Cannot get rid of Torpig...

Good morning, It is good to turn off the adware programs as they tend to block changes but turn it back on as soon as you are done. System Restore should not be off, we consider a bad restore point better than no restore point in an emergency, which is what you would have with it off.

Nothing showing in combofix and the HJT log is clean. No doubt you had Vundo infection, it could be you got reinfected. Let me show you how easy it is to pick up an exploit:
http://www.theregister.com/2007/05/11/google_malware_map/
http://redtape.msnbc.com/2007/05/the_next_net_th.html

Let's see what Kaspersky shows us.

Thanks
 
Hi Phil,

And here's the one from Kaspersky as well:-

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2007-06-29 23:07
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 29/06/2007
Kaspersky Anti-Virus database records: 333481
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
N:\
O:\
Z:\

Scan Statistics:
Total number of scanned objects: 92167
Number of viruses found: 4
Number of infected objects: 23 / 0
Number of suspicious objects: 2
Duration of the scan process: 00:58:02

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12262006-114648.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.ldb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.mdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentqt.zip/retadpu2000352.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentqt.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-06-29_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A9C0000\4E9DEB54.VBN Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A9C0001\4E9DEB5C.VBN Infected: Trojan.Win32.Agent.anr skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A9C0002\4E9DED29.VBN Infected: Trojan-Downloader.Win32.Tiny.gx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A9C0003\4E9DF23E.VBN Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AF80000\4EFA3B99.VBN Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AF80001\4EFA3BA1.VBN Infected: Trojan.Win32.Agent.anr skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BAC0000\4FAC6693.VBN Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BAC0001\4FAC66A6.VBN Infected: Trojan.Win32.Agent.anr skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BCC0000\4FCDAACD.VBN Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BCC0001\4FCDAADA.VBN Infected: Trojan.Win32.Agent.anr skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BE40000\4FE5B3AD.VBN Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BF40000\4FF45FD9.VBN Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BF40001\4FF45FF4.VBN Infected: Trojan.Win32.Agent.anr skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BF80000\4FF870FA.VBN Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BF80001\4FF87102.VBN Infected: Trojan.Win32.Agent.anr skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C500000\4ED1F6DE.VBN Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C500001\4ED1F786.VBN Infected: Trojan.Win32.Agent.anr skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CB80000\4EB9F46C.VBN Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CB80001\4EB9F50D.VBN Infected: Trojan.Win32.Agent.anr skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D980000\4F98E38C.VBN Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D980001\4F98E393.VBN Infected: Trojan.Win32.Agent.anr skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB40000\4FB60969.VBN Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB40001\4FB60A00.VBN Infected: Trojan.Win32.Agent.anr skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\contactgroup256.dbb Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\dyncontent\bundle.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\index2.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\profile16384.dbb Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\user1024.dbb Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\user256.dbb Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\voicemail256.dbb Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Teleca\Telecalib\Logging\Application logs\SpecificUSB_log.txt Object is locked skipped
C:\Documents and Settings\chrisglassock\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbc2e.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbdam Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbdao Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbeam Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbeao Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbm Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbu2d.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbvm.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbvmh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\fii.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\fiih.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\hp Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\hpt2i.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\rpm.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\rpm1m.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\rpm1mh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\rpmh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-black-enchashm.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-black-enchashmh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-black-urlm.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-black-urlmh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-malware-domainm.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-malware-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-white-domainm.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-white-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\History\History.IE5\MSHist012007062920070630\index.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Temp\~DF3807.tmp Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Temp\~DF381F.tmp Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Temp\~DFEAC0.tmp Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\chrisglassock\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\chrisglassock\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0453NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0571NAV~.TMP Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{5F1C0B7B-D87A-4D9F-94F3-EAAB64CD8CA1}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\JETB611.tmp Object is locked skipped
C:\WINDOWS\Temp\JETB788.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\VAIO Entertainment\database\MtData.ldb Object is locked skipped
D:\VAIO Entertainment\database\MtData.mdb Object is locked skipped

Scan process completed.


Thanks a lot.

