This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virut.A has my system tied up

159 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Incident Status Location Virus:W32/Virutas.B Disinfected C:\Program Files\Mozilla Firefox\updater.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Mozilla Firefox\xpicleanup.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Mozilla Firefox\extensions\[removed]\components\talkback.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Mozilla Firefox\uninstall\uninstall.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Mozilla Firefox\firefox.exe Virus:W32/Virutas.B Disinfected C:\Downloads\ATF-Cleaner.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\WISPTIS.EXE Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\ctfmon.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe Potentially unwanted tool:Application/PRScheduler Not disinfected C:\undo\backup.cab[\Device\Harddisk0\Partition1\WINDOWS\Start Menu\Programs\StartUp\PowerReg Scheduler.exe] Potentially unwanted tool:Application/PRScheduler Not disinfected C:\undo\backup.cab[\Device\Harddisk0\Partition1\WINDOWS\Start Menu\Programs\Disabled Startup Items\PowerReg Scheduler.exe] Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\ehm720in.default\cookies.txt[.go.com/] Adware:Adware/Transponder Not disinfected C:\Documents and Settings\Neil\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\0f829e07be8b3e8d1776749cb2b9cdc4 Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.tribalfusion.com/] Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.atdmt.com/] Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.tribalfusion.com/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.advertising.com/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.2o7.net/] Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.ads.addynamix.com/] Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.perf.overture.com/] Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.questionmarket.com/] Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.www.myaffiliateprogram.com/] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[server.iad.liveperson.net/] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[server.iad.liveperson.net/hc/78221172]
This looks better. I would like to know that some other scans would run. At least Panda did and previously you had problems with that. And we had results from Kapersky. Wonder if the FSecure will run.

Blacklight

Download Blacklight trial from here:
http://www.f-secure.com/blacklight/
  • Hit I accept. It will take you to download page.
  • Download blbeta.exe and save it to the Desktop.
  • Once saved… double click blbeta.exe to install the program.
  • Click accept agreement and Click scan
    This app too may fire off a warning from antivirus. Let the driver load.
    Wait for it to finish.
  • If it displays any items…don't do anything with them yet. Just hit exit (close)
  • It will drop a log on Desktop that starts with fsbl….big number
Please post contents of log.

Please run the F-Secure Online Scanner
Note: This Scanner is for Internet Explorer Only!
  • Follow the Instruction on the F-Secure page for proper installation.
  • Accept the License Agreement.
  • Once the ActiveX installs,Click Full System Scan
  • Once the download completes,the scan will begin automatically.
  • The scan will take some time to finish,so please be patient.
  • When the scan completes, click the Automatic cleaning (recommended) button.
  • Click the Show Report button and Copy&Paste the entire report in your next reply.

Please post the Blacklight log that stars with the fsbl….big number and the results from F-Secure.
FSBL log results 09/11/06 14:29:22 [Info]: BlackLight Engine 1.0.46 initialized 09/11/06 14:29:22 [Info]: OS: 5.1 build 2600 (Service Pack 2) 09/11/06 14:29:23 [Note]: 7019 4 09/11/06 14:29:23 [Note]: 7005 0 09/11/06 14:29:28 [Note]: 7006 0 09/11/06 14:29:28 [Note]: 7011 1524 09/11/06 14:29:29 [Note]: 7026 0 09/11/06 14:29:29 [Note]: 7026 0 09/11/06 14:29:32 [Note]: FSRAW library version 1.7.1019 F-secure gave me the same error as before, the downloaded database is corrupt. But, its a much bigger database this time.
Hi euqruob,

Just curious. Will this one work? After that infection you had, I would just like to see a few scans complete. Then if this one works, maybe we can start wrapping this up.

http://housecall.trendmicro.com/
That one won't either, I can't get java to install. I've uninstalled and reinstalled via the web and manually and I can't get Java to install Which sucks, because I'd like to have it running.
Will this help?

