Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.12.08
Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Zeus :: ZEUS-PC [administrator]
5/12/2012 6:03:07 PM
mbam-log-2012-05-12 (18-03-07).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 206345
Time elapsed: 6 minute(s), 16 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 3
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|Load (Backdoor.CycBot) -> Data: C:\Users\Zeus\AppData\Roaming\0C593\lvvm.exe -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WtVufNJluOXVUv (Rogue.Agent.SA) -> Data: C:\ProgramData\WtVufNJluOXVUv.exe -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|48C.exe (Backdoor.CycBot.Gen) -> Data: C:\Users\Zeus\AppData\Roaming\Microsoft\B1E7\48C.exe -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 1
C:\Users\Zeus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Recovery (Trojan.FakeAV) -> Quarantined and deleted successfully.
Files Detected: 3
C:\Users\Zeus\Desktop\Windows Recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
C:\Users\Zeus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Recovery\Uninstall Windows Recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
C:\Users\Zeus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Recovery\Windows Recovery.lnk (Trojan.FakeAV) -> Quarantined and deleted successfully.
(end)