dodulo
2008-02-23, 00:13
Hello,
I am trying to fix a PC for a friend, and got to a point above my head. Any help will be greatly appreciated.
1) Kasperski online scan.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, February 22, 2008 11:44:06 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 22/02/2008
Kaspersky Anti-Virus database records: 575848
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
Scan Statistics:
Total number of scanned objects: 57726
Number of viruses found: 6
Number of infected objects: 37
Number of suspicious objects: 0
Duration of the scan process: 01:39:06
Infected Object Name / Virus Name / Last Action
C:\!KillBox\gebabbb.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\!KillBox\gebabbb.dll ( 2) Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\!KillBox\gebabbb.dll ( 3) Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\!KillBox\gebabbb.dll ( 4) Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\!KillBox\gebabbb.dll( 1) Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\!KillBox\wvurq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\!KillBox\wvurq.dll( 1) Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\!KillBox\wvurq.dll( 2) Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\!KillBox\wvurq.dll( 5) Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\!KillBox\wvurq.dll( 6) Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\user1\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt Object is locked skipped
C:\Documents and Settings\user1\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\user1\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\user1\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\user1\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\user1\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\user1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\user1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\user1\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\user1\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\user1\ntuser.dat Object is locked skipped
C:\Documents and Settings\user1\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.me Object is locked skipped
C:\Program Files\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.mm Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\BWKDLogs\BWTargetInf.log Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\L0000006.FCS Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\storydb.idx Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP554\A0113198.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP554\A0113199.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114322.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114323.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114375.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114376.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114377.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114378.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114379.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114380.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114381.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114382.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114383.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114384.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114385.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kb skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114386.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114387.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114388.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114389.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114390.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114391.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114392.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114403.exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{5658D109-4553-4ADC-808E-4A343452264D}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
2) SpyBot S&D scan in safe mode.
- After a reboot, around half dozen items are discovered.
- Repeated scans fail to take care of the following one item:
Company:
Product: Smitfraud-C.CoreService
Threat: Trojan
Functionality: Supposed to be some kind of driver
3) Rebooted in normal mode; HijackThis scan.
... continued in next post ...
Daniel Odulo
I am trying to fix a PC for a friend, and got to a point above my head. Any help will be greatly appreciated.
1) Kasperski online scan.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, February 22, 2008 11:44:06 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 22/02/2008
Kaspersky Anti-Virus database records: 575848
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
Scan Statistics:
Total number of scanned objects: 57726
Number of viruses found: 6
Number of infected objects: 37
Number of suspicious objects: 0
Duration of the scan process: 01:39:06
Infected Object Name / Virus Name / Last Action
C:\!KillBox\gebabbb.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\!KillBox\gebabbb.dll ( 2) Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\!KillBox\gebabbb.dll ( 3) Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\!KillBox\gebabbb.dll ( 4) Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\!KillBox\gebabbb.dll( 1) Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\!KillBox\wvurq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\!KillBox\wvurq.dll( 1) Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\!KillBox\wvurq.dll( 2) Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\!KillBox\wvurq.dll( 5) Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\!KillBox\wvurq.dll( 6) Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\user1\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt Object is locked skipped
C:\Documents and Settings\user1\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\user1\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\user1\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\user1\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\user1\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\user1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\user1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\user1\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\user1\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\user1\ntuser.dat Object is locked skipped
C:\Documents and Settings\user1\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.me Object is locked skipped
C:\Program Files\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.mm Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\BWKDLogs\BWTargetInf.log Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\L0000006.FCS Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\storydb.idx Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP554\A0113198.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP554\A0113199.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114322.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114323.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114375.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114376.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114377.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114378.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114379.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114380.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114381.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114382.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114383.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114384.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114385.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kb skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114386.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114387.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114388.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114389.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114390.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114391.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114392.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\A0114403.exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\System Volume Information\_restore{EDD82BE4-0B26-454E-8987-D66DF044E02E}\RP555\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{5658D109-4553-4ADC-808E-4A343452264D}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
2) SpyBot S&D scan in safe mode.
- After a reboot, around half dozen items are discovered.
- Repeated scans fail to take care of the following one item:
Company:
Product: Smitfraud-C.CoreService
Threat: Trojan
Functionality: Supposed to be some kind of driver
3) Rebooted in normal mode; HijackThis scan.
... continued in next post ...
Daniel Odulo