Here’s the mbam log file…scan is done, mbam is giving me the option of remove or ignore… UACpappanybig.dll…saw that found by Avast…mbam didn’t see it what about that???
Database version: 2736
Windows 5.1.2600 Service Pack 2
9/3/2009 1:09:03 PM
mbam-log-2009-09-03 (13-08-06).txt
Scan type: Full Scan (C:|)
Objects scanned: 216329
Time elapsed: 49 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 3
Registry Data Items Infected: 3
Folders Infected: 2
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Malware.Trace) → No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\Environment\avapp (Rogue.PersonalAntiVirus) → No action taken.
HKEY_CURRENT_USER\Environment\avuninst (Rogue.PersonalAntiVirus) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\personalav (Rogue.PersonalAntiVirus) → No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
Folders Infected:
C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) → No action taken.
C:\Program Files\PersonalAV (Rogue.PersonalAntiVirus) → No action taken.
Files Infected:
C:\WINDOWS\system32\msxmlm.dll (Trojan.FakeAlert) → No action taken.
C:\Documents and Settings\family\Local Settings\Temp\drv4865240.exe (Trojan.Dropper) → No action taken.
C:\Program Files\Common Files\Uninstall\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) → No action taken.
C:\WINDOWS\system32\UACwdbxmplvpe.dat (Rootkit.TDSS) → No action taken.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) → No action taken.
Malwarebytes’ Anti-Malware 1.40
Database version: 2736
Windows 5.1.2600 Service Pack 2
9/3/2009 1:09:03 PM
mbam-log-2009-09-03 (13-08-06).txt
Scan type: Full Scan (C:|)
Objects scanned: 216329
Time elapsed: 49 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 3
Registry Data Items Infected: 3
Folders Infected: 2
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Malware.Trace) → No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\Environment\avapp (Rogue.PersonalAntiVirus) → No action taken.
HKEY_CURRENT_USER\Environment\avuninst (Rogue.PersonalAntiVirus) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\personalav (Rogue.PersonalAntiVirus) → No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
Folders Infected:
C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) → No action taken.
C:\Program Files\PersonalAV (Rogue.PersonalAntiVirus) → No action taken.
Files Infected:
C:\WINDOWS\system32\msxmlm.dll (Trojan.FakeAlert) → No action taken.
C:\Documents and Settings\family\Local Settings\Temp\drv4865240.exe (Trojan.Dropper) → No action taken.
C:\Program Files\Common Files\Uninstall\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) → No action taken.
C:\WINDOWS\system32\UACwdbxmplvpe.dat (Rootkit.TDSS) → No action taken.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) → No action taken.