Hello there,
I'm having trouble removing Smitfraud and according to the Kaspersky Online Scanner, probably some other things as well.
Also, since I was scanning these forums earlier, I did download smitfraudfix v2.244, however I have not cleaned up/fixed anything with it.
Furthermore, before I found out about Spybot, I was trying to track down suspicious items on my own. There were a number of suspicious .dll files in my c:\windows\system32 directory that were created for no apparent reason around the time when I started having spy/malware problems. So, I moved most of these files into a separate directory named "quarantine" on my desktop - you can see their filenames on the kaspersky report below. I say most of those files were moved because I deleted one or two of the .dll files in a desperate move to solve my problems.
In any event, I will post the Kaspersky and HJT logs below. Thank you so much for your help!
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, October 30, 2007 9:59:47 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 30/10/2007
Kaspersky Anti-Virus database records: 448570
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
F:\
G:\
Z:\
Scan Statistics:
Total number of scanned objects: 542279
Number of viruses found: 12
Number of infected objects: 30
Number of suspicious objects: 0
Duration of the scan process: 06:28:57
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Gerald Wang\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Gerald Wang\Desktop\quarantine\fccabba.dll Infected: Trojan-Downloader.Win32.Agent.epy skipped
C:\Documents and Settings\Gerald Wang\Desktop\quarantine\ldcore.dll Infected: Trojan-Downloader.Win32.Small.gkh skipped
C:\Documents and Settings\Gerald Wang\Desktop\quarantine\vtuuvwv.dll Infected: Trojan-Downloader.Win32.Agent.epy skipped
C:\Documents and Settings\Gerald Wang\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Gerald Wang\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Gerald Wang\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Gerald Wang\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Application Data\Identities\{715CEABA-B505-495D-857D-7D48199326A6}\Microsoft\Outlook Express\Folders.dbx Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Application Data\Identities\{715CEABA-B505-495D-857D-7D48199326A6}\Microsoft\Outlook Express\Gcw12 - Inbox.dbx Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Application Data\Identities\{715CEABA-B505-495D-857D-7D48199326A6}\Microsoft\Outlook Express\Offline.dbx Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Temp\wr-1-77.exe Infected: Trojan-Downloader.Win32.Small.gks skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Temporary Internet Files\Content.IE5\3H77R1EJ\in[1].htm Infected: Exploit.HTML.IESlice.aj skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Temporary Internet Files\Content.IE5\7QRNXR9U\in[1].htm Infected: Trojan-Clicker.Win32.Agent.lw skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gerald Wang\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Gerald Wang\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\RECYCLER\S-1-5-21-390228671-1531695939-3868554017-1003\Dc64.exe/stream/data0002 Infected: not-a-virus
ownloader.Win32.Agent.q skipped
C:\RECYCLER\S-1-5-21-390228671-1531695939-3868554017-1003\Dc64.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.AdBand.a skipped
C:\RECYCLER\S-1-5-21-390228671-1531695939-3868554017-1003\Dc64.exe/stream Infected: not-a-virus:AdWare.Win32.AdBand.a skipped
C:\RECYCLER\S-1-5-21-390228671-1531695939-3868554017-1003\Dc64.exe NSIS: infected - 3 skipped
C:\System Volume Information\catalog.wci\00000002.ps1 Object is locked skipped
C:\System Volume Information\catalog.wci\00000002.ps2 Object is locked skipped
C:\System Volume Information\catalog.wci\00010002.ci Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped
C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP35\A0005174.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.sw skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP35\A0005174.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP35\A0005177.exe Infected: not-a-virus:AdWare.Win32.Agent.sw skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP35\A0005179.dll Infected: not-a-virus:AdWare.Win32.AdBand.a skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005292.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005364.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005365.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005395.exe Infected: not-a-virus:AdWare.Win32.Agent.lv skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005398.exe Infected: not-a-virus:AdWare.Win32.Agent.lv skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005402.exe/stream/data0002 Infected: not-a-virus
ownloader.Win32.Agent.q skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005402.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.AdBand.a skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005402.exe/stream Infected: not-a-virus:AdWare.Win32.AdBand.a skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005402.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP37\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{BDFB07BD-493D-4625-BFD8-A9004354662D}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
C:\WINDOWS\system32\drivers\core.sys Object is locked skipped
C:\WINDOWS\system32\e2\caws83122.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\WINDOWS\system32\e2\caws83122.exe NSIS: infected - 1 skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\x22\c124wvr.exe Infected: Trojan-Downloader.Win32.Small.gks skipped
C:\WINDOWS\Temp\Perflib_Perfdata_4d8.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-10071102}.CDF Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Z:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
I'm having trouble removing Smitfraud and according to the Kaspersky Online Scanner, probably some other things as well.
