dvlinsd88
2008-03-30, 00:28
Hello,
Firstly I am grateful for any help I receive for my problems. Thank you so much and it is a truly wonderful deed the people of this website are doing. Keep it up!
Well a while back I managed to infect my computer with a whole bunch of viruses. I initially cleaned some of it up with Norton Anti-Virus and Spybot but quickly noticed that the problem had not completely gone. So I turned to this website and went through all the initial steps with the Kaspersky and HJT scans. The main problem I seem to have is that every time I restarted the computer, the same infections kept getting caught and removed by Norton (geeda.dll). Additionally, every time I tried to open any file or program the system invoked an installer for a (seemingly random) program. So I rushed to quickly cancel the computer from installing microsoft office or something else. Well I don't want to end up with any long-winded speeches, so here are the scans I have done:
*Note: Though the scans are dated March 9, I have not turned on the computer since that time and am currently on another computer.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, March 09, 2008 2:26:14 PM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 9/03/2008
Kaspersky Anti-Virus database records: 618846
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 97576
Number of viruses found: 14
Number of infected objects: 65
Number of suspicious objects: 0
Duration of the scan process: 01:50:02
Infected Object Name / Virus Name / Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\skqrdcrm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\kaouonmx.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\ncjglqfn.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\L9A61.tmp Infected: Trojan-Downloader.Win32.Small.ijp skipped
C:\WINDOWS\system32\wvuusqo.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\geeda.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\wvuroon.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\wbyqgvme.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\nnnkljj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\lkbqochq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\keaqsmel.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\LucentIKESvc.log Object is locked skipped
C:\WINDOWS\Temp\ja.com Infected: Trojan-Dropper.Win32.Agent.atn skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08D80000.VBN Infected: Virus.Win32.Trats.d skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08D80001.VBN Infected: Virus.Win32.Trats.d skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temp\Temporary Internet Files\Content.IE5\GBGXGPKD\l[1].htm Infected: Trojan-Downloader.VBS.Small.co skipped
C:\Documents and Settings\User\Local Settings\Temp\Temporary Internet Files\Content.IE5\IJIV4BUV\l[1].php/packed Infected: Trojan-Downloader.VBS.Small.co skipped
C:\Documents and Settings\User\Local Settings\Temp\Temporary Internet Files\Content.IE5\IJIV4BUV\l[1].php GZIP: infected - 1 skipped
C:\Documents and Settings\User\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\User\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6d691a6b-7124f8fd.zip/vmain.class Infected: Exploit.Java.Gimsh.b skipped
C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6d691a6b-7124f8fd.zip ZIP: infected - 1 skipped
C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\6.0\52\1c9644b4-2f8a51f4/vmain.class Infected: Exploit.Java.Gimsh.b skipped
C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\6.0\52\1c9644b4-2f8a51f4 ZIP: infected - 1 skipped
C:\Documents and Settings\User\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\User\ntuser.dat Object is locked skipped
C:\Documents and Settings\Mera\Local Settings\Temporary Internet Files\Content.IE5\01K345OP\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Mera\Local Settings\Temporary Internet Files\Content.IE5\GHI1KL45\m7[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\debug.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\debug.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\error.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\error.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\hips.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\hips.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\ids.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\ids.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\network.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\network.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\system.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\system.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\warning.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\warning.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\web.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\web.log.idx Object is locked skipped
C:\Program Files\IPSec Client\Log\FW_Session.log Object is locked skipped
C:\Program Files\IPSec Client\Log\logipsec.log Object is locked skipped
C:\Program Files\WinBudget\bin\crap.1165812330.old/data0000.bin Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Program Files\WinBudget\bin\crap.1165812330.old EmbeddedEXE: infected - 1 skipped
C:\Program Files\WinBudget\bin\crap.1165961625.old/data0000.bin Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Program Files\WinBudget\bin\crap.1165961625.old EmbeddedEXE: infected - 1 skipped
C:\Program Files\WinBudget\bin\crap.1165961625.old UPX: infected - 1 skipped
C:\Program Files\WinBudget\bin\crap.1165961625.old PE_Patch.UPX: infected - 1 skipped
C:\Program Files\WinBudget\bin\crap.1165986709.old/data0000.bin Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Program Files\WinBudget\bin\crap.1165986709.old EmbeddedEXE: infected - 1 skipped
