7/31/2011 4:39:54 PM mbam Full scan (C:\|D:\| Windows 5.1.2600 Service Pack 2 (Safe Mode) Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*objxmlaudio.exe (Trojan.FakeAlert) -> Value: *objxmlaudiFiles Infected: Files Infected: c:\documents and settings\networkservice\local settings\application data\objxmlaudio.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\system volume information\_restore{b6441411-87b0-4bda-9e4a-8ac5b81921cd}\RP1154\A0091196.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\system volume information\_restore{b6441411-87b0-4bda-9e4a-8ac5b81921cd}\RP1154\A0091197.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\system volume information\_restore{b6441411-87b0-4bda-9e4a-8ac5b81921cd}\RP1154\A0091212.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. 7/31/2011 8:40:26 PM mbam Full scan (C:\|) Windows 5.1.2600 Service Pack 2 Memory Modules Infected: c:\WINDOWS\system32\6to4v32.dll (Trojan.Dropper) -> Delete on reboot. Files Infected: c:\WINDOWS\system32\6to4v32.dll (Trojan.Dropper) -> Delete on reboot. c:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> Quarantined and deleted successfully. 8/1/2011 8:47:12 AM mbam Quick scan Windows 5.1.2600 Service Pack 2 (Safe Mode) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (Trojan.Downloader) -> Quarantined and deleted successfully. Files Infected: c:\WINDOWS\Temp\lrvufi\setup.exe (Trojan.Downloader) -> Quarantined and deleted successfully. 8/2/2011 10:39:38 AM mbam Quick scan Windows 5.1.2600 Service Pack 2 Files Infected: c:\WINDOWS\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully. c:\WINDOWS\Tasks\{810401e2-dde0-454e-b0e2-aa89c9e5967c}.job (Trojan.FraudPack) -> Quarantined and deleted successfully. 8/3/2011 10:18:46 AM mbam Full scan (C:\| Windows 5.1.2600 Service Pack 2 (Safe Mode) Files Infected: c:\system volume information\_restore{b6441411-87b0-4bda-9e4a-8ac5b81921cd}\RP1\A0000020.exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\system volume information\_restore{b6441411-87b0-4bda-9e4a-8ac5b81921cd}\RP1\A0000021.exe (Trojan.Downloader) -> Quarantined and deleted successfully.