PDA

View Full Version : not a virus adware



verity
2007-06-06, 00:52
Cant get rid of this and it is driving me potty everytime I m online. Please can some tell me how to kill this. Thanks Verity

Tuesday, June 05, 2007 11:24:48 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 6/06/2007
Kaspersky Anti-Virus database records: 340041


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
F:\

Scan Statistics
Total number of scanned objects 96413
Number of viruses found 3
Number of infected objects 5
Number of suspicious objects 0
Duration of the scan process 00:58:54

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-06-05_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped

C:\Documents and Settings\All Users\Documents\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\All Users\Documents\Document.rtf Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Desktop.ini Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\MUSIC.ASX Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\MUSIC.BMP Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\MUSIC.WMA Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Music\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Favorites -- 4 and 5 star rated.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Favorites -- Have not heard recently.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Favorites -- Listen to late at night.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Favorites -- Listen to on Weekdays.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Favorites -- Listen to on Weekends.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Favorites -- One Audio CD worth.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Favorites -- One Data CD-R worth.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Fresh tracks -- yet to be played.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Fresh tracks -- yet to be rated.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Fresh tracks.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\High bitrate media in my library.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Low bitrate media in my library.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Music tracks I dislike.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Music tracks I have not rated.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\004C8367\Music tracks with content protection.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\desktop.ini Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\000490C3\01_Music_auto_rated_at_5_stars.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\000490C3\02_Music_added_in_the_last_month.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\000490C3\03_Music_rated_at_4_or_5_stars.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\000490C3\04_Music_played_in_the_last_month.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\000490C3\05_Pictures_taken_in_the_last_month.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\000490C3\06_Pictures_rated_4_or_5_stars.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\000490C3\07_TV_recorded_in_the_last_week.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\000490C3\08_Video_rated_at_4_or_5_stars.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\000490C3\09_Music_played_the_most.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\000490C3\10_All_Music.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\000490C3\11_All_Pictures.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\000490C3\12_All_Video.wpl Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\desktop.ini Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Pictures\Desktop.ini Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg Object is locked skipped

C:\Documents and Settings\All Users\Documents\My Videos\Desktop.ini Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Rae Stuckey\Cookies\INDEX.DAT Object is locked skipped

C:\Documents and Settings\Rae Stuckey\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped

C:\Documents and Settings\Rae Stuckey\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Rae Stuckey\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Rae Stuckey\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\Rae Stuckey\Local Settings\History\History.IE5\MSHist012007060520070606\index.dat Object is locked skipped

C:\Documents and Settings\Rae Stuckey\Local Settings\Temp\~DFE9CB.tmp Object is locked skipped

C:\Documents and Settings\Rae Stuckey\Local Settings\Temp\~DFEE45.tmp Object is locked skipped

C:\Documents and Settings\Rae Stuckey\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Rae Stuckey\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\Rae Stuckey\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Rae Stuckey\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Rae Stuckey\UserData\index.dat Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\MailBuddy.log Object is locked skipped

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0056347.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bq skipped

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1113\A0058677.dll Infected: Trojan-Clicker.Win32.Small.mw skipped

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1113\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Internet Logs\DESKTOP.ldb Object is locked skipped

C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped

C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped

C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped

C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped

C:\WINDOWS\ModemLog_BCM V.92 56K Voicemodem.txt Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{FD3E3DDC-2CAB-4D19-AD99-487A36521EA6}.bin Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\ddcbayw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bq skipped

C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat Object is locked skipped

C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx Object is locked skipped

C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.dat Object is locked skipped

C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.idx Object is locked skipped

C:\WINDOWS\SYSTEM32\dsapb.exe Object is locked skipped

C:\WINDOWS\SYSTEM32\geeba.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped

C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\wvurron.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bq skipped

C:\WINDOWS\Temp\ZLT0776a.TMP Object is locked skipped

C:\WINDOWS\Temp\ZLT07774.TMP Object is locked skipped

C:\WINDOWS\WIADEBUG.LOG Object is locked skipped

C:\WINDOWS\WIASERVC.LOG Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

pskelley
2007-06-06, 16:34
Welcome to Safer Networking, if you still need help and are not receiving it elsewhere, it appears you have missed some important instructions our administrator has posted at the top of the forum, especially this: "BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please read and follow all instructions and post all required logs or reports, anything less will slow your process.
Use "Post Reply" to post the information in the instructions and stay in the same topic.

It would be most helpful if you would start with the directions that are pinned to the top of the forum where you posted. When you get to the HJT log, please use these instructions.

Download Trend Micro Hijack This™
http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php?page=download
Download it to your Program Files folder.
Doubleclick the HijackThis_V2.exe to start it.
Click "Do a System Scan and save a logfile"
This will create a HijackThislog.
Copy and paste the contents of the log in your next reply

Thanks

tashi
2007-06-11, 23:18
This topic has been archived due to lack of a response.

If you need it re-opened, please send me a private message (pm) and provide a link to the thread. Applies only to the original poster, anyone else with similar problems please start a new topic.