Jez_S
2007-10-22, 18:57
Hi
Don't seem to be able to get rid of this, despite multiple runnings of Spybot. Have run Kaspersky (see below) and this seems to have identified other problems...can you help??? Thanks.
KASPERSKY ONLINE SCANNER REPORT
Monday, October 22, 2007 4:03:55 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 22/10/2007
Kaspersky Anti-Virus database records: 442434
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
Scan Statistics
Total number of scanned objects 553935
Number of viruses found 23
Number of infected objects 119
Number of suspicious objects 16
Duration of the scan process 05:45:21
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Kontiki\error.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\107633ab18f4af9f52a559f75a1cc097_9c928323-9b32-47ad-9462-348453c782cc Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47c29a4a4e0a74bb8b67f3692a3e5265_9c928323-9b32-47ad-9462-348453c782cc Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff2.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff4.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff4.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff6.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff6.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk2.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk4.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk4.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk6.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk6.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\COMET\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\COMET\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\COMET\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\COMET\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\COMET\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\COMET\Local Settings\Temporary Internet Files\Content.IE5\QTTE7UP8\PCTurboProInstallerFree[1].exe Infected: not-a-virus:Downloader.Win32.WinFixer.w skipped
C:\Documents and Settings\COMET\ntuser.dat Object is locked skipped
C:\Documents and Settings\COMET\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\ACTIV Software\ACTIVdriver\ActivControl2.exe Infected: Trojan.Win32.Patched.af skipped
C:\Program Files\ACTIV Software\ACTIVdriver\ActivFilter.exe Infected: Trojan.Win32.Patched.af skipped
C:\Program Files\BroadJump\Client Foundation\CFD.exe Infected: Trojan.Win32.Patched.af skipped
C:\Program Files\hlpsrv.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\Program Files\ntl\broadband medic\log\mpbtn.log Object is locked skipped
C:\Program Files\ntl\broadband medic\SmartBridge\AlertFilter.log Object is locked skipped
C:\Program Files\ntl\broadband medic\SmartBridge\log\httpclient.log Object is locked skipped
C:\Program Files\ntl\broadband medic\SmartBridge\MotiveSB.exe Infected: Trojan.Win32.Patched.af skipped
C:\Program Files\ntl\broadband medic\SmartBridge\SmartBridge.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP310\A0093004.exe Infected: Backdoor.Win32.Agent.ark skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093442.exe Infected: Email-Worm.Win32.Zhelatin.ks skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093443.exe Infected: Email-Worm.Win32.Zhelatin.kt skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093446.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093447.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093458.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093462.exe Infected: Email-Worm.Win32.Zhelatin.kr skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093471.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093533.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093542.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093553.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093561.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093569.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093577.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093585.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093600.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093608.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093623.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093631.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093667.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093689.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093710.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093726.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093741.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093756.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093764.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093772.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093814.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093830.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093845.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093867.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093875.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093890.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093912.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093927.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093935.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093957.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093986.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093994.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094008.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094017.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094053.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094067.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094094.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094105.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094113.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094121.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094149.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094158.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094180.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094211.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094234.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094242.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094254.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094272.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094280.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094295.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094303.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094311.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094339.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094372.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094401.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094413.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094430.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094488.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094507.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094525.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094554.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094562.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094576.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094592.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094621.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094629.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094651.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094666.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094681.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094689.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
continued in post 2
Don't seem to be able to get rid of this, despite multiple runnings of Spybot. Have run Kaspersky (see below) and this seems to have identified other problems...can you help??? Thanks.
KASPERSKY ONLINE SCANNER REPORT
Monday, October 22, 2007 4:03:55 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 22/10/2007
Kaspersky Anti-Virus database records: 442434
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
Scan Statistics
Total number of scanned objects 553935
Number of viruses found 23
Number of infected objects 119
Number of suspicious objects 16
Duration of the scan process 05:45:21
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Kontiki\error.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\107633ab18f4af9f52a559f75a1cc097_9c928323-9b32-47ad-9462-348453c782cc Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47c29a4a4e0a74bb8b67f3692a3e5265_9c928323-9b32-47ad-9462-348453c782cc Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff2.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff4.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff4.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff6.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloff6.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk2.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk4.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk4.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk6.zip/startdrv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMurloffrtk6.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\COMET\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\COMET\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\COMET\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\COMET\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\COMET\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\COMET\Local Settings\Temporary Internet Files\Content.IE5\QTTE7UP8\PCTurboProInstallerFree[1].exe Infected: not-a-virus:Downloader.Win32.WinFixer.w skipped
C:\Documents and Settings\COMET\ntuser.dat Object is locked skipped
C:\Documents and Settings\COMET\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\ACTIV Software\ACTIVdriver\ActivControl2.exe Infected: Trojan.Win32.Patched.af skipped
C:\Program Files\ACTIV Software\ACTIVdriver\ActivFilter.exe Infected: Trojan.Win32.Patched.af skipped
C:\Program Files\BroadJump\Client Foundation\CFD.exe Infected: Trojan.Win32.Patched.af skipped
C:\Program Files\hlpsrv.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\Program Files\ntl\broadband medic\log\mpbtn.log Object is locked skipped
C:\Program Files\ntl\broadband medic\SmartBridge\AlertFilter.log Object is locked skipped
C:\Program Files\ntl\broadband medic\SmartBridge\log\httpclient.log Object is locked skipped
C:\Program Files\ntl\broadband medic\SmartBridge\MotiveSB.exe Infected: Trojan.Win32.Patched.af skipped
C:\Program Files\ntl\broadband medic\SmartBridge\SmartBridge.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP310\A0093004.exe Infected: Backdoor.Win32.Agent.ark skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093442.exe Infected: Email-Worm.Win32.Zhelatin.ks skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093443.exe Infected: Email-Worm.Win32.Zhelatin.kt skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093446.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093447.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093458.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093462.exe Infected: Email-Worm.Win32.Zhelatin.kr skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP319\A0093471.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093533.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093542.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093553.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093561.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093569.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093577.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093585.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093600.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093608.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093623.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093631.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093667.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093689.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093710.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093726.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093741.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093756.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093764.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093772.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093814.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093830.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093845.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093867.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093875.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093890.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093912.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093927.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093935.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093957.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093986.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0093994.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094008.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094017.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094053.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094067.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094094.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094105.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094113.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094121.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094149.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094158.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094180.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094211.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094234.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094242.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094254.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094272.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094280.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094295.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094303.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094311.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094339.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094372.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094401.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094413.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094430.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094488.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094507.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094525.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094554.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094562.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094576.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094592.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094621.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094629.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094651.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094666.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094681.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
C:\System Volume Information\_restore{25EC80A5-ABC8-4E76-AAFA-A9284724DC8A}\RP321\A0094689.exe Infected: Trojan-Downloader.Win32.Agent.eao skipped
continued in post 2