PDA

View Full Version : Virus Help



SueB365
2008-02-11, 05:02
Hi,
I posted this log on 1/25/08 but I don't think anyone replied. It could be user error, if so I apoligize.
Do you have any recommendations?

I posted an HJT log on 1/11/08 and PSkelly asked that I post the Kaspersky Log. It was so long ago that I cant seem to get back to the original post.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, January 05, 2008 9:31:42 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 5/01/2008
Kaspersky Anti-Virus database records: 502797
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 118265
Number of viruses found: 3
Number of infected objects: 4
Number of suspicious objects: 0
Duration of the scan process: 02:15:41

Infected Object Name / Virus Name / Last Action
C:\2ba699ab89db6d379358c775\msxml4-KB927978-enu.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{32F6AC40-63FD-4726-B9F4-3722A76554F3}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{3D4F956E-1F64-47E9-B4B6-F45BA575486C}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR23.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Prism\f4dcf223 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\SupportSoft\DellSupportCenter\SYSTEM\state\logs\sprtcmd.log Object is locked skipped
C:\Documents and Settings\Angi\Incomplete\Preview-T-1932750-Wicked Remix.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
C:\Documents and Settings\Angi\ntuser.dat Object is locked skipped
C:\Documents and Settings\Angi\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Angi\Shared\Wicked Remix.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
C:\Documents and Settings\Dana\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\ApplicationHistory\hpqimzone.exe.3204510e.ini.inuse Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.cdx Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.dbf Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\Musicmatch\Jukebox\mmjbaltlog.txt Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\Musicmatch\Jukebox\mmjblog.txt Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\Musicmatch\MIM\Database\Default.ldb Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Application Data\Musicmatch\MIM\Database\Default.mdb Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\History\History.IE5\MSHist012008010320080104\index.dat Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Temp\JET4D8A.tmp Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Temp\~DF1B4F.tmp Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Temp\~DFB63F.tmp Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Temp\~DFB672.tmp Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Temp\~DFC57.tmp Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Temp\~DFE9DA.tmp Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Dana\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dana\ntuser.dat Object is locked skipped
C:\Documents and Settings\Dana\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Dana\Shared\misery business acoustic.wm Infected: Trojan-Downloader.WMA.Wimad.m skipped
C:\Documents and Settings\Devin\Application Data\Adobe\Acrobat\7.0\AdobeCMapFnt07.lst Object is locked skipped
C:\Documents and Settings\Devin\Application Data\Adobe\Acrobat\7.0\AdobeSysFnt07.lst Object is locked skipped

C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\6743_PromoContent[1].xml Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\6743_stationInfo[2].xml Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\69869_75_75_72_front[1].jpg Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\817-grey[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\9493bytes[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\9493bytes[2].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\9493bytes[3].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\9493bytes[4].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\9493bytes[5].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\addemupsmallicon[1].jpg Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\addFavDialog2005-08-24_16-16-49[1].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\AddressUtil[2].js Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\adjs[1].php Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\adjs[2].php Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\adsEnd[1].js Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\adsize=160x600&site=aim&cat=holidays&subcat=celebratefall&page=category&product=&yr=&gnd=[1].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\adstracking[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\adsWrapperAIM[1].js Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\ads[1].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\ads[2].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\ads[3].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\ads[4].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\ads[5].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\adx[1].js Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\ages.jpg Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\aimtoday[1].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\aimtoday[2].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\aimtoday[3].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\aimtoday[4].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\aimtoday[5].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\aimtoday[6].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\EZQ94JGN\aimtoday[7].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\myyhp_2.1[1].js Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\nails[1].htm Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\navbar[1].xml Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\nav_9_unauth[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\nav_aim[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\nav_bg[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\nav_bg_base[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\nav_grad[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\nav_HP_about_mm_on[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\nav_HP_maggieEmail_on[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\nav_HP_mag_visit_1_on[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\nav_HP_own_franchise_off[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\ZIS3RCSV\nav_HP_tell_maggie_on[1].gif Object is locked skipped
C:\Documents and Settings\Devin\Local Settings\Temporary Internet skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\mcafee_GiKRBq5zygj0Ltq Object is locked skipped
C:\WINDOWS\Temp\mcmsc_6Et6onfYn62zjlx Object is locked skipped
C:\WINDOWS\Temp\mcmsc_IUf0yP55YMPseQh Object is locked skipped
C:\WINDOWS\Temp\mcmsc_KscbfDArclUCrVQ Object is locked skipped
C:\WINDOWS\Temp\mcmsc_Mi0gX1tXdhPK8AU Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

pskelley
2008-02-11, 19:24
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.
The Waiting Room
http://forums.spybot.info/forumdisplay.php?f=37

I apologize for the confusion, seems the first topic was archived because apparantly after four days there was no post to the "Waiting Room" so administration assumes you have resolved the issue elsewhere.
http://forums.spybot.info/showthread.php?t=22418

I have looked at the Kaspersky log and this is what I am seeing:

Delete the files in red:
C:\Documents and Settings\Angi\Incomplete\Preview-T-1932750-Wicked Remix.wma ------> Trojan-Downloader.WMA.Wimad.l
C:\Documents and Settings\Angi\Shared\Wicked Remix.wma ------> Trojan-Downloader.WMA.Wimad.l
C:\Documents and Settings\Dana\Shared\misery business acoustic.wm ------> Trojan-Downloader.WMA.Wimad.m

C:\Documents and Settings\Devin\Local Settings\Temporary Internet <<< delete the contents of the TIF folder

Empty the Recycle Bin on your Desktop, restart your computer.

Post a new HJT log and please tell me exactly what your malware problems are. If you receive error messages, post those word for word.

Thanks...Phil

pskelley
2008-02-18, 15:17
Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.

Everyone else please begin a New Topic.