Horlicks10
New member
HI. I have the virtumode virus on my PC. It's running windows 2000 pro. I've run spybot and it's always left with three components. I have followed your forums advice by running the Kaspersky on line checker and below is the report. To me this doesn't look like it'll help as everything is skipped etc, but maybe you know different) I have tried installing the HijackThis application but always get an error on installation stating that hijackthis.exe has generated an error and then bins out.
Can you please help!!!
THanks.
KASPERSKY ONLINE SCANNER REPORT
Tuesday, May 27, 2008 5:20:53 PM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/05/2008
Kaspersky Anti-Virus database records: 801429
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 40544
Number of viruses found: 2
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 01:03:47
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Application Data\McAfee\MBK\ARBUSFILE.GDB Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012008052720080528\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\sqlite_hHqMYS2DxIrcGJD Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\sqlite_HreTftLLj9mz1Ju Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\sqlite_jBQuQQvBPeFNFgI Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\sqlite_jCUQbSUYatgbvdz Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\sqlite_zaj4EDB81YjeyMd Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\~DFF1C6.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6D0NAL01\kb456456[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.tfx skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\tempIpRules.xdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{A159EB3C-ABB0-4220-A730-D72E01C44F68}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\MSKWMDB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\RBLDB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\settingsdb.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR4.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Default User\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Default User\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\Sti_Trace.log Object is locked skipped
C:\WINNT\SYSTEM32\CatRoot\SYSMAST.CBD Object is locked skipped
C:\WINNT\SYSTEM32\CatRoot\SYSMAST.CBK Object is locked skipped
C:\WINNT\SYSTEM32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATMAST.cbd Object is locked skipped
C:\WINNT\SYSTEM32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATMAST.cbk Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SYSTEM.ALT Object is locked skipped
C:\WINNT\SYSTEM32\gMWEOqss.ini Object is locked skipped
C:\WINNT\SYSTEM32\Perflib_Perfdata_570.dat Object is locked skipped
C:\WINNT\SYSTEM32\qeljxuea.SH! Infected: not-a-virus:AdWare.Win32.Virtumonde.tsh skipped
C:\WINNT\Temp\fb_600.lck Object is locked skipped
C:\WINNT\Temp\mcafee_kuT3sP0oXxlmImu Object is locked skipped
C:\WINNT\Temp\mcafee_ltGGXtIsrR9MdbO Object is locked skipped
C:\WINNT\Temp\mcmsc_C8MmVeweHda9gdu Object is locked skipped
C:\WINNT\Temp\mcmsc_oeafB3IpE01fsgu Object is locked skipped
C:\WINNT\Temp\mcmsc_Qyx3BBYbuqvZ1bS Object is locked skipped
C:\WINNT\Temp\mcmsc_Xgz8M93SI96DRwI Object is locked skipped
C:\WINNT\Temp\sqlite_NPv0EOIQlXOirXk Object is locked skipped
C:\WINNT\Temp\sqlite_peWp7HeMAMv5Bdc Object is locked skipped
Scan process completed.
Can you please help!!!
THanks.
KASPERSKY ONLINE SCANNER REPORT
Tuesday, May 27, 2008 5:20:53 PM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/05/2008
Kaspersky Anti-Virus database records: 801429
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 40544
Number of viruses found: 2
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 01:03:47
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Application Data\McAfee\MBK\ARBUSFILE.GDB Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012008052720080528\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\sqlite_hHqMYS2DxIrcGJD Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\sqlite_HreTftLLj9mz1Ju Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\sqlite_jBQuQQvBPeFNFgI Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\sqlite_jCUQbSUYatgbvdz Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\sqlite_zaj4EDB81YjeyMd Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\~DFF1C6.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6D0NAL01\kb456456[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.tfx skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\tempIpRules.xdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{A159EB3C-ABB0-4220-A730-D72E01C44F68}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\MSKWMDB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\RBLDB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\settingsdb.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR4.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Default User\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Default User\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\Sti_Trace.log Object is locked skipped
C:\WINNT\SYSTEM32\CatRoot\SYSMAST.CBD Object is locked skipped
C:\WINNT\SYSTEM32\CatRoot\SYSMAST.CBK Object is locked skipped
C:\WINNT\SYSTEM32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATMAST.cbd Object is locked skipped
C:\WINNT\SYSTEM32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATMAST.cbk Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SYSTEM.ALT Object is locked skipped
C:\WINNT\SYSTEM32\gMWEOqss.ini Object is locked skipped
C:\WINNT\SYSTEM32\Perflib_Perfdata_570.dat Object is locked skipped
C:\WINNT\SYSTEM32\qeljxuea.SH! Infected: not-a-virus:AdWare.Win32.Virtumonde.tsh skipped
C:\WINNT\Temp\fb_600.lck Object is locked skipped
C:\WINNT\Temp\mcafee_kuT3sP0oXxlmImu Object is locked skipped
C:\WINNT\Temp\mcafee_ltGGXtIsrR9MdbO Object is locked skipped
C:\WINNT\Temp\mcmsc_C8MmVeweHda9gdu Object is locked skipped
C:\WINNT\Temp\mcmsc_oeafB3IpE01fsgu Object is locked skipped
C:\WINNT\Temp\mcmsc_Qyx3BBYbuqvZ1bS Object is locked skipped
C:\WINNT\Temp\mcmsc_Xgz8M93SI96DRwI Object is locked skipped
C:\WINNT\Temp\sqlite_NPv0EOIQlXOirXk Object is locked skipped
C:\WINNT\Temp\sqlite_peWp7HeMAMv5Bdc Object is locked skipped
Scan process completed.