wolkster27
New member
Ok I read the virus scan stuff before posting and did all that. By the way, hi all and I'm glad your here.
Attached is my Karpansky scan and hjt file.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, March 15, 2008 2:47:47 PM
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/03/2008
Kaspersky Anti-Virus database records: 631660
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
G:\
Scan Statistics:
Total number of scanned objects: 128348
Number of viruses found: 14
Number of infected objects: 103
Number of suspicious objects: 8
Duration of the scan process: 01:25:21
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\10693fc17333284bbbe5af437c565ccd_40734c29-153f-4343-a744-d2a513ce9872 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1b8df03006e647858a59bd2bc3053a85_40734c29-153f-4343-a744-d2a513ce9872 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\32552108887cb842bdc5e761f30c2bfc_40734c29-153f-4343-a744-d2a513ce9872 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4ab40a0919d612766b8102fe86ab6555_40734c29-153f-4343-a744-d2a513ce9872 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\900d6ab8cd4183252b91189de0d691f5_40734c29-153f-4343-a744-d2a513ce9872 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aa302ea1dafe8d4789fd58241e382bea_40734c29-153f-4343-a744-d2a513ce9872 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\sbkzudmn.dll Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader1.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader1.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip/updatetc.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant3.zip/saap.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant3.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant7.zip/saap.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant7.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\janice @ home\Local Settings\Temporary Internet Files\Content.IE5\EPSNQ9Y9\iddqd[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\janice @ home\Local Settings\Temporary Internet Files\Content.IE5\ST8W260G\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\janice @ home\Local Settings\Temporary Internet Files\Content.IE5\T8PP32NO\CA1WU557 Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Kristina\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Kristina\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Kristina\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Kristina\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kristina\Local Settings\History\History.IE5\MSHist012008031520080316\index.dat Object is locked skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\45URWP27\iddqd[2] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\45URWP27\Installer2[1].exe Infected: not-a-virus:FraudTool.Win32.Reanimator.a skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\45URWP27\in[1].htm Infected: Trojan-Downloader.JS.Zapchast.f skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\CDM34P2V\in[1].htm Infected: Trojan-Downloader.JS.Zapchast.f skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\CDM34P2V\ptch[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\K30T252B\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\K30T252B\in[1] Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\OHQ7SHUJ\install[1].exe Infected: not-virus:Hoax.Win32.Renos.bcz skipped
C:\Documents and Settings\Kristina\ntuser.dat Object is locked skipped
C:\Documents and Settings\Kristina\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1404\A0112293.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1405\A0112324.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1405\A0112325.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1409\A0112377.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1410\A0112389.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1411\A0113265.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1411\A0113293.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1412\A0114293.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1413\A0116293.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0117408.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0117426.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0117427.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0117433.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0117433.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0117434.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0118408.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118491.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118493.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118495.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118519.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118520.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jxa skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118521.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118634.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jxa skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118647.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118676.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1419\A0125125.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1419\A0125154.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1419\A0125155.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1419\A0125158.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1419\A0125158.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1419\A0125159.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127598.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127649.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127650.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127656.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127656.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127657.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127889.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127891.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127908.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127908.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127909.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0130520.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0130521.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0130523.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0130562.exe Infected: not-virus:Hoax.Win32.Renos.bcz skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0130579.exe Infected: not-virus:Hoax.Win32.Renos.bcs skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1421\A0131968.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1421\A0131969.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1423\change.log Object is locked skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037686.exe Infected: Trojan-Downloader.Win32.Small.ayl skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037687.exe Infected: Trojan-Downloader.Win32.Small.ayl skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037688.dll Infected: not-a-virus:AdWare.Win32.AccessMedia.a skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037689.exe Infected: Trojan-Downloader.Win32.Small.ayl skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037690.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037691.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037692.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037693.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037694.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037695.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037696.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037697.exe Infected: not-a-virus:FraudTool.Win32.Reanimator.a skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
Attached is my Karpansky scan and hjt file.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, March 15, 2008 2:47:47 PM
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/03/2008
Kaspersky Anti-Virus database records: 631660
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
G:\
Scan Statistics:
Total number of scanned objects: 128348
Number of viruses found: 14
Number of infected objects: 103
Number of suspicious objects: 8
Duration of the scan process: 01:25:21
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\10693fc17333284bbbe5af437c565ccd_40734c29-153f-4343-a744-d2a513ce9872 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1b8df03006e647858a59bd2bc3053a85_40734c29-153f-4343-a744-d2a513ce9872 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\32552108887cb842bdc5e761f30c2bfc_40734c29-153f-4343-a744-d2a513ce9872 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4ab40a0919d612766b8102fe86ab6555_40734c29-153f-4343-a744-d2a513ce9872 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\900d6ab8cd4183252b91189de0d691f5_40734c29-153f-4343-a744-d2a513ce9872 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aa302ea1dafe8d4789fd58241e382bea_40734c29-153f-4343-a744-d2a513ce9872 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\sbkzudmn.dll Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader1.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader1.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip/updatetc.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant3.zip/saap.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant3.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant7.zip/saap.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant7.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\janice @ home\Local Settings\Temporary Internet Files\Content.IE5\EPSNQ9Y9\iddqd[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\janice @ home\Local Settings\Temporary Internet Files\Content.IE5\ST8W260G\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\janice @ home\Local Settings\Temporary Internet Files\Content.IE5\T8PP32NO\CA1WU557 Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Kristina\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Kristina\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Kristina\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Kristina\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kristina\Local Settings\History\History.IE5\MSHist012008031520080316\index.dat Object is locked skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\45URWP27\iddqd[2] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\45URWP27\Installer2[1].exe Infected: not-a-virus:FraudTool.Win32.Reanimator.a skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\45URWP27\in[1].htm Infected: Trojan-Downloader.JS.Zapchast.f skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\CDM34P2V\in[1].htm Infected: Trojan-Downloader.JS.Zapchast.f skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\CDM34P2V\ptch[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\K30T252B\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\K30T252B\in[1] Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\Kristina\Local Settings\Temporary Internet Files\Content.IE5\OHQ7SHUJ\install[1].exe Infected: not-virus:Hoax.Win32.Renos.bcz skipped
C:\Documents and Settings\Kristina\ntuser.dat Object is locked skipped
C:\Documents and Settings\Kristina\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1404\A0112293.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1405\A0112324.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1405\A0112325.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1409\A0112377.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1410\A0112389.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1411\A0113265.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1411\A0113293.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1412\A0114293.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1413\A0116293.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0117408.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0117426.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0117427.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0117433.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0117433.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0117434.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1416\A0118408.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118491.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118493.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118495.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118519.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118520.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jxa skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118521.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118634.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jxa skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118647.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1418\A0118676.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1419\A0125125.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1419\A0125154.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1419\A0125155.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1419\A0125158.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1419\A0125158.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1419\A0125159.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127598.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127649.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127650.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127656.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127656.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127657.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127889.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127891.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127908.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127908.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0127909.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0130520.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0130521.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0130523.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0130562.exe Infected: not-virus:Hoax.Win32.Renos.bcz skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1420\A0130579.exe Infected: not-virus:Hoax.Win32.Renos.bcs skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1421\A0131968.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1421\A0131969.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{4C5CE0F5-92D1-4DA1-9FC2-9ADBA5DE5947}\RP1423\change.log Object is locked skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037686.exe Infected: Trojan-Downloader.Win32.Small.ayl skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037687.exe Infected: Trojan-Downloader.Win32.Small.ayl skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037688.dll Infected: not-a-virus:AdWare.Win32.AccessMedia.a skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037689.exe Infected: Trojan-Downloader.Win32.Small.ayl skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037690.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037691.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037692.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037693.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037694.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037695.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037696.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037697.exe Infected: not-a-virus:FraudTool.Win32.Reanimator.a skipped
C:\System Volume Information\_restore{DAD694DE-40A4-4C14-9FD8-83C57F9D5227}\RP909\A0037698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped