capitalcollins
New member
Hello. Thank you so much for your help.
My computer has ad popups constantly and Spybot scan has uncovered various problems which it fixed, but the viruses keep returning. I am confused about the spybot popups which warn about registry changes and whether I should allow them. Do the spybot "fixes" require me to allow them to change the registry? I am afraid to allow them and maybe that is why the fix is not permanent? Also when I read some of the virus descriptions they seem to be more dangerous than a simple ad popup.
Please tell me what to do next. Thank you!!!
Here is the Kapersky Log Report. I copied the HJT log into a separate post since this one was too long.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, March 03, 2008 10:42:02 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 3/03/2008
Kaspersky Anti-Virus database records: 594132
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 100858
Number of viruses found: 12
Number of infected objects: 29
Number of suspicious objects: 0
Duration of the scan process: 01:42:16
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\administrator.CBI\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\administrator.CBI\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\03F40000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04200000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08CC0000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0C800000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0C940000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F3C0002.VBN Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F3C0004.VBN Infected: Trojan-Downloader.Win32.VB.caw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F3C0006.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F3C0008.VBN Infected: Trojan.Win32.BHO.ab skipped
C:\Documents and Settings\All Users\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\All Users\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\CBI user\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\CBI user\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\lcollins\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\lcollins\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temp\sdexe.exe Infected: Trojan-Downloader.Win32.PurityScan.fj skipped
C:\Documents and Settings\lcollins\Local Settings\Temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temp\yazzsnet.exe/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Documents and Settings\lcollins\Local Settings\Temp\yazzsnet.exe NSIS: infected - 1 skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\7JTH9096\_NTluZGZlZXRfbWExNHNfbWIxdA_a2V5aW4_a2V5aW4_[1].exe Infected: not-virus:Hoax.Win32.Renos.ayj skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\110886[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\110886[2].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\122952[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\122952[2].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\129051[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\129060[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\129060[2].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\129154[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\129154[2].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\2221-icon[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\92685[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\9444-icon[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\PWPMAOOV\ptch[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\lcollins\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\lcollins\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\lcollins.CBI\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\lcollins.CBI\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\master.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\mastlog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\model.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\modellog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\tempdb.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\templog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\LOG\ERRORLOG Object is locked skipped
C:\Program Files\Windows Media Player\quzarehox.dll Infected: Trojan.Win32.BHO.ab skipped
C:\RECYCLER\S-1-5-21-3590999001-785074029-25018958-1009\Dc101.exe Infected: not-virus:Hoax.Win32.Renos.ayj skipped
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP696\change.log Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\Q0JJIHVzZXI\asappsrv.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\WINDOWS\Q0JJIHVzZXI\command.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{FAFE6B4B-0B03-4E37-887F-86F4AF86DD1D}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\c4\np89104.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\WINDOWS\SYSTEM32\c4\np89104.exe NSIS: infected - 1 skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\a3055.sys Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\core.cache.dsk Object is locked skipped
C:\WINDOWS\SYSTEM32\ftbibtat.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\jtucpxrm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\SYSTEM32\k8\ravecom3.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\WINDOWS\SYSTEM32\mweotbay.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\SYSTEM32\n5\rvdll36.exe Infected: Trojan-Downloader.Win32.Small.irm skipped
C:\WINDOWS\SYSTEM32\nnduugbs.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wgbswgax.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\SYSTEM32\x3\philcom3.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\WINDOWS\Temp\Perflib_Perfdata_4dc.dat Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Thanks.
My computer has ad popups constantly and Spybot scan has uncovered various problems which it fixed, but the viruses keep returning. I am confused about the spybot popups which warn about registry changes and whether I should allow them. Do the spybot "fixes" require me to allow them to change the registry? I am afraid to allow them and maybe that is why the fix is not permanent? Also when I read some of the virus descriptions they seem to be more dangerous than a simple ad popup.
Please tell me what to do next. Thank you!!!
Here is the Kapersky Log Report. I copied the HJT log into a separate post since this one was too long.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, March 03, 2008 10:42:02 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 3/03/2008
Kaspersky Anti-Virus database records: 594132
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 100858
Number of viruses found: 12
Number of infected objects: 29
Number of suspicious objects: 0
Duration of the scan process: 01:42:16
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\administrator.CBI\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\administrator.CBI\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\03F40000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04200000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08CC0000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0C800000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0C940000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F3C0002.VBN Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F3C0004.VBN Infected: Trojan-Downloader.Win32.VB.caw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F3C0006.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0F3C0008.VBN Infected: Trojan.Win32.BHO.ab skipped
C:\Documents and Settings\All Users\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\All Users\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\CBI user\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\CBI user\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\lcollins\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\lcollins\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temp\sdexe.exe Infected: Trojan-Downloader.Win32.PurityScan.fj skipped
C:\Documents and Settings\lcollins\Local Settings\Temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temp\yazzsnet.exe/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Documents and Settings\lcollins\Local Settings\Temp\yazzsnet.exe NSIS: infected - 1 skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\7JTH9096\_NTluZGZlZXRfbWExNHNfbWIxdA_a2V5aW4_a2V5aW4_[1].exe Infected: not-virus:Hoax.Win32.Renos.ayj skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\110886[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\110886[2].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\122952[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\122952[2].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\129051[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\129060[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\129060[2].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\129154[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\129154[2].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\2221-icon[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\92685[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\9444-icon[1].jpg Object is locked skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\JIGF5T27\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\lcollins\Local Settings\Temporary Internet Files\Content.IE5\PWPMAOOV\ptch[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\lcollins\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\lcollins\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\lcollins.CBI\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\lcollins.CBI\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\master.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\mastlog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\model.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\modellog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\tempdb.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\templog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\LOG\ERRORLOG Object is locked skipped
C:\Program Files\Windows Media Player\quzarehox.dll Infected: Trojan.Win32.BHO.ab skipped
C:\RECYCLER\S-1-5-21-3590999001-785074029-25018958-1009\Dc101.exe Infected: not-virus:Hoax.Win32.Renos.ayj skipped
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP696\change.log Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\Q0JJIHVzZXI\asappsrv.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\WINDOWS\Q0JJIHVzZXI\command.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{FAFE6B4B-0B03-4E37-887F-86F4AF86DD1D}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\c4\np89104.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\WINDOWS\SYSTEM32\c4\np89104.exe NSIS: infected - 1 skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\a3055.sys Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\core.cache.dsk Object is locked skipped
C:\WINDOWS\SYSTEM32\ftbibtat.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\jtucpxrm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\SYSTEM32\k8\ravecom3.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\WINDOWS\SYSTEM32\mweotbay.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\SYSTEM32\n5\rvdll36.exe Infected: Trojan-Downloader.Win32.Small.irm skipped
C:\WINDOWS\SYSTEM32\nnduugbs.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wgbswgax.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\SYSTEM32\x3\philcom3.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\WINDOWS\Temp\Perflib_Perfdata_4dc.dat Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Thanks.