MBAM log (I have re-booted as it asked me, done nothing else except copy log here)
Malwarebytes' Anti-Malware 1.40
Database version: 2719
Windows 5.1.2600 Service Pack 3
8/30/2009 6:02:49 PM
mbam-log-2009-08-30 (18-02-49).txt
Scan type: Quick Scan
Objects scanned: 121898
Time elapsed: 11 minute(s), 11 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 35
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Monopod (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\net (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\kbiwkmiwwkiqad.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\kbiwkmlevymxxu.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\kbiwkmoxbwtumg.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\kbiwkmqeecblnn.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\kbiwkmrielesix.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\net.net (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vsfocemupnsjne.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vsfocevrgyyjdy.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UACgkykedkytb.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UACoviylfxyxw.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UACsvsawnqjpk.dll (Rogue.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UACuoyuehodxl.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kbiwkmwsp.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\kbiwkmyctqeeci.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\drivers\kbiwkmxednclqe.sys (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\drivers\UACjgijxulrvq.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\prun.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\UAC2bdc.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\UAC471a.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\UAC6001.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\UAC60e6.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\rasvsnet.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\recmsaxonw.tmp (Rogue.AVCare) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\soeacwrxmn.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\xomcwrnsae.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\xpre.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\kbiwkmvnmduyfqqy.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UACptiritindo.dat (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UACdhaowybenh.db (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vsfoceknbdosiw.dat (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vsfocelldbosru.dat (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Desktop\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.40
Database version: 2719
Windows 5.1.2600 Service Pack 3
8/30/2009 6:02:49 PM
mbam-log-2009-08-30 (18-02-49).txt
Scan type: Quick Scan
Objects scanned: 121898
Time elapsed: 11 minute(s), 11 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 35
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Monopod (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\net (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\kbiwkmiwwkiqad.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\kbiwkmlevymxxu.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\kbiwkmoxbwtumg.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\kbiwkmqeecblnn.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\kbiwkmrielesix.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\net.net (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vsfocemupnsjne.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vsfocevrgyyjdy.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UACgkykedkytb.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UACoviylfxyxw.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UACsvsawnqjpk.dll (Rogue.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UACuoyuehodxl.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kbiwkmwsp.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\kbiwkmyctqeeci.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\drivers\kbiwkmxednclqe.sys (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\drivers\UACjgijxulrvq.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\prun.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\UAC2bdc.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\UAC471a.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\UAC6001.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\UAC60e6.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\rasvsnet.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\recmsaxonw.tmp (Rogue.AVCare) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\soeacwrxmn.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\xomcwrnsae.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\xpre.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Local Settings\Temp\kbiwkmvnmduyfqqy.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UACptiritindo.dat (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UACdhaowybenh.db (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vsfoceknbdosiw.dat (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vsfocelldbosru.dat (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris W\Desktop\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.