star99ers
2007-12-08, 07:10
Hi there, my PC was recently infected with the VirtuMonde Trojan. It turned up on Spybot S&D, and I removed it, but I am still getting pop ups as well as the info to download random Spyware removal programs.
I also ran VundoFix and deleted one file that it had found, which didn't solve the problem. I need some help with this, it would be much appreciated.
Here's my Kapersky Scan report.
Scan Statistics
Total number of scanned objects 190052
Number of viruses found 24
Number of infected objects 68
Number of suspicious objects 0
Duration of the scan process 03:27:22
Infected Object Name Virus Name Last Action
C:\Documents and Settings\Joel Tetrault\Application Data\Sun\Java\Deployment\cache\6.0\25\9180419-22a00ca5/VaannnaaBaa.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\Joel Tetrault\Application Data\Sun\Java\Deployment\cache\6.0\25\9180419-22a00ca5 ZIP: infected - 1 skipped
C:\Documents and Settings\Joel Tetrault\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\History\History.IE5\MSHist012007120720071208\index.dat Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\!update.exe Infected: Trojan-Downloader.Win32.PurityScan.dx skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\rkvomqoh.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\win1B7.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\win1C5.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\win1C5.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\~uga6psetup.exe/file14 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\~uga6psetup.exe/file20 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\~uga6psetup.exe/file34 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\~uga6psetup.exe/file36 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\~uga6psetup.exe Inno: infected - 4 skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temporary Internet Files\Content.IE5\050H2LEN\1184497718[2].jpg Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temporary Internet Files\Content.IE5\8T6VOD6V\go[1].htm Infected: Trojan-Clicker.HTML.IFrame.fp skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temporary Internet Files\Content.IE5\U3HQ26VQ\1184497718[1].jpg Object is locked skipped
C:\Documents and Settings\Joel Tetrault\My Documents\ѕуstem\ati2evxx.exe Infected: Trojan-Downloader.Win32.PurityScan.ej skipped
C:\Documents and Settings\Joel Tetrault\ntuser.dat Object is locked skipped
C:\Documents and Settings\Joel Tetrault\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\AVSystemCare\FMTR.sys Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Program Files\AVSystemCare\fopnl.dll Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Program Files\AVSystemCare\scnkrnl.dll Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Program Files\Common Files\AVSystemCare\ugcw.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Program Files\Evrsoft First Page 2006\Iscripts\Page Details\crazy-window.izs Infected: not-virus:BadJoke.JS.RJump skipped
C:\Program Files\fp2006-final-3.00-setup.zip/fp2006-final-3.00-setup.exe/file1626 Infected: not-virus:BadJoke.JS.RJump skipped
C:\Program Files\fp2006-final-3.00-setup.zip/fp2006-final-3.00-setup.exe Infected: not-virus:BadJoke.JS.RJump skipped
C:\Program Files\fp2006-final-3.00-setup.zip ZIP: infected - 2 skipped
C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Norton AntiVirus\Quarantine\01635C27 Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Norton AntiVirus\Quarantine\0A64543E.tmp Infected: not-virus:Hoax.Win32.Renos.hx skipped
C:\Program Files\Norton AntiVirus\Quarantine\0C046F95 Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Norton AntiVirus\Quarantine\0C046F95.part Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Norton AntiVirus\Quarantine\0C723BFB.tmp Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\Program Files\Norton AntiVirus\Quarantine\0C7634D0.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\0EB83C53 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton AntiVirus\Quarantine\1034721D.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\227D5AE1 Infected: Trojan.Java.ClassLoader.as skipped
C:\Program Files\Norton AntiVirus\Quarantine\23AE08BF.bin Infected: Exploit.Win32.IMG-ANI.w skipped
C:\Program Files\Norton AntiVirus\Quarantine\24376F87 Infected: Trojan.Java.ClassLoader.as skipped
C:\Program Files\Norton AntiVirus\Quarantine\27AC61B9 Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Norton AntiVirus\Quarantine\2BA1395F Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\3F6D52AD Infected: not-virus:Hoax.Win32.Renos.kd skipped
C:\Program Files\Norton AntiVirus\Quarantine\3F6D52AD.exe Infected: not-virus:Hoax.Win32.Renos.kd skipped
C:\Program Files\Norton AntiVirus\Quarantine\42253298 Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\Program Files\Norton AntiVirus\Quarantine\52482AD6.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gl skipped
C:\Program Files\Norton AntiVirus\Quarantine\56F65BAF Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\57BD5CD4 Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\75A567A5 Infected: Exploit.Java.Gimsh.a skipped
C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP0 Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP0.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP1 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP1.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP2.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145423.exe Infected: Trojan.Win32.Inject.ks skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145424.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.bja skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145425.exe/data.rar/keygen.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.bja skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145425.exe/data.rar/patch.exe Infected: Trojan.Win32.Dialer.yq skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145425.exe/data.rar/crack.exe Infected: Trojan.Win32.Inject.ks skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145425.exe/data.rar Infected: Trojan.Win32.Inject.ks skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145425.exe RarSFX: infected - 4 skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP470\A0147468.dll Infected: Trojan.Win32.Dialer.yq skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP470\A0147470.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP471\A0148500.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP471\A0148501.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gl skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP471\A0148502.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP471\A0148503.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP472\A0149942.exe Infected: Trojan.Win32.Dialer.yq skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP472\A0151017.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP472\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped
C:\WINDOWS\Downloaded Program Files\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\FMTR.sys Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\WINDOWS\system32\dsymagnm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\khfecca.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bja skipped
C:\WINDOWS\system32\lnnzkrxr.dll Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_290.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
I also ran VundoFix and deleted one file that it had found, which didn't solve the problem. I need some help with this, it would be much appreciated.
