Hi,
My browser was acting funny ( symptoms: unable to search in Google, some sites refuses to open, some site ads are replaced with junk adult ads etc)
I did a scan with SpyBot and got these results shown up in red:
doubleclick - tracking cookie,
fastclick - tracking cookie,
mediaplex - tracking cookie
Virtumonde - 2 entries
Virtumonde.dll - 8 entries
Tried deleting them but Spybot hung on Virtumonde dll and I lost my patience and quit . Spybot also got jammed in safemode so I rebooted to normal mode and deleted the others.
When faced with serious problems like this I prefer to reinstall the OS and other programs but I am unable to do even that. The os setup files gets copied, the system reboots and then.....zilch,...nothing happens except the old os reboots (no OS install setup code in the boot menu)
TIA
--------------------------------------------------------------
Here is my HJT result:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:50:30 PM, on 4/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe ??????
C:\Program Files\Comodo\Firewall\CPF.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\HDD Thermometer\HDD Thermometer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\IPCheck Server Monitor 5\Firebird\bin\fbguard.exe
C:\Program Files\IPCheck Server Monitor 5\Firebird\bin\fbserver.exe
C:\Program Files\IPCheck Server Monitor 5\IPCheckProbe.exe
C:\Program Files\IPCheck Server Monitor 5\IPCheckServer.exe
C:\Program Files\IPCheck Server Monitor 5\IPCheckServer.exe
C:\Program Files\Avast4\ashMaiSv.exe
C:\Program Files\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O3 - Toolbar: &Netcraft Toolbar - {D554D8FC-B36D-4BB4-93DB-4A3394D505E3} - C:\Program Files\Netcraft Toolbar\nctb.dll
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [BMc7743b3e] Rundll32.exe "C:\WINDOWS\system32\jmwkqrky.dll",s
O4 - HKLM\..\Run: [c44708a2] rundll32.exe "C:\WINDOWS\system32\nndryghm.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [RSD_HDDThermo] C:\Program Files\HDD Thermometer\HDD Thermometer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB2609] command /c del "C:\WINDOWS\system32\dqlhwipj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2242] cmd /c del "C:\WINDOWS\system32\dqlhwipj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7830] command /c del "C:\WINDOWS\system32\hgGwVMFU.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9882] cmd /c del "C:\WINDOWS\system32\hgGwVMFU.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB849] command /c del "C:\WINDOWS\system32\ohsukjxw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3201] cmd /c del "C:\WINDOWS\system32\ohsukjxw.dll_old"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1205358557234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1205652980468
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.12) - http://service.futuremark.com/virtualmark/tc/MSC3.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Bandwidth Controller Server (bcserver) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\IPCheck Server Monitor 5\Firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\IPCheck Server Monitor 5\Firebird\bin\fbserver.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\ISO Recorder\ImapiHelper.exe
O23 - Service: IPCheck Server Monitor Local/Remote Probe Module (IPCProbeService) - Paessler AG - C:\Program Files\IPCheck Server Monitor 5\IPCheckProbe.exe
O23 - Service: IPCheck Server Monitor Webserver Module (IPCServerService) - Paessler AG - C:\Program Files\IPCheck Server Monitor 5\IPCheckServer.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SandraLite\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SandraLite\RpcSandraSrv.exe
--
End of HJT file
----------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, April 28, 2008 5:34:45 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/04/2008
Kaspersky Anti-Virus database records: 727826
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
L:\
Scan Statistics
Total number of scanned objects 336823
Number of viruses found 19
Number of infected objects 45
Number of suspicious objects 0
Duration of the scan process 03:14:20
Infected Object Name Virus Name Last Action
C:\Documents and Settings\admin\ntuser.dat Object is locked skipped
C:\Documents and Settings\admin\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\username\Application Data\Apple Computer\Safari\PubSub\Database\Database.sqlite3 Object is locked skipped
