Malwarebytes' Anti-Malware 1.20 Database version: 960 Windows 5.1.2600 Service Pack 2 11:24:16 AM 7/17/2008 mbam-log-7-17-2008 (11-24-16).txt Scan type: Quick Scan Objects scanned: 75727 Time elapsed: 8 minute(s), 33 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 1 Registry Values Infected: 3 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 14 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\amvo1.dll (Trojan.Agent) -> Unloaded module successfully. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{88abc5c0-4fcb-11bb-aax5-81cx1c635612} (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kamsoft (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\amva (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\f08a9bfb (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\m88coaim.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Documents and Settings\ssa\Local Settings\Temp\tru17D.tmp (Trojan.Vaklik) -> Quarantined and deleted successfully. C:\Documents and Settings\ssa\Local Settings\Temp\tru3.tmp (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ckvo.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\xmnm2.cmd (Trojan.Agent) -> Quarantined and deleted successfully. C:\6x8be16.cmd (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\clbdll.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\amvo.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\amvo0.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\amvo1.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\drivers\clbdriver.sys (Rootkit.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\ssa\Local Settings\Temp\tru4.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\ssa\Local Settings\Temp\tru5.tmp (Trojan.Agent) -> Quarantined and deleted successfully.