First off, thank you for providing these forums for users to come in and get more reliable, professional help that may never be available to us otherwise.
My virus software first picked up an infected file last night. I believe the source is a carrier on some game mods I downloaded yesterday afternoon.
After the discovery, I did the following:
- Updated all virus softare
- Ran a complete scan using PC-Cillin Internet Security 2007
- Ran Spybot S&D v1.5
Both scans found things, and most were removed, with the exception of a .Mydor virus.
- Rebooted to Safe-Mode and ran Spybot S&D again
- Rebooted Normally to pop-ups caused by virus/malware (asking to download said program to clear it, its the only way)
- Reran complete PC-Cillin scan to find some previously deleted infections had returned.
Then this morning, I ran updates for both programs and did the above again. Things are 'better' in that my computer is usable (performance improvement), and less random pop-ups, but there is still this .Mydor with possibly a few other things that I am unsure of.
Here are the KASPERSKY scan results:
Tuesday, November 27, 2007 7:16:24 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/11/2007
Kaspersky Anti-Virus database records: 467150
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
F:\
Scan Statistics
Total number of scanned objects 146567
Number of viruses found 14
Number of infected objects 35
Number of suspicious objects 0
Duration of the scan process 01:46:35
Infected Object Name Virus Name Last Action
C:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip/winoyb32.dll Infected: Trojan.Win32.Dialer.qn skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Bryan\Application Data\CiscoCAA\event.log Object is locked skipped
C:\Documents and Settings\Bryan\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Bryan\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Bryan\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Bryan\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Bryan\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Application Data\Ahead\Nero Home\is2.db Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Temp\~DF59F4.tmp Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Temporary Internet Files\Content.IE5\9YBAI89Q\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\Documents and Settings\Bryan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Temporary Internet Files\Content.IE5\M1V9US18\pochki20071106[1] Infected: Trojan.Win32.Obfuscated.kp skipped
C:\Documents and Settings\Bryan\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Bryan\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\DAP\Offers\spo3.exe/WISE0010.BIN Infected: not-a-virus:AdTool.Win32.MyWebSearch.bk skipped
C:\Program Files\DAP\Offers\spo3.exe WiseSFX: infected - 1 skipped
C:\Program Files\DAP\Offers\spo3.exe WiseSFX Dropper: infected - 1 skipped
C:\Program Files\DAP\Offers\VA21_DAPSO_US.exe/WISE0009.BIN Infected: not-a-virus:AdTool.Win32.MyWebSearch.bk skipped
C:\Program Files\DAP\Offers\VA21_DAPSO_US.exe WiseSFX: infected - 1 skipped
C:\Program Files\DAP\Offers\VA21_DAPSO_US.exe WiseSFX Dropper: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\61D.tmp Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\648.tmp Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP144\A0029472.dll Object is locked skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP144\A0029473.exe Object is locked skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP160\A0031370.exe Infected: Trojan-Dropper.Win32.Agent.csv skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP160\A0032413.sys Infected: Trojan-Downloader.Win32.Agent.bnm skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP160\A0032414.dll Infected: Trojan-Downloader.Win32.Agent.bnm skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP160\A0032415.dll Infected: Trojan-Downloader.Win32.Agent.bnm skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP161\A0032451.dll Infected: not-a-virus:AdTool.Win32.WhenU.r skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP161\A0032460.dll Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP161\A0034469.sys Infected: Rootkit.Win32.Agent.jp skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP161\A0035500.exe Infected: Trojan-Downloader.Win32.Injecter.ai skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP162\A0035551.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP162\A0035582.exe Infected: Trojan-Downloader.Win32.Injecter.ai skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP162\A0035587.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP162\A0035594.exe Object is locked skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP162\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\fccyvut.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.arm skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\ivuaphbk.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\WINDOWS\system32\jkkllkj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.arm skipped
C:\WINDOWS\system32\ljjkihh.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.arm skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\pokbmkdn.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\WINDOWS\system32\sioeftjh.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\WINDOWS\system32\srafltaq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wqvadbre.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\WINDOWS\system32\xpdx.sys Infected: Trojan.Win32.Agent.cxs skipped
C:\WINDOWS\Temp\$_2341233.TMP Object is locked skipped
C:\WINDOWS\Temp\$_2341234.TMP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_198.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP162\change.log Object is locked skipped
Scan process completed.