C:\Program Files\WinBudget\bin\crap.1165986709.old UPX: infected - 1 skipped
C:\Program Files\WinBudget\bin\crap.1165986709.old PE_Patch.UPX: infected - 1 skipped
C:\Program Files\QdrModule\QdrModule12.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\Program Files\QdrPack\QdrPack12 .exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\Program Files\QdrPack\QdrPack12.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0845NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0635NAV~.TMP Object is locked skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP546\A0120853.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP546\A0120854.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP547\A0122086.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP547\change.log Object is locked skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0111662.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0111664.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0111725.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0111727.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0112725.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0112727.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0112754.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0112780.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0112782.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0112802.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0113774.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0113778.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0113797.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0117187.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0118280.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0118280.exe NSIS: infected - 1 skipped
C:\43.tmp/stream/data0002 Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\43.tmp/stream/data0003 Infected: not-a-virus:AdWare.Win32.AdBand.c skipped
C:\43.tmp/stream Infected: not-a-virus:AdWare.Win32.AdBand.c skipped
C:\43.tmp NSIS: infected - 3 skipped
D:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP547\change.log Object is locked skipped
D:\Family\Alex\Codecs and Installation\BSINSTALL.exe/WISE0023.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
D:\Family\Alex\Codecs and Installation\BSINSTALL.exe/WISE0023.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
D:\Family\Alex\Codecs and Installation\BSINSTALL.exe/WISE0023.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
D:\Family\Alex\Codecs and Installation\BSINSTALL.exe/WISE0027.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
D:\Family\Alex\Codecs and Installation\BSINSTALL.exe WiseSFX: infected - 4 skipped
D:\Family\Alex\Codecs and Installation\BSINSTALL.exe WiseSFXDropper: infected - 4 skipped
Scan process completed.
Firstly I am grateful for any help I receive for my problems. Thank you so much and it is a truly wonderful deed the people of this website are doing. Keep it up!
Well a while back I managed to infect my computer with a whole bunch of viruses. I initially cleaned some of it up with Norton Anti-Virus and Spybot but quickly noticed that the problem had not completely gone. So I turned to this website and went through all the initial steps with the Kaspersky and HJT scans. The main problem I seem to have is that every time I restarted the computer, the same infections kept getting caught and removed by Norton (geeda.dll). Additionally, every time I tried to open any file or program the system invoked an installer for a (seemingly random) program. So I rushed to quickly cancel the computer from installing microsoft office or something else. Well I don't want to end up with any long-winded speeches, so here are the scans I have done:
*Note: Though the scans are dated March 9, I have not turned on the computer since that time and am currently on another computer.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, March 09, 2008 2:26:14 PM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 9/03/2008
Kaspersky Anti-Virus database records: 618846
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 97576
Number of viruses found: 14
Number of infected objects: 65
Number of suspicious objects: 0
Duration of the scan process: 01:50:02
Infected Object Name / Virus Name / Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\skqrdcrm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\kaouonmx.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\ncjglqfn.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\L9A61.tmp Infected: Trojan-Downloader.Win32.Small.ijp skipped
C:\WINDOWS\system32\wvuusqo.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\geeda.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\wvuroon.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\wbyqgvme.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\nnnkljj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\lkbqochq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\keaqsmel.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\LucentIKESvc.log Object is locked skipped
C:\WINDOWS\Temp\ja.com Infected: Trojan-Dropper.Win32.Agent.atn skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08D80000.VBN Infected: Virus.Win32.Trats.d skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08D80001.VBN Infected: Virus.Win32.Trats.d skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temp\Temporary Internet Files\Content.IE5\GBGXGPKD\l[1].htm Infected: Trojan-Downloader.VBS.Small.co skipped
C:\Documents and Settings\User\Local Settings\Temp\Temporary Internet Files\Content.IE5\IJIV4BUV\l[1].php/packed Infected: Trojan-Downloader.VBS.Small.co skipped
C:\Documents and Settings\User\Local Settings\Temp\Temporary Internet Files\Content.IE5\IJIV4BUV\l[1].php GZIP: infected - 1 skipped
C:\Documents and Settings\User\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\User\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6d691a6b-7124f8fd.zip/vmain.class Infected: Exploit.Java.Gimsh.b skipped
C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6d691a6b-7124f8fd.zip ZIP: infected - 1 skipped
C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\6.0\52\1c9644b4-2f8a51f4/vmain.class Infected: Exploit.Java.Gimsh.b skipped
C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\6.0\52\1c9644b4-2f8a51f4 ZIP: infected - 1 skipped
C:\Documents and Settings\User\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\User\ntuser.dat Object is locked skipped
C:\Documents and Settings\Mera\Local Settings\Temporary Internet Files\Content.IE5\01K345OP\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Mera\Local Settings\Temporary Internet Files\Content.IE5\GHI1KL45\m7[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\debug.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\debug.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\error.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\error.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\hips.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\hips.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\ids.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\ids.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\network.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\network.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\system.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\system.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\warning.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\warning.log.idx Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\web.log Object is locked skipped
C:\Program Files\Kerio\Personal Firewall 4\logs\web.log.idx Object is locked skipped
C:\Program Files\IPSec Client\Log\FW_Session.log Object is locked skipped
C:\Program Files\IPSec Client\Log\logipsec.log Object is locked skipped
C:\Program Files\WinBudget\bin\crap.1165812330.old/data0000.bin Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Program Files\WinBudget\bin\crap.1165812330.old EmbeddedEXE: infected - 1 skipped
C:\Program Files\WinBudget\bin\crap.1165961625.old/data0000.bin Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Program Files\WinBudget\bin\crap.1165961625.old EmbeddedEXE: infected - 1 skipped
C:\Program Files\WinBudget\bin\crap.1165961625.old UPX: infected - 1 skipped
C:\Program Files\WinBudget\bin\crap.1165961625.old PE_Patch.UPX: infected - 1 skipped
C:\Program Files\WinBudget\bin\crap.1165986709.old/data0000.bin Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Program Files\WinBudget\bin\crap.1165986709.old EmbeddedEXE: infected - 1 skipped
C:\Program Files\WinBudget\bin\crap.1165986709.old UPX: infected - 1 skipped
C:\Program Files\WinBudget\bin\crap.1165986709.old PE_Patch.UPX: infected - 1 skipped
C:\Program Files\QdrModule\QdrModule12.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\Program Files\QdrPack\QdrPack12 .exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\Program Files\QdrPack\QdrPack12.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0845NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0635NAV~.TMP Object is locked skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP546\A0120853.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP546\A0120854.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP547\A0122086.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP547\change.log Object is locked skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0111662.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0111664.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0111725.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0111727.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0112725.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0112727.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0112754.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0112780.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0112782.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0112802.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0113774.exe Infected: not-a-virus:AdWare.Win32.Agent.aev skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0113778.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0113797.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0117187.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0118280.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP543\A0118280.exe NSIS: infected - 1 skipped
C:\43.tmp/stream/data0002 Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\43.tmp/stream/data0003 Infected: not-a-virus:AdWare.Win32.AdBand.c skipped
C:\43.tmp/stream Infected: not-a-virus:AdWare.Win32.AdBand.c skipped
C:\43.tmp NSIS: infected - 3 skipped
D:\System Volume Information\_restore{FF8778E9-8BCF-47A6-AE69-E0579573171D}\RP547\change.log Object is locked skipped
D:\Family\Alex\Codecs and Installation\BSINSTALL.exe/WISE0023.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
D:\Family\Alex\Codecs and Installation\BSINSTALL.exe/WISE0023.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
D:\Family\Alex\Codecs and Installation\BSINSTALL.exe/WISE0023.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
D:\Family\Alex\Codecs and Installation\BSINSTALL.exe/WISE0027.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
D:\Family\Alex\Codecs and Installation\BSINSTALL.exe WiseSFX: infected - 4 skipped
D:\Family\Alex\Codecs and Installation\BSINSTALL.exe WiseSFXDropper: infected - 4 skipped
Scan process completed.