Here's my Kapersky Scan report.
Scan Statistics
Total number of scanned objects 190052
Number of viruses found 24
Number of infected objects 68
Number of suspicious objects 0
Duration of the scan process 03:27:22
Infected Object Name Virus Name Last Action
C:\Documents and Settings\Joel Tetrault\Application Data\Sun\Java\Deployment\cache\6.0\25\9180419-22a00ca5/VaannnaaBaa.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\Joel Tetrault\Application Data\Sun\Java\Deployment\cache\6.0\25\9180419-22a00ca5 ZIP: infected - 1 skipped
C:\Documents and Settings\Joel Tetrault\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\History\History.IE5\MSHist012007120720071208\index.dat Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\!update.exe Infected: Trojan-Downloader.Win32.PurityScan.dx skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\rkvomqoh.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\win1B7.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\win1C5.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\win1C5.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\~uga6psetup.exe/file14 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\~uga6psetup.exe/file20 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\~uga6psetup.exe/file34 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\~uga6psetup.exe/file36 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temp\~uga6psetup.exe Inno: infected - 4 skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temporary Internet Files\Content.IE5\050H2LEN\1184497718[2].jpg Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temporary Internet Files\Content.IE5\8T6VOD6V\go[1].htm Infected: Trojan-Clicker.HTML.IFrame.fp skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Joel Tetrault\Local Settings\Temporary Internet Files\Content.IE5\U3HQ26VQ\1184497718[1].jpg Object is locked skipped
C:\Documents and Settings\Joel Tetrault\My Documents\ѕуstem\ati2evxx.exe Infected: Trojan-Downloader.Win32.PurityScan.ej skipped
C:\Documents and Settings\Joel Tetrault\ntuser.dat Object is locked skipped
C:\Documents and Settings\Joel Tetrault\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\AVSystemCare\FMTR.sys Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Program Files\AVSystemCare\fopnl.dll Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Program Files\AVSystemCare\scnkrnl.dll Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Program Files\Common Files\AVSystemCare\ugcw.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Program Files\Evrsoft First Page 2006\Iscripts\Page Details\crazy-window.izs Infected: not-virus:BadJoke.JS.RJump skipped
C:\Program Files\fp2006-final-3.00-setup.zip/fp2006-final-3.00-setup.exe/file1626 Infected: not-virus:BadJoke.JS.RJump skipped
C:\Program Files\fp2006-final-3.00-setup.zip/fp2006-final-3.00-setup.exe Infected: not-virus:BadJoke.JS.RJump skipped
C:\Program Files\fp2006-final-3.00-setup.zip ZIP: infected - 2 skipped
C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Norton AntiVirus\Quarantine\01635C27 Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Norton AntiVirus\Quarantine\0A64543E.tmp Infected: not-virus:Hoax.Win32.Renos.hx skipped
C:\Program Files\Norton AntiVirus\Quarantine\0C046F95 Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Norton AntiVirus\Quarantine\0C046F95.part Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Norton AntiVirus\Quarantine\0C723BFB.tmp Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\Program Files\Norton AntiVirus\Quarantine\0C7634D0.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\0EB83C53 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton AntiVirus\Quarantine\1034721D.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\227D5AE1 Infected: Trojan.Java.ClassLoader.as skipped
C:\Program Files\Norton AntiVirus\Quarantine\23AE08BF.bin Infected: Exploit.Win32.IMG-ANI.w skipped
C:\Program Files\Norton AntiVirus\Quarantine\24376F87 Infected: Trojan.Java.ClassLoader.as skipped
C:\Program Files\Norton AntiVirus\Quarantine\27AC61B9 Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Norton AntiVirus\Quarantine\2BA1395F Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\3F6D52AD Infected: not-virus:Hoax.Win32.Renos.kd skipped
C:\Program Files\Norton AntiVirus\Quarantine\3F6D52AD.exe Infected: not-virus:Hoax.Win32.Renos.kd skipped
C:\Program Files\Norton AntiVirus\Quarantine\42253298 Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\Program Files\Norton AntiVirus\Quarantine\52482AD6.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gl skipped
C:\Program Files\Norton AntiVirus\Quarantine\56F65BAF Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\57BD5CD4 Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\75A567A5 Infected: Exploit.Java.Gimsh.a skipped
C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP0 Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP0.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP1 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP1.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP2.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145423.exe Infected: Trojan.Win32.Inject.ks skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145424.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.bja skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145425.exe/data.rar/keygen.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.bja skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145425.exe/data.rar/patch.exe Infected: Trojan.Win32.Dialer.yq skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145425.exe/data.rar/crack.exe Infected: Trojan.Win32.Inject.ks skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145425.exe/data.rar Infected: Trojan.Win32.Inject.ks skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP469\A0145425.exe RarSFX: infected - 4 skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP470\A0147468.dll Infected: Trojan.Win32.Dialer.yq skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP470\A0147470.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP471\A0148500.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP471\A0148501.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gl skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP471\A0148502.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP471\A0148503.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP472\A0149942.exe Infected: Trojan.Win32.Dialer.yq skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP472\A0151017.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{9C11B671-0EF2-4B80-87DC-9A604B4CA9C4}\RP472\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped
C:\WINDOWS\Downloaded Program Files\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\FMTR.sys Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\WINDOWS\system32\dsymagnm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\khfecca.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bja skipped
C:\WINDOWS\system32\lnnzkrxr.dll Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_290.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped