log from MBAM
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 911122205
Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421
23/12/2011 10:13:56 AM
mbam-log-2011-12-23 (10-13-56).txt
Scan type: Quick scan
Objects scanned: 206996
Time elapsed: 13 minute(s), 35 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 1
Registry Keys Infected: 2
Registry Values Infected: 6
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 10
Memory Processes Infected:
c:\program files\common files\ArcSoft\connection service\Bin\acservice.exe (Trojan.PatchLoad) -> 2024 -> Unloaded process successfully.
c:\Users\Leah\AppData\Roaming\dpapgraf.exe (Trojan.Agent.MVO) -> 3648 -> Unloaded process successfully.
Memory Modules Infected:
c:\programdata\Windows\msdr.dll (Trojan.Downloader.bh) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ACDaemon (Trojan.PatchLoad) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{F12BE2CC-A901-4203-B4F2-ADCB957D1887} (Trojan.Downloader.bh) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jusched (Trojan.Agent.MVO) -> Value: jusched -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\dpapgraf.exe (Trojan.Agent.MVO) -> Value: dpapgraf.exe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Backdoor.Agent) -> Value: Shell -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{E6595601-73B9-D849-0FDC-EEF58AB1291A} (Trojan.ZbotR.Gen) -> Value: {E6595601-73B9-D849-0FDC-EEF58AB1291A} -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{496ED063-7D84-AD7E-3F13-AB11014A880C} (Trojan.ZbotR.Gen) -> Value: {496ED063-7D84-AD7E-3F13-AB11014A880C} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\helpctrl.exe (Trojan.Agent.MVO) -> Value: helpctrl.exe -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\program files\common files\ArcSoft\connection service\Bin\acservice.exe (Trojan.PatchLoad) -> Quarantined and deleted successfully.
c:\programdata\Windows\msdr.dll (Trojan.Downloader.bh) -> Quarantined and deleted successfully.
c:\$RECYCLE.BIN\s-1-5-21-2194405111-3823188689-1545664750-1003\$RP4J4M3.exe (Affiliate.Downloader) -> Quarantined and deleted successfully.
c:\Users\Leah\AppData\Local\Temp\0.24371585273919405.exe (Trojan.FakeCC) -> Quarantined and deleted successfully.
c:\Users\Leah\AppData\Local\Temp\80dq587l.tmp\setup.exe (Affiliate.Downloader) -> Quarantined and deleted successfully.
c:\Users\Leah\AppData\Local\Temp\kn891d4p.tmp\downloadsetup (11).exe (Affiliate.Downloader) -> Quarantined and deleted successfully.
c:\Users\Leah\local settings\application data\rkr.exe (Rootkit.0Access) -> Quarantined and deleted successfully.
c:\Users\Leah\AppData\Roaming\dpapgraf.exe (Trojan.Agent.MVO) -> Quarantined and deleted successfully.
c:\Users\Leah\AppData\Roaming\Uckul\ydynno.exe (Trojan.ZbotR.Gen) -> Quarantined and deleted successfully.
c:\programdata\helpctrl.exe (Trojan.Agent.MVO) -> Quarantined and deleted successfully.