Updating Java
  • Download the latest version of Java Runtime Environment (JRE) 5.0 Update 8.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-1_5_0_08-windowsi586-p.exe to install the newest version.
So far so good, I am going to be out of town from tomorrow afternoon till Tuesday morning, so if you don't hear from me for a while, you know why
Bit defender ran, here are the results BitDefender Online Scanner Scan report generated at: Tue, Sep 12, 2006 - 15:30:59 Scan path: C:\;D:\;E:\;F:\; Statistics Time 03:25:36 Files 1626224 Folders 22579 Boot Sectors 4 Archives 27991 Packed Files 110775 Results Identified Viruses 5 Infected Files 63 Suspect Files 0 Warnings 0 Disinfected 45 Deleted Files 16 Engines Info Virus Definitions 453879 Engine build AVCORE v1.0 (build 2310) (i386) (Apr 17 2006 16:24:38) Scan plugins 13 Archive plugins 38 Unpack plugins 6 E-mail plugins 6 System plugins 1 Scan Settings First Action Disinfect Second Action Delete Heuristics Yes Enable Warnings Yes Scanned Extensions *; Exclude Extensions Scan Emails Yes Scan Archives Yes Scan Packed Yes Scan Files Yes Scan Boot Yes Scanned File Status C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_08.b03\zipper.exe Infected with: Win32.Virtob.C C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_08.b03\zipper.exe Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_08.b03\launcher.exe Infected with: Win32.Virtob.C C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_08.b03\launcher.exe Disinfected C:\Program Files\Mozilla Firefox\updater.exe Infected with: Win32.Virtob.C C:\Program Files\Mozilla Firefox\updater.exe Disinfected C:\Program Files\Mozilla Firefox\xpicleanup.exe Infected with: Win32.Virtob.C C:\Program Files\Mozilla Firefox\xpicleanup.exe Disinfected C:\Program Files\Mozilla Firefox\extensions\[removed]\components\talkback.exe Infected with: Win32.Virtob.C C:\Program Files\Mozilla Firefox\extensions\[removed]\components\talkback.exe Disinfected C:\Program Files\Mozilla Firefox\uninstall\uninstall.exe Infected with: Win32.Virtob.C C:\Program Files\Mozilla Firefox\uninstall\uninstall.exe Disinfected C:\Program Files\Mozilla Firefox\firefox.exe Infected with: Win32.Virtob.C C:\Program Files\Mozilla Firefox\firefox.exe Disinfection failed C:\Program Files\Mozilla Firefox\firefox.exe Delete failed C:\Program Files\Magellan\MapSend DirectRoute NA\MapSend.exe Infected with: Win32.Virtob.C C:\Program Files\Magellan\MapSend DirectRoute NA\MapSend.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\java.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\java.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\javacpl.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\javacpl.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\javaw.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\javaw.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\javaws.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\javaws.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\jucheck.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\jucheck.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\keytool.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\keytool.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\kinit.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\kinit.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\klist.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\klist.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\ktab.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\ktab.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\orbd.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\orbd.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\pack200.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\pack200.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\policytool.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\policytool.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\rmid.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\rmid.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\rmiregistry.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\rmiregistry.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\servertool.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\servertool.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\tnameserv.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\tnameserv.exe Disinfected C:\Program Files\Java\jre1.5.0_08\bin\unpack200.exe Infected with: Win32.Virtob.C C:\Program Files\Java\jre1.5.0_08\bin\unpack200.exe Disinfected C:\Downloads\ATF-Cleaner.exe Infected with: Win32.Virtob.C C:\Downloads\ATF-Cleaner.exe Disinfected C:\WINDOWS\system32\WISPTIS.EXE Infected with: Win32.Virtob.C C:\WINDOWS\system32\WISPTIS.EXE Disinfection failed C:\WINDOWS\system32\WISPTIS.EXE Delete failed C:\WINDOWS\system32\java.exe Infected with: Win32.Virtob.C C:\WINDOWS\system32\java.exe Disinfected C:\WINDOWS\system32\javaw.exe Infected with: Win32.Virtob.C C:\WINDOWS\system32\javaw.exe Disinfected C:\WINDOWS\system32\javaws.exe Infected with: Win32.Virtob.C C:\WINDOWS\system32\javaws.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe Infected with: Win32.Virtob.C C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\OnlineScanner\Anti-Virus\fsgk32.exe Infected with: Win32.Virtob.C C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\OnlineScanner\Anti-Virus\fsgk32.exe Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\OnlineScanner\Anti-Virus\fssm32.exe Infected with: Win32.Virtob.C C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\OnlineScanner\Anti-Virus\fssm32.exe Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\mexe.com Infected with: BehavesLike:Win32.FileInfector C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\mexe.com Disinfection failed C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\mexe.com Deleted C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\mwavscan.com Infected with: BehavesLike:Win32.FileInfector C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\mwavscan.com Disinfection failed