howie1108
Topic Starter
A brief description of the situation:
My OS is a windows XP, and for about a month now I have had an infection on my computer. I get a really annoying pop up that occurs whenever I open a folder, EG I click My Computer -> Local Disk C -> Program File **Then I get the virus pop up**. I have followed the instructions, downloaded Malwarebyte's Antimalware program and HJThis. After doing scans etc and following the instructions, I still get the error. The error is:
WARNING! {USERNAME} You do not have any anti-virus set up, please download our anti-virus ware.
Then there is just a "Yes" or a "No" button.
Even if I click No, it will try to redirect me to their site, but my Panda software (I installed it after I had the virus and it didn't help me one bit unfortunately) blocks me from being directed to the site fortunately. But, if I click Yes they will direct me to the site without my Panda Software blocking me. I was able to find out the virus name, IE-AV.exe
My problem is that all I want to to do is remove the pop up so it does not occur every time I try to open a folder (it makes it impossible for me to browse my OS since I get redirected every click).
So you get the problem now, now for the log files.
Hijackthis Log File:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:01:59 AM, on 8/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\AVENGINE.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
c:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\ApvxdWin.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Documents and Settings\Howard\Desktop\Everything For Ventrilo\WinAmp\winampa.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\Popupscn.exe
C:\Program Files\TopDesk\topdesk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\SRVLOAD.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\WebProxy.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PavBckPT.exe
C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\program files\mozilla firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.pimpmysearch.com/home.html?gname=Howie
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F3 - REG:win.ini: run="C:\Documents and Settings\Howard\Application Data\Adobe\Manager.exe"
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Internet Security 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Security\Panda Internet Security 2008\Inicio.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Documents and Settings\Howard\Desktop\Everything For Ventrilo\WinAmp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [987cb631] rundll32.exe "C:\WINDOWS\system32\iugmankh.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Pop-Up_Scanner] "C:\PROGRA~1\PANICW~1\POP-UP~1\Popupscn.exe"
O4 - HKCU\..\Run: [TopDesk] C:\Program Files\TopDesk\topdesk.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - AppInit_DLLs: wbsys.dll sfwhgf.dll wddsfx.dll rbgsjb.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe
–
End of file - 8451 bytes
Malwarebytes' Anti-Malware Log File:
Malwarebytes' Anti-Malware 1.24
Database version: 1054
Windows 5.1.2600 Service Pack 2
2:22:04 AM 8/15/2008
malwarebyte antimalware log file
Scan type: Quick Scan
Objects scanned: 43197
Time elapsed: 9 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 7
Registry Keys Infected: 32
Registry Values Infected: 3
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 62
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\fccccYpn.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\iugmankh.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tuvVmNGX.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wddsfx.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\rbgsjb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\edmwno.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\aoltoolbar.dll (Trojan.FakeAlert) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77c70b3b-a6fe-486c-84ed-9a89082b156b} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{77c70b3b-a6fe-486c-84ed-9a89082b156b} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8b926775-aee0-4a97-9118-3afb810af18d} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{8b926775-aee0-4a97-9118-3afb810af18d} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6230596f-3a44-4cdf-815b-372fa03c75d6} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6230596f-3a44-4cdf-815b-372fa03c75d6} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvvmngx (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{fb0e529a-3d2c-473e-83fe-9e56ac6cc0eb} (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fb0e529a-3d2c-473e-83fe-9e56ac6cc0eb} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\diablo (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\battle.net (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{d5e5cfec-bece-41a5-9840-0bdd4281c2f8} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{5a863b4c-7a56-4b72-ae6a-d79dd66b1a06} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\987cb631 (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6230596f-3a44-4cdf-815b-372fa03c75d6} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run (Trojan.Agent) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\fccccypn -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\fccccypn -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\fccccYpn.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\npYccccf.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\npYccccf.ini2 (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\edmwno.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\iugmankh.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\hknamgui.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ncaptbyy.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\yybtpacn.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\qtqhrwdg.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\gdwrhqtq.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\sooothgt.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tghtooos.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\xkoeiqxt.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\txqieokx.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ydmqixkt.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tkxiqmdy.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ypeyctmw.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wmtcyepy.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tuvVmNGX.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wddsfx.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\rbgsjb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\aoltoolbar.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\diabunin.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\bnetunin.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\djwcgqac.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\jgxndcjs.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\jnbxdoiy.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\jrncvbnf.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\jrvjrc.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\kfyevdsl.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\kxvtpecy.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\takvdj.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wercoegb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wgrkxrkq.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wmszzd.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\doigot.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\qdhxuqtg.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\rfthrj.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\rtvquz.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tyrbduhc.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\uivukd.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\gztbfw.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\heicgf.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\cgerrqou.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\aktjjaik.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\vzhtbb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\bcrpxh.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wwngdb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wybrfhkt.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\xhqijb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\xmsrbgxj.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\xstbvspb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\xtwjolnc.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ykidkd.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ytfrprjp.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ploaawti.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\feuiyvem.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\qxridq.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> No action taken.
C:\WINDOWS\cookies.ini (Malware.Trace) -> No action taken.
C:\WINDOWS\BM9b4f85ad.xml (Trojan.Vundo) -> No action taken.
C:\WINDOWS\BM9b4f85ad.txt (Trojan.Vundo) -> No action taken.
It seems to be that the alwarebytes' Anti-Malware was not able to remove the virus? Also please, if you reply, please make it easy and not sound technical as I might not understand alot of what is being said (because I know you guys are a lot smarter than me).
My OS is a windows XP, and for about a month now I have had an infection on my computer. I get a really annoying pop up that occurs whenever I open a folder, EG I click My Computer -> Local Disk C -> Program File **Then I get the virus pop up**. I have followed the instructions, downloaded Malwarebyte's Antimalware program and HJThis. After doing scans etc and following the instructions, I still get the error. The error is:
WARNING! {USERNAME} You do not have any anti-virus set up, please download our anti-virus ware.
Then there is just a "Yes" or a "No" button.
Even if I click No, it will try to redirect me to their site, but my Panda software (I installed it after I had the virus and it didn't help me one bit unfortunately) blocks me from being directed to the site fortunately. But, if I click Yes they will direct me to the site without my Panda Software blocking me. I was able to find out the virus name, IE-AV.exe
My problem is that all I want to to do is remove the pop up so it does not occur every time I try to open a folder (it makes it impossible for me to browse my OS since I get redirected every click).
So you get the problem now, now for the log files.
Hijackthis Log File:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:01:59 AM, on 8/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\AVENGINE.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
c:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\ApvxdWin.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Documents and Settings\Howard\Desktop\Everything For Ventrilo\WinAmp\winampa.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\Popupscn.exe
C:\Program Files\TopDesk\topdesk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\SRVLOAD.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\WebProxy.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PavBckPT.exe
C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\program files\mozilla firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.pimpmysearch.com/home.html?gname=Howie
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F3 - REG:win.ini: run="C:\Documents and Settings\Howard\Application Data\Adobe\Manager.exe"
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Internet Security 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Security\Panda Internet Security 2008\Inicio.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Documents and Settings\Howard\Desktop\Everything For Ventrilo\WinAmp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [987cb631] rundll32.exe "C:\WINDOWS\system32\iugmankh.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Pop-Up_Scanner] "C:\PROGRA~1\PANICW~1\POP-UP~1\Popupscn.exe"
O4 - HKCU\..\Run: [TopDesk] C:\Program Files\TopDesk\topdesk.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - AppInit_DLLs: wbsys.dll sfwhgf.dll wddsfx.dll rbgsjb.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe
–
End of file - 8451 bytes
Malwarebytes' Anti-Malware Log File:
Malwarebytes' Anti-Malware 1.24
Database version: 1054
Windows 5.1.2600 Service Pack 2
2:22:04 AM 8/15/2008
malwarebyte antimalware log file
Scan type: Quick Scan
Objects scanned: 43197
Time elapsed: 9 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 7
Registry Keys Infected: 32
Registry Values Infected: 3
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 62
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\fccccYpn.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\iugmankh.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tuvVmNGX.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wddsfx.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\rbgsjb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\edmwno.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\aoltoolbar.dll (Trojan.FakeAlert) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77c70b3b-a6fe-486c-84ed-9a89082b156b} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{77c70b3b-a6fe-486c-84ed-9a89082b156b} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8b926775-aee0-4a97-9118-3afb810af18d} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{8b926775-aee0-4a97-9118-3afb810af18d} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6230596f-3a44-4cdf-815b-372fa03c75d6} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6230596f-3a44-4cdf-815b-372fa03c75d6} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvvmngx (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{fb0e529a-3d2c-473e-83fe-9e56ac6cc0eb} (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fb0e529a-3d2c-473e-83fe-9e56ac6cc0eb} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\diablo (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\battle.net (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{d5e5cfec-bece-41a5-9840-0bdd4281c2f8} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{5a863b4c-7a56-4b72-ae6a-d79dd66b1a06} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\987cb631 (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6230596f-3a44-4cdf-815b-372fa03c75d6} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run (Trojan.Agent) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\fccccypn -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\fccccypn -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\fccccYpn.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\npYccccf.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\npYccccf.ini2 (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\edmwno.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\iugmankh.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\hknamgui.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ncaptbyy.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\yybtpacn.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\qtqhrwdg.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\gdwrhqtq.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\sooothgt.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tghtooos.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\xkoeiqxt.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\txqieokx.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ydmqixkt.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tkxiqmdy.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ypeyctmw.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wmtcyepy.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tuvVmNGX.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wddsfx.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\rbgsjb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\aoltoolbar.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\diabunin.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\bnetunin.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\djwcgqac.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\jgxndcjs.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\jnbxdoiy.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\jrncvbnf.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\jrvjrc.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\kfyevdsl.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\kxvtpecy.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\takvdj.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wercoegb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wgrkxrkq.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wmszzd.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\doigot.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\qdhxuqtg.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\rfthrj.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\rtvquz.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tyrbduhc.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\uivukd.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\gztbfw.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\heicgf.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\cgerrqou.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\aktjjaik.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\vzhtbb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\bcrpxh.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wwngdb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wybrfhkt.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\xhqijb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\xmsrbgxj.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\xstbvspb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\xtwjolnc.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ykidkd.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ytfrprjp.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ploaawti.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\feuiyvem.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\qxridq.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> No action taken.
C:\WINDOWS\cookies.ini (Malware.Trace) -> No action taken.
C:\WINDOWS\BM9b4f85ad.xml (Trojan.Vundo) -> No action taken.
C:\WINDOWS\BM9b4f85ad.txt (Trojan.Vundo) -> No action taken.
It seems to be that the alwarebytes' Anti-Malware was not able to remove the virus? Also please, if you reply, please make it easy and not sound technical as I might not understand alot of what is being said (because I know you guys are a lot smarter than me).