My computer is infected with virtumonde and other viruses. I already try sdfix but nothing happened. I follow the instructions of this forum and I'm posting the results here (part 1 Kaspersky report. I'm sending HJT in the next message):
KASPERSKY ONLINE SCANNER REPORT
Thursday, September 13, 2007 11:47:15 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 14/09/2007
Kaspersky Anti-Virus database records: 418187
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 72356
Number of viruses found: 19
Number of infected objects: 54
Number of suspicious objects: 0
Duration of the scan process: 01:01:05
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\7BWR29WW\SpywareSecure_trial_setup[2].exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\7BWR29WW\SpywareSecure_trial_setup[2].exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\7BWR29WW\SpywareSecure_trial_setup[2].exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\7BWR29WW\SpywareSecure_trial_setup[2].exe Embedded EXE: infected - 3 skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\7BWR29WW\SpywareSecure_trial_setup[2].exe UPX: infected - 3 skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\7BWR29WW\SpywareSecure_trial_setup[2].exe PE_Patch.UPX: infected - 3 skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Datos de programa\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Temp\vxcvliff.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Pamela\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Pamela\Datos de programa\Microsoft\MSNLiveFav\LiveFavorites.xml Object is locked skipped
C:\Documents and Settings\Pamela\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Pamela\NTUSER.DAT.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP101\A0077865.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP101\A0077866.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP101\change.log Object is locked skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP77\A0045457.exe Infected: not-a-virus:AdWare.Win32.NaviPromo.gen skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe/EXE-file/stream/data0006 Infected: not-a-virus:AdWare.Win32.NaviPromo.ao skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe/EXE-file/stream Infected: not-a-virus:AdWare.Win32.NaviPromo.ao skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe/EXE-file Infected: not-a-virus:AdWare.Win32.NaviPromo.ao skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe Embedded EXE: infected - 3 skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe PECompact: infected - 3 skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe PecBundle: infected - 3 skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe PE_Patch.PECompact: infected - 3 skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073439.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073444.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073447.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073448.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073449.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.af skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073450.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073451.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073452.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073453.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073454.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073455.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.an skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073456.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.aq skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073457.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073459.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073460.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073462.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073464.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073465.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073466.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ad skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073468.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073469.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073470.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073471.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073483.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073484.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073485.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073486.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073487.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073488.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073489.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073490.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0074482.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP98\A0077603.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP98\A0077604.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP98\A0077605.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{4F1B0BB5-DBB1-4D4E-81B7-FAD0CF6D58A4}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\awtrsqp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\vtutq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
KASPERSKY ONLINE SCANNER REPORT
Thursday, September 13, 2007 11:47:15 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 14/09/2007
Kaspersky Anti-Virus database records: 418187
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 72356
Number of viruses found: 19
Number of infected objects: 54
Number of suspicious objects: 0
Duration of the scan process: 01:01:05
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\7BWR29WW\SpywareSecure_trial_setup[2].exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\7BWR29WW\SpywareSecure_trial_setup[2].exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\7BWR29WW\SpywareSecure_trial_setup[2].exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\7BWR29WW\SpywareSecure_trial_setup[2].exe Embedded EXE: infected - 3 skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\7BWR29WW\SpywareSecure_trial_setup[2].exe UPX: infected - 3 skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\7BWR29WW\SpywareSecure_trial_setup[2].exe PE_Patch.UPX: infected - 3 skipped
C:\Documents and Settings\Pamela\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Datos de programa\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Pamela\Configuración local\Temp\vxcvliff.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Pamela\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Pamela\Datos de programa\Microsoft\MSNLiveFav\LiveFavorites.xml Object is locked skipped
C:\Documents and Settings\Pamela\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Pamela\NTUSER.DAT.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP101\A0077865.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP101\A0077866.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP101\change.log Object is locked skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP77\A0045457.exe Infected: not-a-virus:AdWare.Win32.NaviPromo.gen skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe/EXE-file/stream/data0006 Infected: not-a-virus:AdWare.Win32.NaviPromo.ao skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe/EXE-file/stream Infected: not-a-virus:AdWare.Win32.NaviPromo.ao skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe/EXE-file Infected: not-a-virus:AdWare.Win32.NaviPromo.ao skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe Embedded EXE: infected - 3 skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe PECompact: infected - 3 skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe PecBundle: infected - 3 skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073416.exe PE_Patch.PECompact: infected - 3 skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073439.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073444.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073447.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073448.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073449.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.af skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073450.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073451.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073452.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073453.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073454.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073455.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.an skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073456.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.aq skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073457.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073459.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073460.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073462.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073464.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073465.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073466.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ad skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073468.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073469.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073470.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073471.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073483.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073484.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073485.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073486.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073487.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073488.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073489.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0073490.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP96\A0074482.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP98\A0077603.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP98\A0077604.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\System Volume Information\_restore{7010A40F-22CD-4FE3-BE7C-8B1849020E53}\RP98\A0077605.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{4F1B0BB5-DBB1-4D4E-81B7-FAD0CF6D58A4}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\awtrsqp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\vtutq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.