PDA

View Full Version : help remove viruses



woodgabe
2008-04-28, 03:13
I scanned my computer with norton antivirus and found two viruses that I could do nothing about. When a ran kapersky it found many more. I really don't know what to do.

here is my hjt log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:08:43 PM, on 4/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\Program Files\TSU_VPN\cvpnd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\javaw.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Spybot1.5 - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1.5-S\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [regcmdcons] c:\hp\bin\cloaker.exe c:\hp\bin\cmdcons.cmd
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [SprintModemUpdate] javaw.exe -cp "C:\Program Files\Motive\FirmwareUpdater\lib\SprintModemUpdate.jar" com.motive.firmwareUpdater.client.SprintModemUpdate
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [EZInstaller] "E:\EZInstaller.exe" -plugin
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot1.5 - Search & Destroy\TeaTimer.exe
O4 - Startup: Magic Holdem.lnk = C:\Program Files\Magic Holdem\MagicHoldem.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TSU VPN Client.lnk = C:\Program Files\TSU_VPN\ipsecdialer.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?2d1bc3984937474f839ea221c75af1dd
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?2d1bc3984937474f839ea221c75af1dd
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1.5-S\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1.5-S\SDHelper.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\TSU_VPN\cvpnd.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 13726 bytes

here is the report for kapersky:

Sunday, April 27, 2008 5:56:44 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/04/2008
Kaspersky Anti-Virus database records: 727671
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Scan Statistics
Total number of scanned objects 182811
Number of viruses found 32
Number of infected objects 65
Number of suspicious objects 0
Duration of the scan process 04:14:22

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-04-27_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\All Users\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\v6whxknh.default\cert8.db Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\v6whxknh.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\v6whxknh.default\foxmarks.log Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\v6whxknh.default\history.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\v6whxknh.default\key3.db Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\v6whxknh.default\parent.lock Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\v6whxknh.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\dbc2e.ht1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\dbdam Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\dbdao Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\dbeam Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\dbeao Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\dbm Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\dbu2d.ht1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\dbvm.cf1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\dbvmh.ht1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\fii.cf1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\fiih.ht1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\hp Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\hpt2i.ht1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\rpm.cf1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\rpm1m.cf1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\rpm1mh.ht1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\rpmh.ht1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\safeweb\goog-black-enchashm.cf1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\safeweb\goog-black-enchashmh.ht1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\safeweb\goog-black-urlm.cf1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\safeweb\goog-black-urlmh.ht1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\safeweb\goog-malware-domainm.cf1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\safeweb\goog-malware-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\safeweb\goog-white-domainm.cf1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google\Google Desktop\da03b3ed3873\safeweb\goog-white-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\v6whxknh.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\v6whxknh.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\v6whxknh.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\v6whxknh.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\History\History.IE5\MSHist012008042720080428\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Arc5B.tmp\VirtualAssistant.exe//VirtualAssistant.exe/WISE0032.BIN/WISE0008.BIN Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Arc5B.tmp\VirtualAssistant.exe//VirtualAssistant.exe/WISE0032.BIN/WISE0009.BIN Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Arc5B.tmp\VirtualAssistant.exe//VirtualAssistant.exe/WISE0032.BIN Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Arc5B.tmp\VirtualAssistant.exe//VirtualAssistant.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Arc5B.tmp\VirtualAssistant.exe CabSFX: infected - 4 skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Perflib_Perfdata_310.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\~DFD888.tmp Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\~DFF085.tmp Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Compaq_Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_4a4.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\AOL\ACS\US\forms.fdb Object is locked skipped
C:\Program Files\Common Files\AOL\ACS\US\static Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\AntiSpam\Log\Spam.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPStop.log Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\master.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\mastlog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\model.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\modellog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdbdata.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdblog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\tempdb.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\templog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\ERRORLOG Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\log_72.trc Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\04EB2DA9.tmp Infected: Worm.Win32.VB.an skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\12A00099.tmp Infected: Worm.Win32.VB.an skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\18185CC0.tmp Infected: Trojan.Win32.Crypt.e skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\230954F6.tmp Infected: Email-Worm.VBS.Gedza skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2A5B0A76.tmp Infected: Trojan-Dropper.Win32.Small.ux skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3983503A.tmp Infected: Trojan.Win32.Crypt.e skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\650A3867.tmp Infected: Worm.Win32.VB.an skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\68D2629E.exe/data0002/data0003 Infected: Trojan-Downloader.Win32.Keenval.f skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\68D2629E.exe/data0002 Infected: Trojan-Downloader.Win32.Keenval.f skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\68D2629E.exe NSIS: infected - 2 skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\68D2629E.exe CryptFF: infected - 2 skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6C901A7D.exe Infected: Worm.Win32.VB.an skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6E7F5E5F.exe Infected: Trojan-Downloader.Win32.Zlob.bon skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\71616F33.exe Infected: not-virus:BadJoke.Win32.VB.p skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\718F3B01.exe/data0003 Infected: Trojan-Downloader.Win32.Keenval.f skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\718F3B01.exe NSIS: infected - 1 skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\718F3B01.exe CryptFF: infected - 1 skipped
C:\Program Files\Virtual Assistant\SmartBridge\AlertFilter.log Object is locked skipped
C:\Program Files\Virtual Assistant\SmartBridge\log\httpclient.log Object is locked skipped
C:\Program Files\Virtual Assistant\SmartBridge\SmartBridge.log Object is locked skipped
C:\ProgramData\Electronic Arts\EADM\cache\logs\Core.html Object is locked skipped
C:\RECYCLER\S-1-5-21-3389637950-4173144626-1092267258-1009\Dc59.exe/data.rar/crack.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.qon skipped
C:\RECYCLER\S-1-5-21-3389637950-4173144626-1092267258-1009\Dc59.exe/data.rar/keygen.exe Infected: Trojan-Downloader.Win32.Small.ury skipped
C:\RECYCLER\S-1-5-21-3389637950-4173144626-1092267258-1009\Dc59.exe/data.rar/serial.exe Infected: Trojan-Downloader.Win32.Small.usn skipped
C:\RECYCLER\S-1-5-21-3389637950-4173144626-1092267258-1009\Dc59.exe/data.rar Infected: Trojan-Downloader.Win32.Small.usn skipped
C:\RECYCLER\S-1-5-21-3389637950-4173144626-1092267258-1009\Dc59.exe RarSFX: infected - 4 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP985\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\I386\Apps\APP15425\src\HPSummer2005.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
D:\I386\Apps\APP15425\src\HPSummer2005.exe WiseSFX: infected - 1 skipped
D:\I386\Apps\APP15425\src\HPSummer2005.exe WiseSFXDropper: infected - 1 skipped
D:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP985\change.log Object is locked skipped
J:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
J:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonName.zip/fsg_4104.exe Infected: not-a-virus:AdWare.Win32.Gator.4104 skipped
J:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonName.zip/Setup_PerfectNav.exe/data0002/data0005 Infected: Trojan-Downloader.Win32.Keenval.g skipped
J:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonName.zip/Setup_PerfectNav.exe/data0002 Infected: Trojan-Downloader.Win32.Keenval.g skipped
J:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonName.zip/Setup_PerfectNav.exe/data0003 Infected: Trojan-Downloader.Win32.Small.alx skipped
J:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonName.zip/Setup_PerfectNav.exe/data0004 Infected: not-a-virus:AdWare.Win32.Perfnav.a skipped
J:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonName.zip/Setup_PerfectNav.exe Infected: not-a-virus:AdWare.Win32.Perfnav.a skipped
J:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonName.zip ZIP: infected - 6 skipped
J:\Documents and Settings\Gabe\My Documents\secret!\HPIM0032.JPG Object is locked skipped
J:\Documents and Settings\Gabe\My Documents\secret!\HPIM0152.JPG Object is locked skipped
J:\Documents and Settings\Gabe\My Documents\secret!\HPIM0154.JPG Object is locked skipped
J:\Documents and Settings\Gabe\My Documents\secret!\HPIM0168.JPG Object is locked skipped
J:\Documents and Settings\Gabe\My Documents\secret!\HPIM0172.JPG Object is locked skipped
J:\Documents and Settings\Gabe\My Documents\secret!\HPIM0173.JPG Object is locked skipped
J:\Documents and Settings\Gabe\My Documents\secret!\HPIM0174.JPG Object is locked skipped
J:\Documents and Settings\Gabe\My Documents\secret!\hpothb07.dat Object is locked skipped
J:\Documents and Settings\Gabe\My Documents\secret!\hpothb07.tif Object is locked skipped
J:\Documents and Settings\Gabe\My Documents\secret!\Thumbs.db Object is locked skipped
J:\Program Files\MyWay\myBar\1.bin\MY2NS.EXE Infected: not-a-virus:AdWare.Win32.MyWay.b skipped
J:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL Infected: not-a-virus:AdWare.Win32.MyWay.g skipped
J:\Program Files\MyWay\myBar\1.bin\NPMYWAY.DLL Infected: not-a-virus:AdWare.Win32.MyWay.f skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\017D481D Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\03484CFC.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\07A855BC Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\07AB7FB8 Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\090800FB.htm Infected: Exploit.VBS.Phel.a skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\09364CC9.class Infected: Trojan.Java.ClassLoader.c skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\09746A84.htm Infected: Exploit.VBS.Phel.a skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\12DC22C5.class Infected: Trojan.Java.ClassLoader.d skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\17F544F5.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\34833DD7.htm Infected: Exploit.HTML.Mht skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\34A137B6.class Infected: Trojan.Java.ClassLoader.j skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\354E27A7.class Infected: Trojan.Java.ClassLoader.c skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\355151A3.class Infected: Exploit.Java.ByteVerify skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\35557BA0.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3C9C57A5.class Infected: Trojan-Dropper.Java.Beyond.c skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3CA70D3D.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4CCB1046.class Infected: Exploit.Java.ByteVerify skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\51DD2C63 Infected: not-a-virus:AdWare.Win32.Altnet.j skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\58E71B78.class Infected: Exploit.Java.ByteVerify skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5A6365F9.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6A86218E.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6AE9190B.class Infected: Trojan.Java.ClassLoader.c skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6C1427D1 Infected: not-a-virus:AdWare.Win32.BrilliantDigital.3039 skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\756F3390.class Infected: Exploit.Java.ByteVerify skipped
J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\78C80932 Infected: not-a-virus:AdWare.Win32.SideStep.a skipped
J:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
J:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP985\change.log Object is locked skipped
J:\WINDOWS\$NtUninstallKB824141$\user32.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB824141$\win32k.sys Object is locked skipped
J:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\dao360.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\expsrv.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msexch40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msexcl40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msjet40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msjetol1.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msjetoledb40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msjint40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msjter40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msjtes40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msltus40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\mspbde40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msrd2x40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msrd3x40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msrepl40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\mstext40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\mswdat10.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\mswstr10.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\msxbde40.dll Object is locked skipped
J:\WINDOWS\$NtUninstallKB837001$\vbajet32.dll Object is locked skipped
J:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
J:\WINDOWS\$NtUninstallQ828026$\wmpcore.dll Object is locked skipped
Scan process completed.

I hope someone can help. Thanks

pskelley
2008-05-07, 13:33
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

The Waiting Room <<< you missed this
http://forums.spybot.info/forumdisplay.php?f=37

If your issues are not resolved, not sure if I can help or not but I will give it a try. First you said:

I scanned my computer with norton antivirus and found two viruses that I could do nothing about.Run NAV again and if it finds anything delete or quarantine the items. If you can not do that, post the exact name and location of the items and the reason NAV give for not being able to do what they get paid for.

Your Kaspersky Online Scan is a bit of a mess, and I have no idea what you have Norton Internet Security on both C:\ and J:\ ?
Let try to clean the junk like this:

1) C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Arc5B.tmp\VirtualAssistant.exe//VirtualAssistant.exe/WISE0032.BIN/WISE0008.BIN ------> RemoteAdmin.Win32.WinVNC-based.b
This may be a false positive, if you know it is safe, leave it. If you don't know scan the file in RED to find out.
http://virusscan.jotti.org/ <<< free scanner

2) C:\RECYCLER\ <<< delete the contents of the Recycle Bin on the Desktop

3) D:\I386\Apps\APP15425\src\HPSummer2005.exe/WISE0016.BIN ------> AdWare.Win32.MyWay.j
Installed by HP, Kaspersky says they are adware (does not surprise me) Scan the file to find out and delete it if bad.

4) J:\Program Files\MyWay\ <<< uninstall that program in Add Remove programs.

5) C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\ <<< delete the contents of the folder in RED

6) J:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\ <<< delete the contents of the folder in RED

Restart and run a new KOS which should be clean if directions were followed.

To proceed at all, I will need the information about the "trojans" from the NAV scan and a fresh HJT log. Please mention malware symptoms.

Thanks

pskelley
2008-05-14, 16:16
Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.

Everyone else please begin a New Topic.