OK, So I forgot to update, I am updating right now and will rescan. This is the log for the 1st scan
Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 16
Registry Values Infected: 7
Registry Data Items Infected: 8
Folders Infected: 6
Files Infected: 36
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\WINDOWS\system32\johakehe.dll (Trojan.Vundo.H) → Delete on reboot.
C:\WINDOWS\system32\majubilu.dll (Trojan.Vundo) → Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{b45a4b16-23f2-41ad-f4e4-00aac39c0004} (Trojan.Vundo.H) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{b45a4b16-23f2-41ad-f4e4-00aac39c0004} (Trojan.Vundo.H) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{6a2a6263-87a3-40ab-b669-e707680980a4} (Trojan.Vundo.H) → Delete on reboot.
HKEY_CLASSES_ROOT\CLSID{0ed403e8-470a-4a8a-85a4-d7688cfe39a3} (Adware.Gamevance) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{0ed403e8-470a-4a8a-85a4-d7688cfe39a3} (Adware.Gamevance) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{afd4ad01-58c1-47db-a404-fbe00a6c5486} (Trojan.BHO) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib{014c4232-6904-47b9-9144-7e0fb7277444} (Adware.Gamevance) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface{0ab02d6c-f605-425f-b7cb-b9e96c9faf1e} (Adware.Gamevance) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface{32864a05-9d09-472c-abd0-081818ec713b} (Adware.Gamevance) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{beac7dc8-e106-4c6a-931e-5a42e7362883} (Adware.Gamevance) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{beac7dc8-e106-4c6a-931e-5a42e7362883} (Adware.Gamevance) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gamevance (Adware.Gamevance) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AVR (Rogue.AdvancedVirusRemover) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify__c0031fc4 (Trojan.Vundo) → Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mizepobip (Trojan.Vundo.H) → Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\38514930 (Trojan.FakeAlert.H) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler{6a2a6263-87a3-40ab-b669-e707680980a4} (Trojan.Vundo.H) → Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\yabivumok (Trojan.Vundo.H) → Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Agent.exe (Trojan.FraudPack) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) → Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) → Data: c:\windows\system32\johakehe.dll → Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) → Data: system32\johakehe.dll → Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
Folders Infected:
C:\Documents and Settings\All Users\Application Data\38514930 (Rogue.Multiple) → Quarantined and deleted successfully.
C:\Program Files\AdvancedVirusRemover (Rogue.AdvancedVirusRemover) → Quarantined and deleted successfully.
C:\Program Files\Gamevance (Adware.Gamevance) → Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\AntiVirus Plus (Rogue.AntiVirusPlus) → Quarantined and deleted successfully.
C:\Documents and Settings\Nancy\Start Menu\Programs\AntiVirus Plus (Rogue.AntiVirusPlus) → Quarantined and deleted successfully.
C:\WINDOWS\system32\lowsec (Stolen.data) → Quarantined and deleted successfully.