yellowbird
New member
Hi -
I have run spybot s&d in Safe Mode but still have virtumonde coming up in scans. Here is my Kaspersky log. HJT log is too long to include in this post, so I'll post it as a reply to this one. Please let me know what I need to do next to get this fixed. I really appreciate your help!
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, February 11, 2008 12:31:08 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 11/02/2008
Kaspersky Anti-Virus database records: 557799
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 142581
Number of viruses found: 23
Number of infected objects: 65
Number of suspicious objects: 0
Duration of the scan process: 02:37:24
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\cert8.db Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\history.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\key3.db Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\parent.lock Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\ѕуstem32\wuauboot.exe Infected: Trojan-Downloader.Win32.PurityScan.fj skipped
C:\Documents and Settings\Erich Brouhard\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\History\History.IE5\MSHist012008021120080212\index.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\4X6FW1QN\ADCFreeInstaller[1].exe Infected: not-a-virus
ownloader.Win32.AdvancedCleaner.c skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\816ZKHUF\17PHolmes[1].cmt Infected: Trojan-Downloader.Win32.Agent.iug skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\816ZKHUF\_bm1fbWRfcmlka2tpaTIyX3JvbjNfbWE4_aHR0cA_bm1fNjg3MjNfNDk3NjM4ZDBkNzFkMTFkYzk1MDBmNjg3MjNkZWZmZmZfNjkxZTgxOWM3MTQ5NGEzYTlkOWUxMGJiMzE3N2M5M2I_[1].exe Infected: not-virus:Hoax.Win32.Renos.aun skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\G9ZGNS2W\AntiVirusInstallFreeNM_en[1].cab/UGA6P_0001_N120M1710NetInstaller.exe Infected: not-a-virus
ownloader.Win32.WinFixer.an skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\G9ZGNS2W\AntiVirusInstallFreeNM_en[1].cab CAB: infected - 1 skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\J7MIWIDG\CA5WUTHN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\J7MIWIDG\installer[1].exe/file1 Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\J7MIWIDG\installer[1].exe/file2 Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\J7MIWIDG\installer[1].exe/file4 Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\J7MIWIDG\installer[1].exe Inno: infected - 3 skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\M5VAO8MQ\rasesnet[1].exe Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\WLE7G9AN\snapsnet[1].exe/data0006 Infected: Trojan-Downloader.Win32.VB.cgu skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\WLE7G9AN\snapsnet[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\WLE7G9AN\yazzsnet[1].exe/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\WLE7G9AN\yazzsnet[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\XZVYL7A8\!update-4495[1].0000 Infected: Trojan-Downloader.Win32.PurityScan.fk skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\XZVYL7A8\17PHolmes[1].cmt Infected: Trojan-Downloader.Win32.Agent.iug skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\XZVYL7A8\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Erich Brouhard\ntuser.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1263\A0123587.dll Infected: Trojan-Spy.Win32.Agent.ir skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125656.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125658.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125660.exe Infected: not-a-virus:FraudTool.Win32.DrAntispy.ax skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125662.dll Infected: not-a-virus:FraudTool.Win32.BraveSentry.f skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125664.dll Infected: not-a-virus:FraudTool.Win32.BraveSentry.b skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125667.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125668.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125668.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125669.dll Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125670.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125672.exe Infected: not-virus:Hoax.Win32.Renos.aun skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125681.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125683.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126674.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126700.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126701.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126702.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126703.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126704.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126705.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1266\change.log Object is locked skipped
C:\VundoFix Backups\iagofjkv.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\jkkli.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\leeskeaj.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\nwjqdvac.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\tuvuvut.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\xxyywxw.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\yxsatqxy.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\mrofinu1000106.exe Infected: Trojan-Downloader.Win32.Agent.iug skipped
C:\WINDOWS\mrofinu572.exe Infected: Trojan-Downloader.Win32.Agent.iug skipped
C:\WINDOWS\RXJpY2ggQnJvdWhhcmQ\asappsrv.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\WINDOWS\RXJpY2ggQnJvdWhhcmQ\command.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\ac1\tliamdll2.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\WINDOWS\system32\afern.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gv skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\atinrvxxx.sys Object is locked skipped
C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
C:\WINDOWS\system32\ehbukosj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\jdjvyehn.exe Infected: Trojan-Spy.Win32.Agent.ir skipped
C:\WINDOWS\system32\kp9\liopud89104.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\WINDOWS\system32\kp9\liopud89104.exe NSIS: infected - 1 skipped
C:\WINDOWS\system32\mmqoaaaa.exe Infected: Trojan-Clicker.Win32.Delf.hi skipped
C:\WINDOWS\system32\mvrcuaaa.exe Infected: Backdoor.Win32.Small.na skipped
C:\WINDOWS\system32\mxmmcaaa.exe Infected: Trojan-Spy.Win32.BZub.ik skipped
C:\WINDOWS\system32\nastrdmw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe Infected: Trojan-Downloader.Win32.VB.cgu skipped
C:\WINDOWS\system32\rtxhnnue.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\ttehgaju.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\xxyywxw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
I have run spybot s&d in Safe Mode but still have virtumonde coming up in scans. Here is my Kaspersky log. HJT log is too long to include in this post, so I'll post it as a reply to this one. Please let me know what I need to do next to get this fixed. I really appreciate your help!
