Zayne
2007-09-18, 18:41
I am having problems like I've never seen before. Memory access violations, weird things popping up when Windows starts up, my avast! has become corrupted and asks if it's ok to open everytime I start Windows, the avast! Mail Scanner is constantly scanning mail being sent out to all kinds of hostnames. I fear everything on my computer has been compromised.
I've tried all programs listed in other threads about Virtumonde to no avail. I ran S&D in Safe Mode and it found nothing. I just installed ZoneAlarm to try to stop these outgoing emails, which I think has worked. Here are my Kaspersky and HJT logs, which as you can see, basically every executable on my computer has been compromised.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2007-09-18 10:51
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 18/09/2007
Kaspersky Anti-Virus database records: 420148
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 55114
Number of viruses found: 3
Number of infected objects: 2377
Number of suspicious objects: 548
Duration of the scan process: 01:01:18
Infected Object Name / Virus Name / Last Action
C:\AVSVideoTools\Manager\AVSVTManager.exe Infected: Virus.Win32.Virut.q skipped
C:\AVSVideoTools\SmartConverter\AVSSmartConverter-orig.exe Infected: Virus.Win32.Virut.q skipped
C:\AVSVideoTools\SmartConverter\AVSSmartConverter.exe Infected: Virus.Win32.Virut.q skipped
C:\AVSVideoTools\VideoConverter\AVSVideoConverter4-orig.exe Infected: Virus.Win32.Virut.q skipped
C:\AVSVideoTools\VideoConverter\AVSVideoConverter4.exe Infected: Virus.Win32.Virut.q skipped
C:\AVSVideoTools\VideoConverter\CaptureWizard.exe Infected: Virus.Win32.Virut.q skipped
C:\AVSVideoTools\VideoConverter\Registration.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\javacpl.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\javaw.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\keytool.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\kinit.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\klist.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\ktab.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\orbd.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\pack200.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\policytool.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\rmid.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\rmiregistry.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\servertool.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\unpack200.exe Infected: Virus.Win32.Virut.q skipped
C:\check_LSA7.txt Object is locked skipped
C:\ConvertXtoDVD\lang\Lang_Editor.exe Infected: Virus.Win32.Virut.q skipped
C:\DiscCreator\DiscCreator.exe Infected: Virus.Win32.Virut.q skipped
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-09182007-030500.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Matthew\Application Data\Microsoft\Installer\{D27BDB5D-3B4C-44F0-A648-BD00B0E79B39}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe Infected: Virus.Win32.Virut.q skipped
C:\Documents and Settings\Matthew\Application Data\Microsoft\Installer\{D27BDB5D-3B4C-44F0-A648-BD00B0E79B39}\Utility.exe1_D27BDB5D3B4C44F0A648BD00B0E79B39.exe Suspicious: Type_Win32 skipped
C:\Documents and Settings\Matthew\Application Data\Microsoft\Installer\{D27BDB5D-3B4C-44F0-A648-BD00B0E79B39}\Utility.exe2_D27BDB5D3B4C44F0A648BD00B0E79B39.exe Infected: Virus.Win32.Virut.q skipped
C:\Documents and Settings\Matthew\Application Data\Microsoft\Installer\{D27BDB5D-3B4C-44F0-A648-BD00B0E79B39}\Utility.exe_D27BDB5D3B4C44F0A648BD00B0E79B39.exe Infected: Virus.Win32.Virut.q skipped
C:\Documents and Settings\Matthew\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped
C:\Documents and Settings\Matthew\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\Desktop\Europa.Universalis.3-RELOADED\New Folder\autoplay.exe Infected: Virus.Win32.Virut.q skipped
C:\Documents and Settings\Matthew\Desktop\Europa.Universalis.3-RELOADED\New Folder\Setup.exe Infected: Virus.Win32.Virut.q skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\AOL OCP\AIM\Storage\data\i3lacksun\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{010CD007-5539-4970-B442-7CE2DCF369ED} Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{1CF62812-409A-4BE0-873F-8F0D3A572C6D} Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\History\History.IE5\MSHist012007091820070919\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Temp\~DF8E82.tmp Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Temp\~DF9428.tmp Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Matthew\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\hbwpb.exe Object is locked skipped
C:\hxvaqsbo.exe Object is locked skipped
C:\mIRC\mirc.exe Infected: Virus.Win32.Virut.q skipped
C:\NetAlyzer\NetAlyzer.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Adobe\Acrobat 6.0\Reader\AdobeUpdateManager.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Printme\ConsoleApp.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Adobe\Acrobat 6.0\Reader\Updater\acroaum.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Common Files\Ahead\Lib\NeroScoutOptions.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\Ahead\Lib\NeroSearchAdvanced.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe Suspicious: Type_Win32 skipped