C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\mwavscan.com Deleted C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)=>mexe.com Infected with: BehavesLike:Win32.FileInfector C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)=>mexe.com Disinfection failed C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)=>mexe.com Deleted C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o) Update failed C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)=>mwavscan.com Infected with: BehavesLike:Win32.FileInfector C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)=>mwavscan.com Disinfection failed C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)=>mwavscan.com Deleted C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o) Update failed C:\Documents and Settings\Neil Bourque.NEIL.000\.housecall6.6\getMac.exe Infected with: Win32.Virtob.C C:\Documents and Settings\Neil Bourque.NEIL.000\.housecall6.6\getMac.exe Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\.housecall6.6\tsc.exe Infected with: Win32.Virtob.C C:\Documents and Settings\Neil Bourque.NEIL.000\.housecall6.6\tsc.exe Disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010306.exe=>(NSIS o)=>lzma_nsis0001 Infected with: Trojan.Downloader.VB.TX C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010306.exe=>(NSIS o)=>lzma_nsis0001 Disinfection failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010306.exe=>(NSIS o)=>lzma_nsis0001 Deleted C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010306.exe=>(NSIS o) Update failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe=>(NSIS o)=>lzma_nsis0001 Infected with: Trojan.Downloader.VB.TX C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe=>(NSIS o)=>lzma_nsis0001 Disinfection failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe=>(NSIS o)=>lzma_nsis0001 Deleted C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe=>(NSIS o) Update failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011278.exe=>(NSIS o)=>lzma_nsis0001 Infected with: Trojan.Downloader.VB.TX C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011278.exe=>(NSIS o)=>lzma_nsis0001 Disinfection failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011278.exe=>(NSIS o)=>lzma_nsis0001 Deleted C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011278.exe=>(NSIS o) Update failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011289.exe=>(NSIS o)=>lzma_nsis0001 Infected with: Trojan.Downloader.VB.TX C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011289.exe=>(NSIS o)=>lzma_nsis0001 Disinfection failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011289.exe=>(NSIS o)=>lzma_nsis0001 Deleted C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011289.exe=>(NSIS o) Update failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011846.exe=>(NSIS o)=>lzma_nsis0001 Infected with: Trojan.Downloader.VB.TX C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011846.exe=>(NSIS o)=>lzma_nsis0001 Disinfection failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011846.exe=>(NSIS o)=>lzma_nsis0001 Deleted C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011846.exe=>(NSIS o) Update failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe=>(NSIS o)=>lzma_nsis0001 Infected with: Trojan.Downloader.VB.TX C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe=>(NSIS o)=>lzma_nsis0001 Disinfection failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe=>(NSIS o)=>lzma_nsis0001 Deleted C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe=>(NSIS o) Update failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025232.exe=>(NSIS o)=>lzma_nsis0001 Infected with: Trojan.Downloader.VB.TX C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025232.exe=>(NSIS o)=>lzma_nsis0001 Disinfection failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025232.exe=>(NSIS o)=>lzma_nsis0001 Deleted C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025232.exe=>(NSIS o) Update failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025246.exe=>(NSIS o)=>lzma_nsis0001 Infected with: Trojan.Downloader.VB.TX C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025246.exe=>(NSIS o)=>lzma_nsis0001 Disinfection failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025246.exe=>(NSIS o)=>lzma_nsis0001 Deleted C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025246.exe=>(NSIS o) Update failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)=>drxvp.exe Infected with: GenPack:Trojan.DollarRevenue.B C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)=>drxvp.exe Disinfection failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)=>drxvp.exe Deleted C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o) Update failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)=>pnky.exe Infected with: Trojan.Vundo.K C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)=>pnky.exe Disinfection failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)=>pnky.exe Deleted C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o) Update failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032001.exe=>(NSIS o)=>lzma_nsis0001 Infected with: Trojan.Downloader.VB.TX C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032001.exe=>(NSIS o)=>lzma_nsis0001 Disinfection failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032001.exe=>(NSIS o)=>lzma_nsis0001 Deleted C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032001.exe=>(NSIS o) Update failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032008.exe=>(NSIS o)=>lzma_nsis0001 Infected with: Trojan.Downloader.VB.TX C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032008.exe=>(NSIS o)=>lzma_nsis0001 Disinfection failed C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032008.exe=>(NSIS o)=>lzma_nsis0001 Deleted C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032008.exe=>(NSIS o) Update failed
Hi euqruob, Thanks for the log. I noticed that two files could not be cleaned and deleted. I will get back to you but at least the other files were disenfected or deleted.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI