Malwarebytes Anti-Malware (Trial) 1.70.0.1100 www.malwarebytes.org Database version: v2013.01.28.07 Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking) Internet Explorer 9.0.8112.16421 Mateusz :: MATEUSZ-HP [administrator] Protection: Disabled 2013-01-28 18:59:12 MBAM-log-2013-01-28 (20-55-53).txt Scan type: Full scan (C:\|D:\|F:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 863359 Time elapsed: 1 hour(s), 55 minute(s), 45 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 1 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Shell (Exploit.Drop.GSA) -> Bad: (C:\PROGRA~3\dsgsdgdsgdsgw.bat) Good: () -> No action taken. Folders Detected: 0 (No malicious items detected) Files Detected: 8 C:\Program Files (x86)\IVT Corporation\BlueSoleil\Ivt.bluesoleil.8.x.x-patch.exe (Malware.Gen) -> No action taken. C:\Users\Mateusz\wgsdgsdgdsgsd.exe (Trojan.FakeMS) -> No action taken. C:\Users\Mateusz\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\4f4a37d3-3cdf426b (Trojan.FakeMS) -> No action taken. C:\Users\Mateusz\Desktop\Instals\Ivt.bluesoleil.8.x.x-patch\Ivt.bluesoleil.8.x.x-patch.exe (Malware.Gen) -> No action taken. C:\ProgramData\dsgsdgdsgdsgw.bat (Exploit.Drop.GSA) -> No action taken. C:\ProgramData\dsgsdgdsgdsgw.pad (Exploit.Drop.GSA) -> No action taken. C:\ProgramData\dsgsdgdsgdsgw.reg (Exploit.Drop.GSA) -> No action taken. C:\Users\Mateusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk (Trojan.Ransom.SUGen) -> No action taken. (end)