, [dfba6762a1da2c0a003df3c3c63c3ec2], Files: 1 Backdoor.SpyNet.M, C:\directory\CyberGate\install\server.exe, Quarantined, [2871e5e495e6bb7ba1f83b19dc2722de], Physical Sectors: 0 (No malicious items detected) (end)