My virus software first picked up an infected file last night. I believe the source is a carrier on some game mods I downloaded yesterday afternoon.
After the discovery, I did the following:
- Updated all virus softare
- Ran a complete scan using PC-Cillin Internet Security 2007
- Ran Spybot S&D v1.5
Both scans found things, and most were removed, with the exception of a .Mydor virus.
- Rebooted to Safe-Mode and ran Spybot S&D again
- Rebooted Normally to pop-ups caused by virus/malware (asking to download said program to clear it, its the only way)
- Reran complete PC-Cillin scan to find some previously deleted infections had returned.
Then this morning, I ran updates for both programs and did the above again. Things are 'better' in that my computer is usable (performance improvement), and less random pop-ups, but there is still this .Mydor with possibly a few other things that I am unsure of.
Here are the KASPERSKY scan results:
Tuesday, November 27, 2007 7:16:24 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/11/2007
Kaspersky Anti-Virus database records: 467150
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
F:\
Scan Statistics
Total number of scanned objects 146567
Number of viruses found 14
Number of infected objects 35
Number of suspicious objects 0
Duration of the scan process 01:46:35
Infected Object Name Virus Name Last Action
C:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip/winoyb32.dll Infected: Trojan.Win32.Dialer.qn skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Bryan\Application Data\CiscoCAA\event.log Object is locked skipped
C:\Documents and Settings\Bryan\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Bryan\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Bryan\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Bryan\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Bryan\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Application Data\Ahead\Nero Home\is2.db Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Temp\~DF59F4.tmp Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Temporary Internet Files\Content.IE5\9YBAI89Q\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\Documents and Settings\Bryan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bryan\Local Settings\Temporary Internet Files\Content.IE5\M1V9US18\pochki20071106[1] Infected: Trojan.Win32.Obfuscated.kp skipped
C:\Documents and Settings\Bryan\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Bryan\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\DAP\Offers\spo3.exe/WISE0010.BIN Infected: not-a-virus:AdTool.Win32.MyWebSearch.bk skipped
C:\Program Files\DAP\Offers\spo3.exe WiseSFX: infected - 1 skipped
C:\Program Files\DAP\Offers\spo3.exe WiseSFX Dropper: infected - 1 skipped
C:\Program Files\DAP\Offers\VA21_DAPSO_US.exe/WISE0009.BIN Infected: not-a-virus:AdTool.Win32.MyWebSearch.bk skipped
C:\Program Files\DAP\Offers\VA21_DAPSO_US.exe WiseSFX: infected - 1 skipped
C:\Program Files\DAP\Offers\VA21_DAPSO_US.exe WiseSFX Dropper: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\61D.tmp Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\648.tmp Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP144\A0029472.dll Object is locked skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP144\A0029473.exe Object is locked skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP160\A0031370.exe Infected: Trojan-Dropper.Win32.Agent.csv skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP160\A0032413.sys Infected: Trojan-Downloader.Win32.Agent.bnm skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP160\A0032414.dll Infected: Trojan-Downloader.Win32.Agent.bnm skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP160\A0032415.dll Infected: Trojan-Downloader.Win32.Agent.bnm skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP161\A0032451.dll Infected: not-a-virus:AdTool.Win32.WhenU.r skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP161\A0032460.dll Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP161\A0034469.sys Infected: Rootkit.Win32.Agent.jp skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP161\A0035500.exe Infected: Trojan-Downloader.Win32.Injecter.ai skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP162\A0035551.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP162\A0035582.exe Infected: Trojan-Downloader.Win32.Injecter.ai skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP162\A0035587.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP162\A0035594.exe Object is locked skipped
C:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP162\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\fccyvut.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.arm skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\ivuaphbk.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\WINDOWS\system32\jkkllkj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.arm skipped
C:\WINDOWS\system32\ljjkihh.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.arm skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\pokbmkdn.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\WINDOWS\system32\sioeftjh.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\WINDOWS\system32\srafltaq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wqvadbre.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\WINDOWS\system32\xpdx.sys Infected: Trojan.Win32.Agent.cxs skipped
C:\WINDOWS\Temp\$_2341233.TMP Object is locked skipped
C:\WINDOWS\Temp\$_2341234.TMP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_198.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{BF363889-F59E-4D4A-8D3A-341F40D5F2AA}\RP162\change.log Object is locked skipped
Scan process completed.