pdragonfly
New member
Hi,
The usual.
Have Dell laptop Windows XP pro sp2 (not 3) Currently have Bitdefender which didn't even catch it at all.
SBS&D removes it, but it reappears. Here is the Kaspersky readout, next reply with be Hijack readout. Thank you for help.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, June 09, 2008 08:02
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 9/06/2008
Kaspersky Anti-Virus database records: 841128
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 71729
Number of viruses found: 6
Number of infected objects: 32
Number of suspicious objects: 0
Duration of the scan process: 02:01:05
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Dragonfly\Application Data\Bitdefender\Desktop\Profiles\asdict.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\Application Data\TiVo Desktop\Logs\TiVoNotify.log Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\Application Data\TiVo Desktop\Logs\TiVoTransfer.log Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\History\History.IE5\MSHist012008060820080609\index.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temp\IXP000.TMP\NERO-8~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temp\IXP000.TMP\NERO-8~1.EXE 7-Zip: infected - 1 skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temp\IXP001.TMP\NERO-8~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temp\IXP001.TMP\NERO-8~1.EXE 7-Zip: infected - 1 skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temp\NERO14768\Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temporary Internet Files\Content.IE5\XDNIMKIS\kb516107[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.yhx skipped
C:\Documents and Settings\Dragonfly\ntuser.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\TiVo Desktop\Logs\TiVoBeacon.log Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\BitDefender\BitDefender 2008\as2core\antispam_sig_11885\aspdict.dat Object is locked skipped
C:\Program Files\BitDefender\BitDefender 2008\dbokf.db Object is locked skipped
C:\Program Files\BitDefender\BitDefender 2008\dbokf.db-journal Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP94\A0018339.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP94\A0018351.dll Infected: Trojan.Win32.Agent.rep skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP94\A0018354.dll Infected: Trojan.Win32.Agent.reo skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP96\A0018984.dll Infected: Trojan.Win32.Agent.rep skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP96\A0018987.dll Infected: Trojan.Win32.Agent.reo skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP97\A0019100.exe Object is locked skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP97\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\brpfebns.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yhx skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\geBtQKBU.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\iifebCSI.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\WINDOWS\system32\pmnoPJAp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\WINDOWS\system32\qfthycka.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yhx skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wvUoLcaw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\WINDOWS\TEMP\tmp000075e9\tmp00000000 Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
E:\Nero\Nero.8.3.2.1-UE-Full-RLZ\Nero-8.3.2.1.exe/data0000.cab/is155662.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.yfg skipped
E:\Nero\Nero.8.3.2.1-UE-Full-RLZ\Nero-8.3.2.1.exe/data0000.cab/NERO-8~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\Nero\Nero.8.3.2.1-UE-Full-RLZ\Nero-8.3.2.1.exe/data0000.cab/NERO-8~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\Nero\Nero.8.3.2.1-UE-Full-RLZ\Nero-8.3.2.1.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\Nero\Nero.8.3.2.1-UE-Full-RLZ\Nero-8.3.2.1.exe Rsrc-Package: infected - 4 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017048.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.yfg skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017053.exe/data0000.cab/is155662.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.yfg skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017053.exe/data0000.cab/NERO-8~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017053.exe/data0000.cab/NERO-8~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017053.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017053.exe Rsrc-Package: infected - 4 skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017055.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017055.EXE 7-Zip: infected - 1 skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP94\A0018674.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP94\A0018674.EXE 7-Zip: infected - 1 skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP97\change.log Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP97\change.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP97\change.log Object is locked skipped
Scan process completed.
The usual.
Have Dell laptop Windows XP pro sp2 (not 3) Currently have Bitdefender which didn't even catch it at all.
SBS&D removes it, but it reappears. Here is the Kaspersky readout, next reply with be Hijack readout. Thank you for help.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, June 09, 2008 08:02
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 9/06/2008
Kaspersky Anti-Virus database records: 841128
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 71729
Number of viruses found: 6
Number of infected objects: 32
Number of suspicious objects: 0
Duration of the scan process: 02:01:05
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Dragonfly\Application Data\Bitdefender\Desktop\Profiles\asdict.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\Application Data\TiVo Desktop\Logs\TiVoNotify.log Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\Application Data\TiVo Desktop\Logs\TiVoTransfer.log Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\History\History.IE5\MSHist012008060820080609\index.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temp\IXP000.TMP\NERO-8~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temp\IXP000.TMP\NERO-8~1.EXE 7-Zip: infected - 1 skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temp\IXP001.TMP\NERO-8~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temp\IXP001.TMP\NERO-8~1.EXE 7-Zip: infected - 1 skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temp\NERO14768\Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\Local Settings\Temporary Internet Files\Content.IE5\XDNIMKIS\kb516107[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.yhx skipped
C:\Documents and Settings\Dragonfly\ntuser.dat Object is locked skipped
C:\Documents and Settings\Dragonfly\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\TiVo Desktop\Logs\TiVoBeacon.log Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\BitDefender\BitDefender 2008\as2core\antispam_sig_11885\aspdict.dat Object is locked skipped
C:\Program Files\BitDefender\BitDefender 2008\dbokf.db Object is locked skipped
C:\Program Files\BitDefender\BitDefender 2008\dbokf.db-journal Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP94\A0018339.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP94\A0018351.dll Infected: Trojan.Win32.Agent.rep skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP94\A0018354.dll Infected: Trojan.Win32.Agent.reo skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP96\A0018984.dll Infected: Trojan.Win32.Agent.rep skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP96\A0018987.dll Infected: Trojan.Win32.Agent.reo skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP97\A0019100.exe Object is locked skipped
C:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP97\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\brpfebns.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yhx skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\geBtQKBU.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\iifebCSI.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\WINDOWS\system32\pmnoPJAp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\WINDOWS\system32\qfthycka.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yhx skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wvUoLcaw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\WINDOWS\TEMP\tmp000075e9\tmp00000000 Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
E:\Nero\Nero.8.3.2.1-UE-Full-RLZ\Nero-8.3.2.1.exe/data0000.cab/is155662.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.yfg skipped
E:\Nero\Nero.8.3.2.1-UE-Full-RLZ\Nero-8.3.2.1.exe/data0000.cab/NERO-8~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\Nero\Nero.8.3.2.1-UE-Full-RLZ\Nero-8.3.2.1.exe/data0000.cab/NERO-8~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\Nero\Nero.8.3.2.1-UE-Full-RLZ\Nero-8.3.2.1.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\Nero\Nero.8.3.2.1-UE-Full-RLZ\Nero-8.3.2.1.exe Rsrc-Package: infected - 4 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017048.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.yfg skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017053.exe/data0000.cab/is155662.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.yfg skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017053.exe/data0000.cab/NERO-8~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017053.exe/data0000.cab/NERO-8~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017053.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017053.exe Rsrc-Package: infected - 4 skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017055.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP92\A0017055.EXE 7-Zip: infected - 1 skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP94\A0018674.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP94\A0018674.EXE 7-Zip: infected - 1 skipped
E:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP97\change.log Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP97\change.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{43D3D68F-0FC9-4EF1-8490-D8DA385C3A2F}\RP97\change.log Object is locked skipped
Scan process completed.