Also, since I was scanning these forums earlier, I did download smitfraudfix v2.244, however I have not cleaned up/fixed anything with it.
Furthermore, before I found out about Spybot, I was trying to track down suspicious items on my own. There were a number of suspicious .dll files in my c:\windows\system32 directory that were created for no apparent reason around the time when I started having spy/malware problems. So, I moved most of these files into a separate directory named "quarantine" on my desktop - you can see their filenames on the kaspersky report below. I say most of those files were moved because I deleted one or two of the .dll files in a desperate move to solve my problems.
In any event, I will post the Kaspersky and HJT logs below. Thank you so much for your help!
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, October 30, 2007 9:59:47 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 30/10/2007
Kaspersky Anti-Virus database records: 448570
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
F:\
G:\
Z:\
Scan Statistics:
Total number of scanned objects: 542279
Number of viruses found: 12
Number of infected objects: 30
Number of suspicious objects: 0
Duration of the scan process: 06:28:57
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Gerald Wang\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Gerald Wang\Desktop\quarantine\fccabba.dll Infected: Trojan-Downloader.Win32.Agent.epy skipped
C:\Documents and Settings\Gerald Wang\Desktop\quarantine\ldcore.dll Infected: Trojan-Downloader.Win32.Small.gkh skipped
C:\Documents and Settings\Gerald Wang\Desktop\quarantine\vtuuvwv.dll Infected: Trojan-Downloader.Win32.Agent.epy skipped
C:\Documents and Settings\Gerald Wang\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Gerald Wang\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Gerald Wang\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Gerald Wang\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Application Data\Identities\{715CEABA-B505-495D-857D-7D48199326A6}\Microsoft\Outlook Express\Folders.dbx Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Application Data\Identities\{715CEABA-B505-495D-857D-7D48199326A6}\Microsoft\Outlook Express\Gcw12 - Inbox.dbx Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Application Data\Identities\{715CEABA-B505-495D-857D-7D48199326A6}\Microsoft\Outlook Express\Offline.dbx Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Temp\wr-1-77.exe Infected: Trojan-Downloader.Win32.Small.gks skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Temporary Internet Files\Content.IE5\3H77R1EJ\in[1].htm Infected: Exploit.HTML.IESlice.aj skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Temporary Internet Files\Content.IE5\7QRNXR9U\in[1].htm Infected: Trojan-Clicker.Win32.Agent.lw skipped
C:\Documents and Settings\Gerald Wang\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gerald Wang\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Gerald Wang\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\RECYCLER\S-1-5-21-390228671-1531695939-3868554017-1003\Dc64.exe/stream/data0002 Infected: not-a-virus

C:\RECYCLER\S-1-5-21-390228671-1531695939-3868554017-1003\Dc64.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.AdBand.a skipped
C:\RECYCLER\S-1-5-21-390228671-1531695939-3868554017-1003\Dc64.exe/stream Infected: not-a-virus:AdWare.Win32.AdBand.a skipped
C:\RECYCLER\S-1-5-21-390228671-1531695939-3868554017-1003\Dc64.exe NSIS: infected - 3 skipped
C:\System Volume Information\catalog.wci\00000002.ps1 Object is locked skipped
C:\System Volume Information\catalog.wci\00000002.ps2 Object is locked skipped
C:\System Volume Information\catalog.wci\00010002.ci Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped
C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP35\A0005174.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.sw skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP35\A0005174.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP35\A0005177.exe Infected: not-a-virus:AdWare.Win32.Agent.sw skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP35\A0005179.dll Infected: not-a-virus:AdWare.Win32.AdBand.a skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005292.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005364.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005365.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005395.exe Infected: not-a-virus:AdWare.Win32.Agent.lv skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005398.exe Infected: not-a-virus:AdWare.Win32.Agent.lv skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005402.exe/stream/data0002 Infected: not-a-virus

C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005402.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.AdBand.a skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005402.exe/stream Infected: not-a-virus:AdWare.Win32.AdBand.a skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP36\A0005402.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{33FD9BA1-06C8-43B5-B9DE-01EB2D187D1E}\RP37\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{BDFB07BD-493D-4625-BFD8-A9004354662D}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
C:\WINDOWS\system32\drivers\core.sys Object is locked skipped
C:\WINDOWS\system32\e2\caws83122.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\WINDOWS\system32\e2\caws83122.exe NSIS: infected - 1 skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\x22\c124wvr.exe Infected: Trojan-Downloader.Win32.Small.gks skipped
C:\WINDOWS\Temp\Perflib_Perfdata_4d8.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-10071102}.CDF Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Z:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Last edited by a moderator: