Page 3 of 5 FirstFirst 12345 LastLast
Results 21 to 30 of 46

Thread: Problem with search-daily.com Please Help

  1. #21
    Senior Member
    Join Date
    May 2007
    Posts
    131

    Default Kaspersky Online Scanner Report #1

    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Saturday, March 01, 2008 6:23:52 PM
    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 2/03/2008
    Kaspersky Anti-Virus database records: 545990
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: standard
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    C:\
    D:\

    Scan Statistics:
    Total number of scanned objects: 50590
    Number of viruses found: 3
    Number of infected objects: 212
    Number of suspicious objects: 0
    Duration of the scan process: 00:55:43

    Infected Object Name / Virus Name / Last Action
    C:\Documents and Settings\Administrator.TU_DANG\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\Administrator.TU_DANG\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\Administrator.TU_DANG\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\Administrator.TU_DANG\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Administrator.TU_DANG\Local Settings\History\History.IE5\MSHist012008030120080302\index.dat Object is locked skipped
    C:\Documents and Settings\Administrator.TU_DANG\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Administrator.TU_DANG\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\Administrator.TU_DANG\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
    C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\chandir.dat Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\chandir.idx Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\chn.dat Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\chn.idx Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\D0000000.FCS Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\inuse.txt Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\L0000003.FCS Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\main.log Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\prs.dat Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\prs.idx Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\prs_die.dat Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\prs_die.idx Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\prs_dnd.dat Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\prs_dnd.idx Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\prs_ext.dat Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\prs_ext.idx Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\prs_rcv.dat Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\prs_rcv.idx Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\storydb.dat Object is locked skipped
    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Administrator\Data\storydb.idx Object is locked skipped
    C:\Program Files\Norton SystemWorks\Norton AntiVirus\AVApp.log Object is locked skipped
    C:\Program Files\Norton SystemWorks\Norton AntiVirus\AVError.log Object is locked skipped
    C:\Program Files\Norton SystemWorks\Norton AntiVirus\AVVirus.log Object is locked skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP755\A0109462.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP755\A0109463.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP755\A0109464.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP756\A0109483.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP756\A0109484.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP756\A0109485.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP756\A0109495.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP756\A0109496.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP756\A0109497.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP756\A0109511.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP756\A0109512.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP756\A0109513.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP757\A0109548.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP757\A0109549.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP757\A0109550.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP758\A0109574.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP758\A0109575.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP758\A0109576.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP759\A0109599.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP759\A0109600.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP759\A0109601.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP760\A0109619.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP760\A0109620.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP760\A0109621.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP761\A0109642.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP761\A0109643.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP761\A0109644.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP761\A0109655.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP761\A0109656.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP761\A0109657.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP762\A0109667.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP762\A0109668.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP762\A0109669.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP763\A0109682.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP763\A0109683.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP763\A0109684.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP763\A0110682.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP763\A0110683.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP763\A0110684.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP764\A0111682.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP764\A0111683.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP764\A0111684.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP764\A0111693.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP764\A0111694.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP764\A0111695.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP765\A0111709.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP765\A0111710.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP765\A0111711.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP766\A0111730.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP766\A0111731.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP766\A0111732.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP767\A0112730.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP767\A0112731.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP767\A0112732.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP767\A0112746.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP767\A0112747.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP767\A0112748.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP767\A0113747.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP767\A0113748.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP767\A0113749.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP768\A0114746.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP768\A0114747.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP768\A0114748.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP768\A0114758.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP768\A0114759.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP768\A0114760.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP768\A0115758.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP768\A0115759.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP768\A0115760.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0116758.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0116759.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0116760.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0116777.exe Infected: not-virus:Hoax.Win32.Fera.u skipped