C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\Ahead\RemoteControl\NeroRemoteCtrlHandler.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\AVSMedia\ActiveX\Repair.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\AVSMedia\MobileUploader\Uploader.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft (2)\Uninstall.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe Suspicious: Type_Win32 skipped
C:\Program Files\Creative\MediaSource5\CTMALitU.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\MediaSource5\CTMetAcU.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\MediaSource5\CTQSWizu.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\MediaSource5\CTSUAppu.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\MediaSource5\startMSu.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Product Registration\English\InetReg.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Shared Files\CDAsvc.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Shared Files\CTRegSvr.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Shared Files\CTRegSvu.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Console Launcher\CTAPR2.exe Suspicious: Type_Win32 skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Console Launcher\MdSwtchu.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Diagnostics\diagnos3.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Program\setup.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Program\support\amd64\ctzapxx.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Program\support\i386\ctzapxx.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Program\wdm\common\i386\oalinst.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Support\System Information\CTSI.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\CDS\CDSVersion.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\DVD Suite\OLRSubmission\OLRStateCheck.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\DVD Suite\OLRSubmission\OLRSubmission.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\DVD Suite\PowerStarter.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\PowerDVD\CLDMA.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\PowerDVD\cltest.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\PowerDVD\ddtester.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\PowerDVD\dvdrgn.exe Suspicious: Type_Win32 skipped
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe Suspicious: Type_Win32 skipped
C:\Program Files\CyberLink\PowerProducer\CLDMA.exe Suspicious: Type_Win32 skipped
C:\Program Files\CyberLink\PowerProducer\CLDrvChk.exe Suspicious: Type_Win32 skipped
C:\Program Files\CyberLink\PowerProducer\Producer.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\Shared Files\richvideoinstall.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\Shared Files\richvideouninstall.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Gigabyte\ET5\ET5SC.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Gigabyte\VGA Utility Manager\Utility.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Gigabyte\VGA Utility Manager\VTuner.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avgamsvr.exe Suspicious: Type_Win32 skipped
C:\Program Files\Grisoft\AVG7\avgcc.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avgdiag.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avginet.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avgrssvc.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avgupdln.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avgupsvc.exe Suspicious: Type_Win32 skipped
C:\Program Files\Grisoft\AVG7\avgvv.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avgw.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\setup.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\InstallShield Installation Information\{E0AD4033-D89B-11D7-97C2-00055D0CA761}\Setup.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe Suspicious: Type_Win32 skipped
C:\Program Files\Internet Explorer\Connection Wizard\icwconn2.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Internet Explorer\Connection Wizard\icwrmind.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Internet Explorer\Connection Wizard\icwtutor.exe Suspicious: Type_Win32 skipped
C:\Program Files\Internet Explorer\Connection Wizard\inetwiz.exe Suspicious: Type_Win32 skipped
C:\Program Files\Internet Explorer\Connection Wizard\isignup.exe Suspicious: Type_Win32 skipped
C:\Program Files\Internet Explorer\iedw.exe Suspicious: Type_Win32 skipped
C:\Program Files\Internet Explorer\iexplore.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Movie Maker\moviemk.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\MSN\MSNCoreFiles\copymar.exe Suspicious: Type_Win32 skipped
C:\Program Files\MSN\MSNCoreFiles\msn6.exe Suspicious: Type_Win32 skipped
C:\Program Files\MSN\MSNCoreFiles\Setup\msnunin.exe Suspicious: Type_Win32 skipped
C:\Program Files\MSN\MSNCoreFiles\update.exe Suspicious: Type_Win32 skipped
C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\MSN Gaming Zone\Windows\zClientm.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Nero\Nero 7\Core\nero.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Nero\Nero 7\Core\NeroCmd.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Nero\Nero 7\Nero BackItUp\BackItUp.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe Suspicious: Type_Win32 skipped
C:\Program Files\Nero\Nero 7\Nero BackItUp\NBSFtp.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\NetMeeting\cb32.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\NetMeeting\conf.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Outlook Express\msimn.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Outlook Express\setup50.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Outlook Express\wab.exe Suspicious: Type_Win32 skipped
C:\Program Files\Paradox Interactive\Europa Universalis III\eu3.exe Suspicious: Type_Win32 skipped
C:\Program Files\Paradox Interactive\Europa Universalis III\movies\binkplay.exe Object is locked skipped
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Connect 2\wmccds.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Connect 2\WMCCFG.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\dlimport.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\migrate.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\mplayer2.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\setup_wm.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmdbexport.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmlaunch.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmpenc.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmplayer.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmpnetwk.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmpnscfg.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmpshare.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmsetsdk.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows NT\Accessories\wordpad.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows NT\dialer.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows NT\hypertrm.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows NT\Pinball\pinball.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\WinRAR\RarExtLoader.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\WinRAR\Uninstall.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\WinRAR\UnRAR.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\WinRAR\WinRAR.exe Infected: Virus.Win32.Virut.q skipped
I've tried all programs listed in other threads about Virtumonde to no avail. I ran S&D in Safe Mode and it found nothing. I just installed ZoneAlarm to try to stop these outgoing emails, which I think has worked. Here are my Kaspersky and HJT logs, which as you can see, basically every executable on my computer has been compromised.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2007-09-18 10:51
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 18/09/2007
Kaspersky Anti-Virus database records: 420148
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 55114
Number of viruses found: 3
Number of infected objects: 2377
Number of suspicious objects: 548
Duration of the scan process: 01:01:18
Infected Object Name / Virus Name / Last Action
C:\AVSVideoTools\Manager\AVSVTManager.exe Infected: Virus.Win32.Virut.q skipped
C:\AVSVideoTools\SmartConverter\AVSSmartConverter-orig.exe Infected: Virus.Win32.Virut.q skipped
C:\AVSVideoTools\SmartConverter\AVSSmartConverter.exe Infected: Virus.Win32.Virut.q skipped
C:\AVSVideoTools\VideoConverter\AVSVideoConverter4-orig.exe Infected: Virus.Win32.Virut.q skipped
C:\AVSVideoTools\VideoConverter\AVSVideoConverter4.exe Infected: Virus.Win32.Virut.q skipped
C:\AVSVideoTools\VideoConverter\CaptureWizard.exe Infected: Virus.Win32.Virut.q skipped
C:\AVSVideoTools\VideoConverter\Registration.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\javacpl.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\javaw.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\keytool.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\kinit.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\klist.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\ktab.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\orbd.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\pack200.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\policytool.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\rmid.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\rmiregistry.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\servertool.exe Infected: Virus.Win32.Virut.q skipped
C:\Azureus\jre\bin\unpack200.exe Infected: Virus.Win32.Virut.q skipped
C:\check_LSA7.txt Object is locked skipped
C:\ConvertXtoDVD\lang\Lang_Editor.exe Infected: Virus.Win32.Virut.q skipped
C:\DiscCreator\DiscCreator.exe Infected: Virus.Win32.Virut.q skipped