Fritz
 
Thanks, clean out the Symantec quarantine folder:
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\
http://service1.symantec.com/SUPPORT/nav.nsf/docid/2000041213443506

Clean your Cache and Cookies in IE:
  • Close all instances of Outlook Express and Internet Explorer
  • Go to Control Panel > Internet Options > General tab
  • Click the "Delete Cookies" button
  • Next to it, Click the "Delete Files" button
  • When prompted, place a check in: "Delete all offline content", click OK
* Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
  • Go to Tools > Options.
  • Click Privacy in the menu on the left side of the Options window.
  • Click the Clear button located to the right of each option (History, Cookies, Cache).
  • Click OK to close the Options window
    Alternatively, you can clear all information stored while browsing by clicking Clear All.
    A confirmation dialog box will be shown before clearing the information.
* Clean other Temporary files + Recycle bin
  • Go to start > run and type: cleanmgr and click ok.
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Press OK to remove them.

Post another Kasperky scan results.

Thanks
 
Hi Again!

Cleaned out the Symantec files - they were in the backups folder

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Backups

but were all the trojans etc. that we have been looking at.


Did these:-

- Clean your Cache and Cookies in IE
- Clean other Temporary files + Recycle bin


And here's the Kaspersky scan - looking better now - fingers crossed!

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2007-06-30 10:58
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 30/06/2007
Kaspersky Anti-Virus database records: 333827
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
N:\
O:\
Z:\

Scan Statistics:
Total number of scanned objects: 91923
Number of viruses found: 1
Number of infected objects: 0 / 0
Number of suspicious objects: 2
Duration of the scan process: 00:57:07

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12262006-114648.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.ldb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.mdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentqt.zip/retadpu2000352.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentqt.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-06-29_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\contactgroup256.dbb Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\dyncontent\bundle.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\index2.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\profile16384.dbb Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\user1024.dbb Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\user256.dbb Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Skype\fritz135\voicemail256.dbb Object is locked skipped
C:\Documents and Settings\chrisglassock\Application Data\Teleca\Telecalib\Logging\Application logs\SpecificUSB_log.txt Object is locked skipped
C:\Documents and Settings\chrisglassock\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbc2e.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbdam Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbdao Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbeam Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbeao Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbm Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbu2d.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbvm.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\dbvmh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\fii.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\fiih.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\hp Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\hpt2i.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\rpm.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\rpm1m.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\rpm1mh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\rpmh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-black-enchashm.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-black-enchashmh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-black-urlm.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-black-urlmh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-malware-domainm.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-malware-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-white-domainm.cf1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Google\Google Desktop\ae5d0f510216\safeweb\goog-white-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{137DCD80-CDDA-4BB3-B776-54150E15DD26} Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\History\History.IE5\MSHist012007063020070701\index.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Temp\~DFEAC0.tmp Object is locked skipped
C:\Documents and Settings\chrisglassock\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\chrisglassock\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\chrisglassock\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\chrisglassock\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0453NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0571NAV~.TMP Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{3F8A943F-EA94-4A97-9E58-B55D13F926B5}\RP2\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{7BBE04F4-4100-46B9-8C19-789EB78DC20A}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\JETB611.tmp Object is locked skipped
C:\WINDOWS\Temp\JETB788.tmp Object is locked skipped
C:\WINDOWS\Temp\~DF3008.tmp Object is locked skipped
C:\WINDOWS\Temp\~DF30C2.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\VAIO Entertainment\database\MtData.ldb Object is locked skipped
D:\VAIO Entertainment\database\MtData.mdb Object is locked skipped

Scan process completed.
 
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ <<< delete the contents of Spybot S&D Recovery.
(two suspecious items in there)

I looked up and down that list and can not spot the infected item? Perhaps it is system remove, so let's clean those again to be sure, if you spot then infected item in that report, let me know what it was.
System Restore does not know the good files from the bad. In case bad stuff has gotten into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, reboot then turn it back on:
http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/tips/mcgill1.mspx

If everything is running ok now, I would say you are good to go.

Thanks...Phil
 
Hi Phil,

Done all that and created a restor point and things do seem to be running a lot better.

What do we do from here? I guess I just keep an eye on it for a week or so and fingers crossed it's all good.

I cannot convey how much I appreciate your help with all of this. I will go through all of the tutorials and set up the suggested tools and settings on both my laptop and home PC.

Do you have a charity or something like that that I could make a donation to for your time and effort?

All the best.

Fritz
 
Back
Top