C:\Documents and Settings\username\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\username\Local Settings\Application Data\Apple Computer\Safari\Cache.db Object is locked skipped
C:\Documents and Settings\username\Local Settings\Application Data\Apple Computer\Safari\WebpageIcons.db Object is locked skipped
C:\Documents and Settings\username\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\username\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\username\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\username\Local Settings\Temp\Perflib_Perfdata_2bc.dat Object is locked skipped
C:\Documents and Settings\username\Local Settings\Temp\~DF891B.tmp Object is locked skipped
C:\Documents and Settings\username\Local Settings\Temporary Internet Files\Content.IE5\8QM4ZQYK\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.qrj skipped
C:\Documents and Settings\username\Local Settings\Temporary Internet Files\Content.IE5\B8J4UR0P\CA5WUTHN Infected: not-a-virus:AdWare.Win32.Virtumonde.qni skipped
C:\Documents and Settings\username\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\username\Local Settings\Temporary Internet Files\Content.IE5\UMI0RM6Q\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.qri skipped
C:\Documents and Settings\username\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\username\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\firebird\security2.fdb Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\firebird\WINDOWS.lck Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\IPCBACKUP.FDB Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\IPCHECK.FDB Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\log\ipcerror.log Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\log\ipcweb20080428.log Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\log\remerr.log Object is locked skipped
C:\System Volume Information\_restore{1B5A7CA2-368E-48E2-997F-F9638DAEFA7B}\RP1\A0003125.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qni skipped
C:\System Volume Information\_restore{1B5A7CA2-368E-48E2-997F-F9638DAEFA7B}\RP1\A0003126.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrh skipped
C:\System Volume Information\_restore{1B5A7CA2-368E-48E2-997F-F9638DAEFA7B}\RP1\A0004125.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrj skipped
C:\System Volume Information\_restore{1B5A7CA2-368E-48E2-997F-F9638DAEFA7B}\RP1\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\NetLimit.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\dqlhwipj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qri skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\ljJYQGaA.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qne skipped
C:\WINDOWS\system32\msclwroq.dll Infected: Packed.Win32.Monder.gen skipped
C:\WINDOWS\system32\ohsukjxw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrg skipped
C:\WINDOWS\system32\onfvwmrh.dll Infected: Packed.Win32.Monder.gen skipped
C:\WINDOWS\system32\puegmmgb.dll Infected: Packed.Win32.Monder.gen skipped
C:\WINDOWS\system32\qnljjhbd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qri skipped
C:\WINDOWS\system32\smejnurr.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrj skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_72c.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\PROGRAM FILES\+ CMS New\Joomla\server\SlimFTPd_3.16.exe/data.rar/SlimFTPd/SlimFTPd.exe Infected: not-a-virus:Server-FTP.Win32.SlimFTPd.316 skipped
E:\PROGRAM FILES\+ CMS New\Joomla\server\SlimFTPd_3.16.exe/data.rar Infected: not-a-virus:Server-FTP.Win32.SlimFTPd.316 skipped
E:\PROGRAM FILES\+ CMS New\Joomla\server\SlimFTPd_3.16.exe RarSFX: infected - 2 skipped
E:\PROGRAM FILES\+ SOUND\Download_smrproa.exe Infected: not-a-virus
ownloader.Win32.WinFixer.fs skipped
E:\PROGRAM FILES\+ TOOLS\Network Monitor\FinitySoftNetworkMonitor.exe/stream/data0006 Infected: not-a-virus:Monitor.Win32.NetMon.c skipped
E:\PROGRAM FILES\+ TOOLS\Network Monitor\FinitySoftNetworkMonitor.exe/stream Infected: not-a-virus:Monitor.Win32.NetMon.c skipped
E:\PROGRAM FILES\+ TOOLS\Network Monitor\FinitySoftNetworkMonitor.exe NSIS: infected - 2 skipped
E:\PROGRAM FILES\+SECURITY\SmitFraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
E:\PROGRAM FILES\+SECURITY\SmitFraudFix\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
E:\PROGRAM FILES\+SECURITY\SmitFraudFix\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
E:\PROGRAM FILES\+SECURITY\SmitFraudFix\SmitfraudFix.exe RarSFX: infected - 2 skipped
E:\PROGRAM FILES\+SECURITY\SmitFraudFix\SmitfraudFix.exe PE_Patch.UPX: infected - 2 skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.exe/data0004 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.exe Inno: infected - 3 skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.zip/vnc-3.3.7-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.zip/vnc-3.3.7-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.zip/vnc-3.3.7-x86_win32.exe/data0004 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.zip/vnc-3.3.7-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.zip ZIP: infected - 4 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{1B5A7CA2-368E-48E2-997F-F9638DAEFA7B}\RP1\change.log Object is locked skipped
F:\OTHER CONTENT\MISCfromDdrive\from CD\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar/axdlplug.dll Infected: not-a-virus:AdWare.Win32.PluginDL.a skipped
F:\OTHER CONTENT\MISCfromDdrive\from CD\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar/buddy.exe Infected: Trojan.Win32.Obfuscated.s skipped
F:\OTHER CONTENT\MISCfromDdrive\from CD\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar/setup2.exe Infected: not-a-virus:AdWare.Win32.PluginDL.a skipped
F:\OTHER CONTENT\MISCfromDdrive\from CD\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar Infected: not-a-virus:AdWare.Win32.PluginDL.a skipped
F:\OTHER CONTENT\MISCfromDdrive\from CD\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe RarSFX: infected - 4 skipped
F:\OTHER CONTENT\old docs\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar/axdlplug.dll Infected: not-a-virus:AdWare.Win32.PluginDL.a skipped
F:\OTHER CONTENT\old docs\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar/buddy.exe Infected: Trojan.Win32.Obfuscated.s skipped
F:\OTHER CONTENT\old docs\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar/setup2.exe Infected: not-a-virus:AdWare.Win32.PluginDL.a skipped
F:\OTHER CONTENT\old docs\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar Infected: not-a-virus:AdWare.Win32.PluginDL.a skipped
F:\OTHER CONTENT\old docs\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe RarSFX: infected - 4 skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
End of Kaspersky Scan process
----------------------------------------------------------------
My browser was acting funny ( symptoms: unable to search in Google, some sites refuses to open, some site ads are replaced with junk adult ads etc)
I did a scan with SpyBot and got these results shown up in red:
doubleclick - tracking cookie,
fastclick - tracking cookie,
mediaplex - tracking cookie
Virtumonde - 2 entries
Virtumonde.dll - 8 entries
Tried deleting them but Spybot hung on Virtumonde dll and I lost my patience and quit . Spybot also got jammed in safemode so I rebooted to normal mode and deleted the others.
When faced with serious problems like this I prefer to reinstall the OS and other programs but I am unable to do even that. The os setup files gets copied, the system reboots and then.....zilch,...nothing happens except the old os reboots (no OS install setup code in the boot menu)
TIA

--------------------------------------------------------------
Here is my HJT result:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:50:30 PM, on 4/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe ??????
C:\Program Files\Comodo\Firewall\CPF.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\HDD Thermometer\HDD Thermometer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\IPCheck Server Monitor 5\Firebird\bin\fbguard.exe
C:\Program Files\IPCheck Server Monitor 5\Firebird\bin\fbserver.exe
C:\Program Files\IPCheck Server Monitor 5\IPCheckProbe.exe
C:\Program Files\IPCheck Server Monitor 5\IPCheckServer.exe
C:\Program Files\IPCheck Server Monitor 5\IPCheckServer.exe
C:\Program Files\Avast4\ashMaiSv.exe
C:\Program Files\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O3 - Toolbar: &Netcraft Toolbar - {D554D8FC-B36D-4BB4-93DB-4A3394D505E3} - C:\Program Files\Netcraft Toolbar\nctb.dll
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [BMc7743b3e] Rundll32.exe "C:\WINDOWS\system32\jmwkqrky.dll",s
O4 - HKLM\..\Run: [c44708a2] rundll32.exe "C:\WINDOWS\system32\nndryghm.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [RSD_HDDThermo] C:\Program Files\HDD Thermometer\HDD Thermometer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB2609] command /c del "C:\WINDOWS\system32\dqlhwipj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2242] cmd /c del "C:\WINDOWS\system32\dqlhwipj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7830] command /c del "C:\WINDOWS\system32\hgGwVMFU.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9882] cmd /c del "C:\WINDOWS\system32\hgGwVMFU.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB849] command /c del "C:\WINDOWS\system32\ohsukjxw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3201] cmd /c del "C:\WINDOWS\system32\ohsukjxw.dll_old"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1205358557234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1205652980468
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.12) - http://service.futuremark.com/virtualmark/tc/MSC3.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Bandwidth Controller Server (bcserver) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\IPCheck Server Monitor 5\Firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\IPCheck Server Monitor 5\Firebird\bin\fbserver.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\ISO Recorder\ImapiHelper.exe
O23 - Service: IPCheck Server Monitor Local/Remote Probe Module (IPCProbeService) - Paessler AG - C:\Program Files\IPCheck Server Monitor 5\IPCheckProbe.exe
O23 - Service: IPCheck Server Monitor Webserver Module (IPCServerService) - Paessler AG - C:\Program Files\IPCheck Server Monitor 5\IPCheckServer.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SandraLite\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SandraLite\RpcSandraSrv.exe
--
End of HJT file
----------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, April 28, 2008 5:34:45 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/04/2008
Kaspersky Anti-Virus database records: 727826
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
L:\
Scan Statistics
Total number of scanned objects 336823
Number of viruses found 19
Number of infected objects 45
Number of suspicious objects 0
Duration of the scan process 03:14:20
Infected Object Name Virus Name Last Action
C:\Documents and Settings\admin\ntuser.dat Object is locked skipped
C:\Documents and Settings\admin\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\username\Application Data\Apple Computer\Safari\PubSub\Database\Database.sqlite3 Object is locked skipped
C:\Documents and Settings\username\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\username\Local Settings\Application Data\Apple Computer\Safari\Cache.db Object is locked skipped
C:\Documents and Settings\username\Local Settings\Application Data\Apple Computer\Safari\WebpageIcons.db Object is locked skipped
C:\Documents and Settings\username\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\username\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\username\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\username\Local Settings\Temp\Perflib_Perfdata_2bc.dat Object is locked skipped
C:\Documents and Settings\username\Local Settings\Temp\~DF891B.tmp Object is locked skipped
C:\Documents and Settings\username\Local Settings\Temporary Internet Files\Content.IE5\8QM4ZQYK\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.qrj skipped
C:\Documents and Settings\username\Local Settings\Temporary Internet Files\Content.IE5\B8J4UR0P\CA5WUTHN Infected: not-a-virus:AdWare.Win32.Virtumonde.qni skipped
C:\Documents and Settings\username\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\username\Local Settings\Temporary Internet Files\Content.IE5\UMI0RM6Q\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.qri skipped
C:\Documents and Settings\username\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\username\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\firebird\security2.fdb Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\firebird\WINDOWS.lck Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\IPCBACKUP.FDB Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\IPCHECK.FDB Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\log\ipcerror.log Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\log\ipcweb20080428.log Object is locked skipped
C:\Program Files\IPCheck Server Monitor 5\log\remerr.log Object is locked skipped
C:\System Volume Information\_restore{1B5A7CA2-368E-48E2-997F-F9638DAEFA7B}\RP1\A0003125.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qni skipped
C:\System Volume Information\_restore{1B5A7CA2-368E-48E2-997F-F9638DAEFA7B}\RP1\A0003126.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrh skipped
C:\System Volume Information\_restore{1B5A7CA2-368E-48E2-997F-F9638DAEFA7B}\RP1\A0004125.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrj skipped
C:\System Volume Information\_restore{1B5A7CA2-368E-48E2-997F-F9638DAEFA7B}\RP1\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\NetLimit.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\dqlhwipj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qri skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\ljJYQGaA.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qne skipped
C:\WINDOWS\system32\msclwroq.dll Infected: Packed.Win32.Monder.gen skipped
C:\WINDOWS\system32\ohsukjxw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrg skipped
C:\WINDOWS\system32\onfvwmrh.dll Infected: Packed.Win32.Monder.gen skipped
C:\WINDOWS\system32\puegmmgb.dll Infected: Packed.Win32.Monder.gen skipped
C:\WINDOWS\system32\qnljjhbd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qri skipped
C:\WINDOWS\system32\smejnurr.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrj skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_72c.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\PROGRAM FILES\+ CMS New\Joomla\server\SlimFTPd_3.16.exe/data.rar/SlimFTPd/SlimFTPd.exe Infected: not-a-virus:Server-FTP.Win32.SlimFTPd.316 skipped
E:\PROGRAM FILES\+ CMS New\Joomla\server\SlimFTPd_3.16.exe/data.rar Infected: not-a-virus:Server-FTP.Win32.SlimFTPd.316 skipped
E:\PROGRAM FILES\+ CMS New\Joomla\server\SlimFTPd_3.16.exe RarSFX: infected - 2 skipped
E:\PROGRAM FILES\+ SOUND\Download_smrproa.exe Infected: not-a-virus

E:\PROGRAM FILES\+ TOOLS\Network Monitor\FinitySoftNetworkMonitor.exe/stream/data0006 Infected: not-a-virus:Monitor.Win32.NetMon.c skipped
E:\PROGRAM FILES\+ TOOLS\Network Monitor\FinitySoftNetworkMonitor.exe/stream Infected: not-a-virus:Monitor.Win32.NetMon.c skipped
E:\PROGRAM FILES\+ TOOLS\Network Monitor\FinitySoftNetworkMonitor.exe NSIS: infected - 2 skipped
E:\PROGRAM FILES\+SECURITY\SmitFraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
E:\PROGRAM FILES\+SECURITY\SmitFraudFix\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
E:\PROGRAM FILES\+SECURITY\SmitFraudFix\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
E:\PROGRAM FILES\+SECURITY\SmitFraudFix\SmitfraudFix.exe RarSFX: infected - 2 skipped
E:\PROGRAM FILES\+SECURITY\SmitFraudFix\SmitfraudFix.exe PE_Patch.UPX: infected - 2 skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.exe/data0004 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.exe Inno: infected - 3 skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.zip/vnc-3.3.7-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.zip/vnc-3.3.7-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.zip/vnc-3.3.7-x86_win32.exe/data0004 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.zip/vnc-3.3.7-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
E:\PROGRAM FILES\RealVNC PC2PC\vnc-3.3.7-x86_win32.zip ZIP: infected - 4 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{1B5A7CA2-368E-48E2-997F-F9638DAEFA7B}\RP1\change.log Object is locked skipped
F:\OTHER CONTENT\MISCfromDdrive\from CD\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar/axdlplug.dll Infected: not-a-virus:AdWare.Win32.PluginDL.a skipped
F:\OTHER CONTENT\MISCfromDdrive\from CD\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar/buddy.exe Infected: Trojan.Win32.Obfuscated.s skipped
F:\OTHER CONTENT\MISCfromDdrive\from CD\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar/setup2.exe Infected: not-a-virus:AdWare.Win32.PluginDL.a skipped
F:\OTHER CONTENT\MISCfromDdrive\from CD\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar Infected: not-a-virus:AdWare.Win32.PluginDL.a skipped
F:\OTHER CONTENT\MISCfromDdrive\from CD\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe RarSFX: infected - 4 skipped
F:\OTHER CONTENT\old docs\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar/axdlplug.dll Infected: not-a-virus:AdWare.Win32.PluginDL.a skipped
F:\OTHER CONTENT\old docs\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar/buddy.exe Infected: Trojan.Win32.Obfuscated.s skipped
F:\OTHER CONTENT\old docs\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar/setup2.exe Infected: not-a-virus:AdWare.Win32.PluginDL.a skipped
F:\OTHER CONTENT\old docs\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe/data.rar Infected: not-a-virus:AdWare.Win32.PluginDL.a skipped
F:\OTHER CONTENT\old docs\MiscFiles\axdlplug-1.5.0.0-0147-setup.exe RarSFX: infected - 4 skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
End of Kaspersky Scan process
----------------------------------------------------------------