teamind
2007-12-18, 21:22
HI and thank in advance for your help. I have a Windows XP machine that is showing lots of malware.
Tried fixing yesterday with Spybot but to no avail.
Did a Kapersky scan but to long to post so I am posting all identified malicious from the kapersky scan...
-------------------------------------------------------------------------------
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, December 18, 2007 10:46:44 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/12/2007
Kaspersky Anti-Virus database records: 486393
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 51257
Number of viruses found: 9
Number of infected objects: 90
Number of suspicious objects: 0
Duration of the scan process: 01:17:54
Infected Object Name / Virus Name / Last Action
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\clnr0.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\Trend Micro\HijackThis\backups\backup-20071217-161601-755.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bmd skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0015354.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0015458.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP144\A0015549.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP144\A0015746.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP144\A0015783.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP145\A0015799.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP145\A0015806.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP147\A0015838.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP149\A0015954.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP150\A0015978.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP151\A0016053.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP152\A0016121.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP154\A0016210.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP155\A0016224.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP158\A0016379.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP159\A0016391.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP159\A0016397.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP161\A0016488.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP161\A0016493.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP162\A0016535.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP165\A0016631.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP166\A0016664.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP169\A0016707.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP170\A0016764.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP171\A0016913.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP173\A0017012.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP174\A0018035.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP175\A0018081.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0018118.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\A0018138.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP178\A0018172.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP179\A0018205.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP180\A0018250.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP182\A0018307.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP184\A0018420.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP184\A0018464.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP185\A0018491.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP187\A0018562.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP187\A0018573.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP188\A0018655.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP190\A0018697.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP191\A0018733.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP195\A0019104.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP195\A0019110.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP196\A0019150.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP196\A0019197.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0019231.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0020435.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0020532.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP205\A0020591.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP206\A0020653.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP206\A0020747.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP208\A0020930.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP208\A0021911.exe Infected: not-a-virus:AdWare.Win32.Agent.co skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP208\A0021914.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP213\A0022664.dll Infected: not-a-virus:AdWare.Win32.Agent.wx skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP213\A0022668.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP214\A0022718.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP216\A0022748.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP216\A0022771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP216\A0022774.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP217\A0023771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP217\A0023774.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023826.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023835.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023844.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023854.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023864.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023877.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023886.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bmd skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023891.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023902.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\change.log Object is locked skipped
C:\temp\ulSaa1212.exe/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\temp\ulSaa1212.exe/data0003 Infected: not-a-virus:AdWare.Win32.Agent.co skipped
C:\temp\ulSaa1212.exe/data0004 Infected: Trojan-Downloader.Win32.Small.gzs skipped
C:\temp\ulSaa1212.exe/data0006/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\temp\ulSaa1212.exe/data0006 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\temp\ulSaa1212.exe NSIS: infected - 5 skipped
C:\VundoFix Backups\byxvwtu.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.bmd skipped
C:\VundoFix Backups\efcdeda.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.bmd skipped
C:\VundoFix Backups\hflwgfun.dll.bad Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\VundoFix Backups\kyekkfrl.dll.bad Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\VundoFix Backups\ltftkwvy.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\VundoFix Backups\qomkhec.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.bmd skipped
C:\VundoFix Backups\rvcoguvj.dll.bad Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\VundoFix Backups\xxywxvt.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.bmd skipped
C:\WINDOWS\system32\oc9\qopre83122.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\WINDOWS\system32\oc9\qopre83122.exe NSIS: infected - 1 skipped
Scan process completed.
------------------------------------
Any help would be greatly appreciated, will post HijackThis scan momentarily after re-naming hijackthis.exe
Tried fixing yesterday with Spybot but to no avail.
Did a Kapersky scan but to long to post so I am posting all identified malicious from the kapersky scan...
-------------------------------------------------------------------------------
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, December 18, 2007 10:46:44 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/12/2007
Kaspersky Anti-Virus database records: 486393
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 51257
Number of viruses found: 9
Number of infected objects: 90
Number of suspicious objects: 0
Duration of the scan process: 01:17:54
Infected Object Name / Virus Name / Last Action
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\clnr0.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\Trend Micro\HijackThis\backups\backup-20071217-161601-755.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bmd skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0015354.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0015458.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP144\A0015549.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP144\A0015746.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP144\A0015783.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP145\A0015799.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP145\A0015806.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP147\A0015838.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP149\A0015954.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP150\A0015978.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP151\A0016053.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP152\A0016121.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP154\A0016210.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP155\A0016224.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP158\A0016379.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP159\A0016391.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP159\A0016397.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP161\A0016488.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP161\A0016493.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP162\A0016535.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP165\A0016631.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP166\A0016664.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP169\A0016707.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP170\A0016764.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP171\A0016913.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP173\A0017012.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP174\A0018035.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP175\A0018081.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0018118.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\A0018138.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP178\A0018172.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP179\A0018205.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP180\A0018250.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP182\A0018307.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP184\A0018420.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP184\A0018464.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP185\A0018491.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP187\A0018562.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP187\A0018573.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP188\A0018655.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP190\A0018697.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP191\A0018733.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP195\A0019104.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP195\A0019110.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP196\A0019150.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP196\A0019197.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0019231.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0020435.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0020532.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP205\A0020591.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP206\A0020653.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP206\A0020747.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP208\A0020930.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP208\A0021911.exe Infected: not-a-virus:AdWare.Win32.Agent.co skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP208\A0021914.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP213\A0022664.dll Infected: not-a-virus:AdWare.Win32.Agent.wx skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP213\A0022668.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP214\A0022718.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP216\A0022748.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP216\A0022771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP216\A0022774.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP217\A0023771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP217\A0023774.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023826.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023835.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023844.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023854.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023864.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023877.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023886.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bmd skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023891.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\A0023902.dll Infected: Trojan.Win32.Gorshok.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP220\change.log Object is locked skipped
C:\temp\ulSaa1212.exe/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\temp\ulSaa1212.exe/data0003 Infected: not-a-virus:AdWare.Win32.Agent.co skipped
C:\temp\ulSaa1212.exe/data0004 Infected: Trojan-Downloader.Win32.Small.gzs skipped
C:\temp\ulSaa1212.exe/data0006/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\temp\ulSaa1212.exe/data0006 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\temp\ulSaa1212.exe NSIS: infected - 5 skipped
C:\VundoFix Backups\byxvwtu.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.bmd skipped
C:\VundoFix Backups\efcdeda.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.bmd skipped
C:\VundoFix Backups\hflwgfun.dll.bad Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\VundoFix Backups\kyekkfrl.dll.bad Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\VundoFix Backups\ltftkwvy.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\VundoFix Backups\qomkhec.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.bmd skipped
C:\VundoFix Backups\rvcoguvj.dll.bad Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\VundoFix Backups\xxywxvt.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.bmd skipped
C:\WINDOWS\system32\oc9\qopre83122.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\WINDOWS\system32\oc9\qopre83122.exe NSIS: infected - 1 skipped
Scan process completed.
------------------------------------
Any help would be greatly appreciated, will post HijackThis scan momentarily after re-naming hijackthis.exe