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, February 11, 2008 12:31:08 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 11/02/2008
Kaspersky Anti-Virus database records: 557799
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 142581
Number of viruses found: 23
Number of infected objects: 65
Number of suspicious objects: 0
Duration of the scan process: 02:37:24
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\cert8.db Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\history.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\key3.db Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\parent.lock Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Application Data\ѕуstem32\wuauboot.exe Infected: Trojan-Downloader.Win32.PurityScan.fj skipped
C:\Documents and Settings\Erich Brouhard\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Application Data\Mozilla\Firefox\Profiles\362zmt2f.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\History\History.IE5\MSHist012008021120080212\index.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\4X6FW1QN\ADCFreeInstaller[1].exe Infected: not-a-virus

C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\816ZKHUF\17PHolmes[1].cmt Infected: Trojan-Downloader.Win32.Agent.iug skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\816ZKHUF\_bm1fbWRfcmlka2tpaTIyX3JvbjNfbWE4_aHR0cA_bm1fNjg3MjNfNDk3NjM4ZDBkNzFkMTFkYzk1MDBmNjg3MjNkZWZmZmZfNjkxZTgxOWM3MTQ5NGEzYTlkOWUxMGJiMzE3N2M5M2I_[1].exe Infected: not-virus:Hoax.Win32.Renos.aun skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\G9ZGNS2W\AntiVirusInstallFreeNM_en[1].cab/UGA6P_0001_N120M1710NetInstaller.exe Infected: not-a-virus

C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\G9ZGNS2W\AntiVirusInstallFreeNM_en[1].cab CAB: infected - 1 skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\J7MIWIDG\CA5WUTHN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\J7MIWIDG\installer[1].exe/file1 Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\J7MIWIDG\installer[1].exe/file2 Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\J7MIWIDG\installer[1].exe/file4 Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\J7MIWIDG\installer[1].exe Inno: infected - 3 skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\M5VAO8MQ\rasesnet[1].exe Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\WLE7G9AN\snapsnet[1].exe/data0006 Infected: Trojan-Downloader.Win32.VB.cgu skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\WLE7G9AN\snapsnet[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\WLE7G9AN\yazzsnet[1].exe/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\WLE7G9AN\yazzsnet[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\XZVYL7A8\!update-4495[1].0000 Infected: Trojan-Downloader.Win32.PurityScan.fk skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\XZVYL7A8\17PHolmes[1].cmt Infected: Trojan-Downloader.Win32.Agent.iug skipped
C:\Documents and Settings\Erich Brouhard\Local Settings\Temporary Internet Files\Content.IE5\XZVYL7A8\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Erich Brouhard\ntuser.dat Object is locked skipped
C:\Documents and Settings\Erich Brouhard\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1263\A0123587.dll Infected: Trojan-Spy.Win32.Agent.ir skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125656.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125658.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125660.exe Infected: not-a-virus:FraudTool.Win32.DrAntispy.ax skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125662.dll Infected: not-a-virus:FraudTool.Win32.BraveSentry.f skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125664.dll Infected: not-a-virus:FraudTool.Win32.BraveSentry.b skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125667.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125668.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125668.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125669.dll Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125670.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125672.exe Infected: not-virus:Hoax.Win32.Renos.aun skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125681.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0125683.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126674.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126700.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126701.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126702.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126703.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126704.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1264\A0126705.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{58E30938-66A1-4D08-9DCD-360CE25B3A88}\RP1266\change.log Object is locked skipped
C:\VundoFix Backups\iagofjkv.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\jkkli.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\leeskeaj.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\nwjqdvac.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\tuvuvut.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\xxyywxw.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\yxsatqxy.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\mrofinu1000106.exe Infected: Trojan-Downloader.Win32.Agent.iug skipped
C:\WINDOWS\mrofinu572.exe Infected: Trojan-Downloader.Win32.Agent.iug skipped
C:\WINDOWS\RXJpY2ggQnJvdWhhcmQ\asappsrv.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\WINDOWS\RXJpY2ggQnJvdWhhcmQ\command.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\ac1\tliamdll2.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\WINDOWS\system32\afern.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gv skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\atinrvxxx.sys Object is locked skipped
C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
C:\WINDOWS\system32\ehbukosj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\jdjvyehn.exe Infected: Trojan-Spy.Win32.Agent.ir skipped
C:\WINDOWS\system32\kp9\liopud89104.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\WINDOWS\system32\kp9\liopud89104.exe NSIS: infected - 1 skipped
C:\WINDOWS\system32\mmqoaaaa.exe Infected: Trojan-Clicker.Win32.Delf.hi skipped
C:\WINDOWS\system32\mvrcuaaa.exe Infected: Backdoor.Win32.Small.na skipped
C:\WINDOWS\system32\mxmmcaaa.exe Infected: Trojan-Spy.Win32.BZub.ik skipped
C:\WINDOWS\system32\nastrdmw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe Infected: Trojan-Downloader.Win32.VB.cgu skipped
C:\WINDOWS\system32\rtxhnnue.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\ttehgaju.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\xxyywxw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.