  2. #22
    Senior Member
    Join Date
    May 2007
    Posts
    131

    Default Kaspersky report part 2

    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0116778.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0116779.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0117777.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0117778.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0117779.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0118777.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0118778.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0118779.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0118794.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0118795.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP769\A0118796.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP770\A0118816.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP770\A0118817.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP770\A0118818.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP771\A0118840.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP771\A0118841.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP771\A0118842.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP772\A0118862.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP772\A0118863.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP772\A0118864.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP773\A0118890.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP773\A0118891.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP773\A0118892.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP774\A0119890.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP774\A0119891.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP774\A0119892.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0119912.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0119913.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0119914.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0120610.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0120616.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0120618.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0120627.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0120628.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0120629.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0120642.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0120643.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0120644.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP776\A0120663.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP776\A0120664.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP776\A0120665.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP777\A0120686.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP777\A0120687.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP777\A0120688.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP780\A0120787.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP780\A0120788.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP780\A0120789.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP780\A0120810.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP780\A0120811.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP780\A0120812.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP782\A0120830.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP782\A0120831.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP782\A0120832.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP783\A0120851.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP783\A0120852.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP783\A0120853.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP783\A0120862.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP783\A0120863.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP783\A0120870.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP783\A0120881.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP783\A0120882.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP783\A0120883.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP783\A0120900.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP783\A0120901.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP783\A0120902.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP784\A0120921.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP784\A0120922.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP784\A0120923.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP785\A0120958.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP785\A0120959.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP785\A0120960.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP786\A0120983.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP786\A0120984.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP786\A0120985.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP787\A0121001.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP787\A0121002.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP787\A0121003.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP789\A0121032.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP789\A0121033.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP789\A0121034.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP790\A0121050.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP790\A0121051.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP790\A0121052.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP790\A0121069.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP790\A0121070.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP790\A0121071.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP791\A0121095.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP791\A0121096.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP791\A0121097.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP791\A0121107.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP791\A0121108.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP791\A0121109.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP791\A0122107.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP791\A0122108.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP791\A0122109.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP791\A0122121.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP791\A0122122.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP791\A0122123.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP792\A0122142.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP792\A0122143.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP792\A0122144.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP793\A0122171.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP793\A0122172.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP793\A0122173.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP794\A0122187.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP794\A0122188.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP794\A0122189.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP794\A0122200.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP794\A0122201.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP794\A0122202.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP795\A0122217.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP795\A0122218.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP795\A0122219.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP796\A0122233.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP796\A0122234.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP796\A0122235.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP796\A0122245.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP796\A0122246.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP796\A0122247.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP797\A0122272.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP797\A0122273.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP797\A0122274.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122295.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122296.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122297.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122299.dll Infected: Trojan-Downloader.Win32.Zlob.gjg skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122300.exe Infected: Trojan-Downloader.Win32.Zlob.fqq skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122309.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122310.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122311.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122313.dll Infected: Trojan-Downloader.Win32.Zlob.gjg skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122314.exe Infected: Trojan-Downloader.Win32.Zlob.fqq skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122326.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122327.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122328.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122329.dll Infected: Trojan-Downloader.Win32.Zlob.gjg skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122331.exe Infected: Trojan-Downloader.Win32.Zlob.fqq skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122339.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP798\A0122340.exe Infected: not-virus:Hoax.Win32.Fera.u skipped
    C:\System Volume Information\_restore{2DB944E5-6F8F-4542-BB3B-06EF2863636F}\RP1\change.log Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

  3. #23
    Senior Member
    Join Date
    May 2007
    Posts
    131

    Default Kaspersky report part 3

    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\Sti_Trace.log Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
    C:\WINDOWS\system32\config\sam Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\security Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\wiadebug.log Object is locked skipped
    C:\WINDOWS\wiaservc.log Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.

  4. #24
    Senior Member
    Join Date
    May 2007
    Posts
    131

    Default new hjthis report

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:11:47 PM, on 3/1/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
    C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
    C:\WINDOWS\system32\msiconf.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {ECEA6D5A-4F00-4908-B64F-C8AA2670FF8C} - C:\WINDOWS\system32\asycfil.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
    O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    O4 - HKCU\..\Run: [MSI Configuration] msiconf.exe
    O4 - HKCU\..\Run: [SpyShredder] C:\Program Files\SpyShredder\SpyShredder.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe

    --
    End of file - 5849 bytes

  5. #25
    Senior Member
    Join Date
    May 2007
    Posts
    131

    Default Malware alert popup window

    Sorry cannot load it. My doc file 99.5KB (over .5)
    Hope you understand what program I am talking about
    SpyShredder 2.1

  6. #26
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    Thanks for returning your information, we will try another tool on C:\WINDOWS\system32\asycfil.dll and you do have additional infections. You are keeping this computer offline except for when you have to be on to troubleshoot?

    Please read through the instructions a couple of times, you may want to print them. If you have any doubt about your ability to complete these instructions, you may want to seek local professional help or ask someone with more computer experience to work with you.


    1) Since Kaspersky is showing over 200 infected System Restore files it appears you did not follow directions I posted. These directions will clean System Restore:

    Turn off System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.

    Reboot

    Turn ON System Restore,
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    UN-Check *Turn off System Restore*.
    Click Apply, and then click OK.


    2) Download The Avenger (http://swandog46.geekstogo.com/avenger.zip) Copyright © Swandog46
    You must extract avenger.exe to your Desktop, before you run it.