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-09182007-030500.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Matthew\Application Data\Microsoft\Installer\{D27BDB5D-3B4C-44F0-A648-BD00B0E79B39}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe Infected: Virus.Win32.Virut.q skipped
C:\Documents and Settings\Matthew\Application Data\Microsoft\Installer\{D27BDB5D-3B4C-44F0-A648-BD00B0E79B39}\Utility.exe1_D27BDB5D3B4C44F0A648BD00B0E79B39.exe Suspicious: Type_Win32 skipped
C:\Documents and Settings\Matthew\Application Data\Microsoft\Installer\{D27BDB5D-3B4C-44F0-A648-BD00B0E79B39}\Utility.exe2_D27BDB5D3B4C44F0A648BD00B0E79B39.exe Infected: Virus.Win32.Virut.q skipped
C:\Documents and Settings\Matthew\Application Data\Microsoft\Installer\{D27BDB5D-3B4C-44F0-A648-BD00B0E79B39}\Utility.exe_D27BDB5D3B4C44F0A648BD00B0E79B39.exe Infected: Virus.Win32.Virut.q skipped
C:\Documents and Settings\Matthew\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped
C:\Documents and Settings\Matthew\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\Desktop\Europa.Universalis.3-RELOADED\New Folder\autoplay.exe Infected: Virus.Win32.Virut.q skipped
C:\Documents and Settings\Matthew\Desktop\Europa.Universalis.3-RELOADED\New Folder\Setup.exe Infected: Virus.Win32.Virut.q skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\AOL OCP\AIM\Storage\data\i3lacksun\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{010CD007-5539-4970-B442-7CE2DCF369ED} Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{1CF62812-409A-4BE0-873F-8F0D3A572C6D} Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\History\History.IE5\MSHist012007091820070919\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Temp\~DF8E82.tmp Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Temp\~DF9428.tmp Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Matthew\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\hbwpb.exe Object is locked skipped
C:\hxvaqsbo.exe Object is locked skipped
C:\mIRC\mirc.exe Infected: Virus.Win32.Virut.q skipped
C:\NetAlyzer\NetAlyzer.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Adobe\Acrobat 6.0\Reader\AdobeUpdateManager.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Printme\ConsoleApp.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Adobe\Acrobat 6.0\Reader\Updater\acroaum.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Common Files\Ahead\Lib\NeroScoutOptions.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\Ahead\Lib\NeroSearchAdvanced.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe Suspicious: Type_Win32 skipped
C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\Ahead\RemoteControl\NeroRemoteCtrlHandler.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\AVSMedia\ActiveX\Repair.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\AVSMedia\MobileUploader\Uploader.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft (2)\Uninstall.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe Suspicious: Type_Win32 skipped
C:\Program Files\Creative\MediaSource5\CTMALitU.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\MediaSource5\CTMetAcU.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\MediaSource5\CTQSWizu.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\MediaSource5\CTSUAppu.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\MediaSource5\startMSu.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Product Registration\English\InetReg.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Shared Files\CDAsvc.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Shared Files\CTRegSvr.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Shared Files\CTRegSvu.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Console Launcher\CTAPR2.exe Suspicious: Type_Win32 skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Console Launcher\MdSwtchu.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Diagnostics\diagnos3.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Program\setup.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Program\support\amd64\ctzapxx.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Program\support\i386\ctzapxx.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Sound Blaster X-Fi\Program\wdm\common\i386\oalinst.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Creative\Support\System Information\CTSI.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\CDS\CDSVersion.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\DVD Suite\OLRSubmission\OLRStateCheck.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\DVD Suite\OLRSubmission\OLRSubmission.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\DVD Suite\PowerStarter.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\PowerDVD\CLDMA.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\PowerDVD\cltest.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\PowerDVD\ddtester.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\PowerDVD\dvdrgn.exe Suspicious: Type_Win32 skipped
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe Suspicious: Type_Win32 skipped
