Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes
Database version: 5617
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
27/01/2011 20:11:58
mbam-log-2011-01-27 (20-11-58).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 313931
Time elapsed: 29 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 15
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MRXCLS (Rootkit.TmpHider) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MRXNET (Rootkit.TmpHider) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\program files\mIRC\IRC Bot\anjing_malingsia.sys (Backdoor.IRCBot) -> Quarantined and deleted successfully.
c:\program files\mIRC\IRC Bot\Asshole.sys (Backdoor.IRCBot) -> Quarantined and deleted successfully.
c:\program files\mIRC\IRC Bot\channel_babi.sys (Backdoor.IRCBot) -> Quarantined and deleted successfully.
c:\program files\mIRC\IRC Bot\****.sys (Backdoor.IRCBot) -> Quarantined and deleted successfully.
c:\program files\mIRC\IRC Bot\kontol.mrc (Backdoor.IRCBot) -> Quarantined and deleted successfully.
c:\program files\mIRC\IRC Bot\nama_anjing.sys (Backdoor.IRCBot) -> Quarantined and deleted successfully.
c:\program files\mIRC\IRC Bot\nama_babi.sys (Backdoor.IRCBot) -> Quarantined and deleted successfully.
c:\program files\mIRC\IRC Bot\perampok_budaya.sys (Backdoor.IRCBot) -> Quarantined and deleted successfully.
c:\program files\mIRC\IRC Bot\services.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\program files\mIRC\IRC Bot\Stupid.sys (Backdoor.IRCBot) -> Quarantined and deleted successfully.
c:\program files\mIRC\IRC Bot\svchost.exe (Backdoor.IRCBot) -> Quarantined and deleted successfully.
c:\Windows\inf\mdmcpq3.PNF (Rootkit.TmpHider) -> Quarantined and deleted successfully.
c:\Windows\inf\mdmeric3.PNF (Rootkit.TmpHider) -> Quarantined and deleted successfully.
c:\Windows\inf\oem6C.PNF (Rootkit.TmpHider) -> Quarantined and deleted successfully.
c:\Windows\inf\oem7A.PNF (Rootkit.TmpHider) -> Quarantined and deleted successfully.