    The Avenger must be run from a user account with administrator privileges,
    and ONLY works on Windows 2000 and XP, and only on 32-bit versions!

    Copy all the text contained in the code box below to your Clipboard.

    Code:
    Files to delete:
    C:\WINDOWS\system32\asycfil.dll
    C:\WINDOWS\system32\msiconf.exe
    The above script is for this user only, if you need help please start your own thread.

    Start the Avenger.
    Under "Script file to execute" choose "Input Script Manually".
    Click on the Magnifying Glass icon which will open a new window titled "View/edit script".
    Paste the entire text in into this window.
    Click done, now click on the Green Light
    Answer "Yes" twice when prompted.
    Your computer shoud reboot, and briefly open a black command window on your desktop, this is normal.

    After the restart, it will create a log file that should open.
    This log file will be located at C:\avenger.txt
    Paste the contents of the file into your reply along with a fresh HJT log.

    Also: Avenger has made backups of all the files, etc., that you asked it to delete, located at C:\avenger\backup.zip.

    (wait until we finish to post the report and logs)

    3) How to make files and folders visible:
    Click Start > Open My Computer.
    Select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm. Click OK.
    You may reverse this for safety when we are finished.

    4) Start > Control Panel > Add Remove Programs and uninstall SpyShredder if it is there.

    (some items may be gone, removed by Avenger, don't be concerned, just do not miss any)

    5) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

    O2 - BHO: (no name) - {ECEA6D5A-4F00-4908-B64F-C8AA2670FF8C} - C:\WINDOWS\system32\asycfil.dll
    O4 - HKCU\..\Run: [MSI Configuration] msiconf.exe
    O4 - HKCU\..\Run: [SpyShredder] C:\Program Files\SpyShredder\SpyShredder.exe

    Close all programs but HJT and all browser windows, then click on "Fix Checked"

    6) Right click Start > Explore and navigate to these files/folders and delete them if there.

    (make sure these items are gone)

    C:\WINDOWS\system32\msiconf.exe <<< file

    C:\WINDOWS\system32\asycfil.dll <<< file

    C:\Program Files\SpyShredder\ <<< folder and contents

    6) Run ATF Cleaner
    Double-click ATF-Cleaner.exe to run the program.
    Click Select All found at the bottom of the list.
    Click the Empty Selected button.
    Click Exit on the Main menu to close the program.

    Restart and post C:\avenger.txt and a new HJT log.

    Thanks
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  7. #27
    Senior Member
    Join Date
    May 2007
    Posts
    131

    Default Please trust me, I can do it by myself with your help. Thanks

    1. Turn off, Reboot, Turn on system restore. Done
    2. The avenger link to download look total different what you said" Script to Execute", "Input Script Manually", Magnifying Glass icon, "Green light". I don't see all off them, I just add the box: Files to delete: C\Windows\system32........
    And hit Execute button. Done.

  8. #28
    Senior Member
    Join Date
    May 2007
    Posts
    131

    Default C:\avenger.txt

    //////////////////////////////////////////
    Avenger Pre-Processor log
    //////////////////////////////////////////

    Platform: Windows XP (build 2600, Service Pack 2)
    Sun Mar 02 10:22:35 2008

    10:22:35: Error: Invalid script. A valid script must begin with a command directive.
    Aborting execution!


    //////////////////////////////////////////


    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com

    Platform: Windows XP

    *******************

    Script file opened successfully.
    Script file read successfully.

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Rootkit scan active.
    No rootkits found!


    Error: could not open file "C:\WINDOWS\system32\asycfil.dll"
    Deletion of file "C:\WINDOWS\system32\asycfil.dll" failed!
    Status: 0xc0000022 (STATUS_ACCESS_DENIED)

    File "C:\WINDOWS\system32\msiconf.exe" deleted successfully.

    Completed script processing.

    *******************

    Finished! Terminate.

  9. #29
    Senior Member
    Join Date
    May 2007
    Posts
    131

    Default Can not delete asycfil.dll

    The avenger report showed can not delete asycfil.dll.
    I still tried step 6 (right click Start>Explore>navigate to file asycfil.dll, and I still can not delete it.

  10. #30
    Senior Member
    Join Date
    May 2007
    Posts
    131

    Default Latest HijackThis log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:43:08 AM, on 3/2/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
    C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
    C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {ECEA6D5A-4F00-4908-B64F-C8AA2670FF8C} - C:\WINDOWS\system32\asycfil.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
    O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe

    --
    End of file - 5557 bytes

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •