Malwarebytes' Anti-Malware 1.44
Database version: 3721
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/10/2010 7:48:53 PM
mbam-log-2010-02-10 (19-48-53).txt
Scan type: Quick Scan
Objects scanned: 137813
Time elapsed: 3 minute(s), 32 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 4
Memory Processes Infected:
C:\Program Files\AV\antivir.exe (Rogue.Antivir2010) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{d34d56e9-b37b-4c37-a854-1ac144592d5c} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d34d56e9-b37b-4c37-a854-1ac144592d5c} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d34d56e9-b37b-4c37-a854-1ac144592d5c} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{45296DBE-C6F0-44C0-86B4-5AA85C61894B}_is1 (Rogue.AntiSpyware2010) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\Environment\evapp (Rogue.Antivir2010) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Environment\evuninst (Rogue.Antivir2010) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\av (Rogue.Antivir2010) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Common Files\Uninstall\AV (Rogue.Antivir2010) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\UpdateCheck.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\Uninstall\AV\Uninstall.lnk (Rogue.Antivir2010) -> Quarantined and deleted successfully.
C:\Documents and Settings\{username}\Desktop\Antivir.lnk (Rogue.Antivir2010) -> Quarantined and deleted successfully.
C:\Program Files\AV\antivir.exe (Rogue.Antivir2010) -> Quarantined and deleted successfully.