I have a Windows XP PC infected with Windows Antivirus 2009. I have run MalwareBytes Anti-Malware, here is the log:
Malwarebytes' Anti-Malware 1.30
Database version: 1324
Windows 5.1.2600 Service Pack 2
27/10/2008 12:25:19 p.m.
mbam-log-2008-10-27 (12-25-19).txt
Scan type: Quick Scan
Objects scanned: 77049
Time elapsed: 14 minute(s), 43 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 16
Registry Values Infected: 7
Registry Data Items Infected: 0
Folders Infected: 11
Files Infected: 31
Memory Processes Infected:
C:\Program Files\Common Files\DriveCleaner Free\udcsdr.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\Program Files\Common Files\DriveCleaner Free\udcpas.exe (Trojan.Downloader) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\xml.xml (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\{5222008a-dd62-49c7-a735-7bd18ecc7350} (Rogue.VirusRemover) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\{5222008a-dd62-49c7-a735-7bd18ecc7350} (Rogue.VirusRemover) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{9233c3c0-1472-4091-a505-5580a23bb4ac} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e596df5f-4239-4d40-8367-ebadf0165917} (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{01e69986-a054-4c52-abe8-ef63df1c5211} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\virusremover2008 (Rogue.VirusRemove) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\virusremover2008 (Rogue.VirusRemove) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MSFox (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XBTB04482 (Adware.WebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sdr6_check (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pas_check (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\registrydoctor2008 (Rogue.AntiSpywareExpert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{01e69986-a054-4c52-abe8-ef63df1c5211} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{01e69986-a054-4c52-abe8-ef63df1c5211} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\33926651857717257354973341144139 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSFox (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\FindFM Toolbar (Adware.SoftMate) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\DriveCleaner Free (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Program Files\Antivirus 2009 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\RegistryDoctor2008 (Rogue.RegistryDoctor) -> Quarantined and deleted successfully.
C:\Program Files\RegistryDoctor2008 (Rogue.RegistryDoctor) -> Quarantined and deleted successfully.
C:\Program Files\RegistryDoctor2008\Download (Rogue.RegistryDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kids\Application Data\DriveCleaner Free (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kids\Application Data\DriveCleaner Free\Logs (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Application Data\DriveCleaner Free (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Application Data\DriveCleaner Free\Logs (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Start Menu\Antivirus 2009 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\Common Files\DriveCleaner Free\udcsdr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\DriveCleaner Free\udcpas.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\RegistryDoctor2008\registrydoctor.exe (Rogue.AntiSpywareExpert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msxml71.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\scui.cpl (Rogue.XPantivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Local Settings\Temp\~tmpb.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Local Settings\Temp\~tmpc.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Local Settings\Temp\UDC6_0001_D21M1601\installer.exe (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Local Settings\Temporary Internet Files\Content.IE5\8LGLI709\personalantispy_ifree[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Local Settings\Temporary Internet Files\Content.IE5\QSO5QCDN\personalantispy_ifree[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Local Settings\Temporary Internet Files\Content.IE5\UT8TCB8V\personalantispy_ifree[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kids\Application Data\winantiviruspro2007freeinstall[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Program Files\FindFM Toolbar\inst.bat (Adware.SoftMate) -> Quarantined and deleted successfully.
C:\Program Files\FindFM Toolbar\toolbar.inf (Adware.SoftMate) -> Quarantined and deleted successfully.
C:\Program Files\Antivirus 2009\av2009.exe (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\RegistryDoctor2008\RegistryDoctor2008.lnk (Rogue.RegistryDoctor) -> Quarantined and deleted successfully.
C:\Program Files\RegistryDoctor2008\FreeApp.exe (Rogue.RegistryDoctor) -> Quarantined and deleted successfully.
C:\Program Files\RegistryDoctor2008\registrydoctor.ini (Rogue.RegistryDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kids\Application Data\DriveCleaner Free\Logs\update.log (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Application Data\DriveCleaner Free\Logs\update.log (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Start Menu\Antivirus 2009\Antivirus 2009.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Start Menu\Antivirus 2009\Uninstall Antivirus 2009.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Application Data\Microsoft\Internet Explorer\Quick Launch\RegistryDoctor2008.lnk (Rogue.RegistryDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ieupdates.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Local Settings\Temp\xxx4080.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Desktop\RegistryDoctor2008.lnk (Rogue.RegistryDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Favorites\Free porn, nude girls, naked celebrities and hot chicks.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Desktop\Antivirus 2009.lnk (Rogue.Antivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Glenn\Local Settings\Temp\~tmpa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kids\Desktop\Install WinAntiVirus Pro 2007 .lnk (Rogue.Link) -> Quarantined and deleted successfully.