C:\Program Files\CyberLink\PowerProducer\CLDMA.exe Suspicious: Type_Win32 skipped
C:\Program Files\CyberLink\PowerProducer\CLDrvChk.exe Suspicious: Type_Win32 skipped
C:\Program Files\CyberLink\PowerProducer\Producer.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\Shared Files\richvideoinstall.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\CyberLink\Shared Files\richvideouninstall.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Gigabyte\ET5\ET5SC.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Gigabyte\VGA Utility Manager\Utility.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Gigabyte\VGA Utility Manager\VTuner.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avgamsvr.exe Suspicious: Type_Win32 skipped
C:\Program Files\Grisoft\AVG7\avgcc.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avgdiag.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avginet.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avgrssvc.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avgupdln.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avgupsvc.exe Suspicious: Type_Win32 skipped
C:\Program Files\Grisoft\AVG7\avgvv.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\avgw.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Grisoft\AVG7\setup.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\InstallShield Installation Information\{E0AD4033-D89B-11D7-97C2-00055D0CA761}\Setup.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe Suspicious: Type_Win32 skipped
C:\Program Files\Internet Explorer\Connection Wizard\icwconn2.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Internet Explorer\Connection Wizard\icwrmind.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Internet Explorer\Connection Wizard\icwtutor.exe Suspicious: Type_Win32 skipped
C:\Program Files\Internet Explorer\Connection Wizard\inetwiz.exe Suspicious: Type_Win32 skipped
C:\Program Files\Internet Explorer\Connection Wizard\isignup.exe Suspicious: Type_Win32 skipped
C:\Program Files\Internet Explorer\iedw.exe Suspicious: Type_Win32 skipped
C:\Program Files\Internet Explorer\iexplore.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Movie Maker\moviemk.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\MSN\MSNCoreFiles\copymar.exe Suspicious: Type_Win32 skipped
C:\Program Files\MSN\MSNCoreFiles\msn6.exe Suspicious: Type_Win32 skipped
C:\Program Files\MSN\MSNCoreFiles\Setup\msnunin.exe Suspicious: Type_Win32 skipped
C:\Program Files\MSN\MSNCoreFiles\update.exe Suspicious: Type_Win32 skipped
C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\MSN Gaming Zone\Windows\zClientm.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Nero\Nero 7\Core\nero.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Nero\Nero 7\Core\NeroCmd.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Nero\Nero 7\Nero BackItUp\BackItUp.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe Suspicious: Type_Win32 skipped
C:\Program Files\Nero\Nero 7\Nero BackItUp\NBSFtp.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\NetMeeting\cb32.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\NetMeeting\conf.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Outlook Express\msimn.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Outlook Express\setup50.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Outlook Express\wab.exe Suspicious: Type_Win32 skipped
C:\Program Files\Paradox Interactive\Europa Universalis III\eu3.exe Suspicious: Type_Win32 skipped
C:\Program Files\Paradox Interactive\Europa Universalis III\movies\binkplay.exe Object is locked skipped
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Connect 2\wmccds.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Connect 2\WMCCFG.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\dlimport.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\migrate.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\mplayer2.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\setup_wm.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmdbexport.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmlaunch.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmpenc.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmplayer.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmpnetwk.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmpnscfg.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmpshare.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows Media Player\wmsetsdk.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows NT\Accessories\wordpad.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows NT\dialer.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows NT\hypertrm.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\Windows NT\Pinball\pinball.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\WinRAR\RarExtLoader.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\WinRAR\Uninstall.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\WinRAR\UnRAR.exe Infected: Virus.Win32.Virut.q skipped
C:\Program Files\WinRAR\WinRAR.exe Infected: Virus.Win32.Virut.q skipped