You may have to turn system restore "off":
http://www.pchell.com/virus/systemrestore.shtml
Then run the scan.
Go ahead and post a partial listing, first.
Just ran a new scan it now shows no virus found , so apparently it did heal them
but IE will not open from original file. The error now reads MSVCRT DLL error
Hmmm…
Find "MSVCRT.DLL" using windows explorer, and rename it to "MSVCRT.old"
Then go here:
http://www.dll-files.com/dllindex/dll-files.shtml?msvcrt
And download a new copy
INTO THE SAME FOLDER WHERE THE ORIGINAL ONE WAS .
Then reboot & try IE.
in the last scan here is a sample of files it said not cured
zip>VerifierBug.class Java.ByteVerify.exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
archiven.jar-26cc6137-50f67d42.zip>Beyond.class Java.Shinwow.I cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
archive.jar-27b6d966-706e199c.zip>BlackBox.class Java.ByteVerify.exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
archive.jar-27b6d966-706e199c.zip>VerifierBug.class Java.ByteVerify.exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
archive.jar-27b6d966-706e199c.zip>Dummy.class Java.ByteVerify.exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
archive.jar-27b6d966-706e199c.zip>Beyond.class Java.Shinwow.F cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
archive.jar-27b6d962-376cf12e.zip>BlackBox.class Java.ByteVerify.exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
archive.jar-27b6d962-376cf12e.zip>VerifierBug.class Java.ByteVerify.exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
archive.jar-27b6d962-376cf12e.zip>Dummy.class Java.ByteVerify.exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
archive.jar-27b6d962-376cf12e.zip>Beyond.class Java.Shinwow.F cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
Dummy.class-6e74ebaf-5f1f1ca6.class Java.ByteVerify.exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\
ok.class-2487e7a1-320ee50b.class Java.ByteVerify.exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\
Dummy.class-5e7a704e-1c2bd9af.class Java.ByteVerify.exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\
javada32.exe Win32.Winshow.N cannot cure C:\WINDOWS\
vaypyq.dat Win32.Winshow.N cannot cure C:\WINDOWS\
pirctj.dat Win32.Winshow.P cannot cure C:\WINDOWS\
yjcfce.dat Win32.Winshow.P cannot cure C:\WINDOWS\
mhtsdu.dat Win32.Winshow.P cannot cure C:\WINDOWS\
These I am sure you can delete:
Java.ByteVerify.exploit cannot cure C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\
javada32.exe
Win32.Winshow.N cannot cure C:\WINDOWS\
vaypyq.dat
Win32.Winshow.N cannot cure C:\WINDOWS\
pirctj.dat
Win32.Winshow.P cannot cure C:\WINDOWS\
yjcfce.dat
Win32.Winshow.P cannot cure C:\WINDOWS\
mhtsdu.dat
I'll ask Daemon to peek in and give us an opinion.
My educated guess is that anything "uncleanable" just needs to be deleted.
BUT WAIT FOR ANOTHER OPINION!!!!
As I understand it, virii do one of two things:
1. Attach themselves to the end of existing files (If so, the file can be cleaned).
2. The WHOLE FILE is a virus and needs deleted.
Let's see what Daemon has to say.
Good job!
Here's something that may get rid of some of the infected files:
Click on Start>Control Panel>Java Plug in>Cache, then click on "Clear".
Reboot.
Run the virus scan again. Post the names of all the infected files left, if possible.