StubbornOx
2007-10-11, 23:05
So I think I got bad codec, so anyway I have nortin's corp edition of A/V It found a version and cleaned the virus. I have ran Spybot multiple times, it says it cleans it run again and its not there. After I reboot my pc it shows back up. here is the kaper and HJT logs, Thanks for any help
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, October 10, 2007 10:43:38 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 11/10/2007
Kaspersky Anti-Virus database records: 430669
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 27187
Number of viruses found: 11
Number of infected objects: 57
Number of suspicious objects: 0
Duration of the scan process: 00:41:01
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Admin\Application Data\MySpace\IM\Logs\MySpaceIM-20071010-211712.log Object is locked skipped
C:\Documents and Settings\Admin\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Temp\~DF3DDD.tmp Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Admin\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Admin\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\007C0000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04B80000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09580000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AC80000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0ADC0000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C5C0000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CF80000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D280000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0E740000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\AntiVirGear 3.8\AntiVirGear 3.8.exe Infected: not-a-virus:FraudTool.Win32.AntiVirGear.e skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0219NAV~.TMP Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008756.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008756.exe/file2 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008756.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008756.exe/file5 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008756.exe/file6 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008756.exe Inno: infected - 5 skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008768.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008769.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008780.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008781.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008787.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008788.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008793.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008795.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008804.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008805.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008818.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008819.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008844.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008846.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008854.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008855.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008863.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008864.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008872.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008873.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008881.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008882.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP149\A0008933.dll Infected: Trojan-Downloader.Win32.Agent.dtg skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP149\A0008942.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP149\A0008943.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP149\A0008951.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP149\A0008952.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP150\A0008972.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP150\A0008973.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP150\A0008978.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP150\A0008979.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP150\A0008992.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP150\A0008993.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009069.exe Infected: Trojan-Downloader.Win32.Zlob.dcl skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009070.exe Infected: Trojan-Downloader.Win32.Zlob.dcg skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009071.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009072.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009073.exe Infected: Trojan-Downloader.Win32.Zlob.dce skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009074.exe Infected: Trojan-Downloader.Win32.Zlob.dcn skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009075.exe Infected: Trojan-Downloader.Win32.Zlob.dcm skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009127.dll Infected: Trojan-Downloader.Win32.Zlob.dcn skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{EAEC68CF-561E-4EEC-9254-C53E2BBC23C4}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
HJT log on next post
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, October 10, 2007 10:43:38 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 11/10/2007
Kaspersky Anti-Virus database records: 430669
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 27187
Number of viruses found: 11
Number of infected objects: 57
Number of suspicious objects: 0
Duration of the scan process: 00:41:01
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Admin\Application Data\MySpace\IM\Logs\MySpaceIM-20071010-211712.log Object is locked skipped
C:\Documents and Settings\Admin\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Temp\~DF3DDD.tmp Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Admin\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Admin\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\007C0000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04B80000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09580000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AC80000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0ADC0000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C5C0000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CF80000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D280000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0E740000.VBN Infected: Trojan-Downloader.Win32.Zlob.dco skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\AntiVirGear 3.8\AntiVirGear 3.8.exe Infected: not-a-virus:FraudTool.Win32.AntiVirGear.e skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0219NAV~.TMP Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008756.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008756.exe/file2 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008756.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008756.exe/file5 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008756.exe/file6 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008756.exe Inno: infected - 5 skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008768.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008769.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008780.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008781.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008787.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008788.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008793.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008795.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008804.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP147\A0008805.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008818.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008819.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008844.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008846.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008854.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008855.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008863.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008864.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008872.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008873.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008881.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP148\A0008882.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP149\A0008933.dll Infected: Trojan-Downloader.Win32.Agent.dtg skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP149\A0008942.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP149\A0008943.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP149\A0008951.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP149\A0008952.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP150\A0008972.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP150\A0008973.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP150\A0008978.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP150\A0008979.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP150\A0008992.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP150\A0008993.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009069.exe Infected: Trojan-Downloader.Win32.Zlob.dcl skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009070.exe Infected: Trojan-Downloader.Win32.Zlob.dcg skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009071.exe Infected: Trojan-Downloader.Win32.Zlob.dcq skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009072.dll Infected: Trojan-Downloader.Win32.Zlob.dcp skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009073.exe Infected: Trojan-Downloader.Win32.Zlob.dce skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009074.exe Infected: Trojan-Downloader.Win32.Zlob.dcn skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009075.exe Infected: Trojan-Downloader.Win32.Zlob.dcm skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\A0009127.dll Infected: Trojan-Downloader.Win32.Zlob.dcn skipped
C:\System Volume Information\_restore{541CEDB7-51C6-460E-BBC0-6664E06B814B}\RP151\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{EAEC68CF-561E-4EEC-9254-C53E2BBC23C4}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
HJT log on next post