I'm running it now, it looks like it is running OK at this point.
I'll get back to you when it finishes, I have it scanning local drives.
Incident Status Location
Virus:W32/Virutas.B Disinfected C:\Program Files\Mozilla Firefox\updater.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Mozilla Firefox\xpicleanup.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Mozilla Firefox\extensions\[removed]\components\talkback.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Mozilla Firefox\uninstall\uninstall.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Mozilla Firefox\firefox.exe
Virus:W32/Virutas.B Disinfected C:\Downloads\ATF-Cleaner.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\WISPTIS.EXE
Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\ctfmon.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected C:\undo\backup.cab[\Device\Harddisk0\Partition1\WINDOWS\Start Menu\Programs\StartUp\PowerReg Scheduler.exe]
Potentially unwanted tool:Application/PRScheduler Not disinfected C:\undo\backup.cab[\Device\Harddisk0\Partition1\WINDOWS\Start Menu\Programs\Disabled Startup Items\PowerReg Scheduler.exe]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\ehm720in.default\cookies.txt[.go.com/]
Adware:Adware/Transponder Not disinfected C:\Documents and Settings\Neil\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\0f829e07be8b3e8d1776749cb2b9cdc4
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.advertising.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.2o7.net/]
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.ads.addynamix.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[.www.myaffiliateprogram.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt[server.iad.liveperson.net/hc/78221172]
This looks better. I would like to know that some other scans would run. At least Panda did and previously you had problems with that. And we had results from Kapersky. Wonder if the FSecure will run.
Blacklight
Download Blacklight trial from here:
http://www.f-secure.com/blacklight/ Hit I accept . It will take you to download page. Download blbeta.exe and save it to the Desktop. Once saved… double click blbeta.exe to install the program. Click accept agreement and Click scan
This app too may fire off a warning from antivirus. Let the driver load.
Wait for it to finish. If it displays any items…don't do anything with them yet. Just hit exit (close) It will drop a log on Desktop that starts with fsbl….big number Please
post contents of log.
Please run the
F-Secure Online Scanner
Note:
This Scanner is for Internet Explorer Only! Follow the Instruction on the F-Secure page for proper installation. Accept the License Agreement. Once the ActiveX installs,Click Full System Scan Once the download completes,the scan will begin automatically. The scan will take some time to finish,so please be patient. When the scan completes, click the Automatic cleaning (recommended) button. Click the Show Report button and Copy&Paste the entire report in your next reply.
Please post the Blacklight log that stars with the fsbl….big number and the results from F-Secure.
FSBL log results
09/11/06 14:29:22 [Info]: BlackLight Engine 1.0.46 initialized
09/11/06 14:29:22 [Info]: OS: 5.1 build 2600 (Service Pack 2)
09/11/06 14:29:23 [Note]: 7019 4
09/11/06 14:29:23 [Note]: 7005 0
09/11/06 14:29:28 [Note]: 7006 0
09/11/06 14:29:28 [Note]: 7011 1524
09/11/06 14:29:29 [Note]: 7026 0
09/11/06 14:29:29 [Note]: 7026 0
09/11/06 14:29:32 [Note]: FSRAW library version 1.7.1019
F-secure gave me the same error as before, the downloaded database is corrupt.
But, its a much bigger database this time.
Hi euqruob,
Just curious. Will this one work? After that infection you had, I would just like to see a few scans complete. Then if this one works, maybe we can start wrapping this up.
http://housecall.trendmicro.com/
That one won't either, I can't get java to install.
I've uninstalled and reinstalled via the web and manually and I can't get Java to install
Which sucks, because I'd like to have it running.
That did the trick, its installed, I'm happy for that.
I'm doing the housecall trend micro scan now
It ran for about a half hour, then closed, shut down the window and everything.
Frustrating.
I tried it again, same deal.
http://be.trendmicro-europe.com/consumer/h…call_launch.php
This is housecall in Europe. It is different. Let's see if it will run.
Same result, it ran for about 45 minutes then shut itself down.
I am so sorry. What about Bit Defender?
http://www.bitdefender.com/scan8/ie.html
I am going to consult with others.
So far so good, I am going to be out of town from tomorrow afternoon till Tuesday morning, so if you don't hear from me for a while, you know why
Bit defender ran, here are the results
BitDefender Online Scanner
Scan report generated at: Tue, Sep 12, 2006 - 15:30:59
Scan path: C:\;D:\;E:\;F:\;
Statistics
Time
03:25:36
Files
1626224
Folders
22579
Boot Sectors
4
Archives
27991
Packed Files
110775
Results
Identified Viruses
5
Infected Files
63
Suspect Files
0
Warnings
0
Disinfected
45
Deleted Files
16
Engines Info
Virus Definitions
453879
Engine build
AVCORE v1.0 (build 2310) (i386) (Apr 17 2006 16:24:38)
Scan plugins
13
Archive plugins
38
Unpack plugins
6
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_08.b03\zipper.exe
Infected with: Win32.Virtob.C
C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_08.b03\zipper.exe
Disinfected
C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_08.b03\launcher.exe
Infected with: Win32.Virtob.C
C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_08.b03\launcher.exe
Disinfected
C:\Program Files\Mozilla Firefox\updater.exe
Infected with: Win32.Virtob.C
C:\Program Files\Mozilla Firefox\updater.exe
Disinfected
C:\Program Files\Mozilla Firefox\xpicleanup.exe
Infected with: Win32.Virtob.C
C:\Program Files\Mozilla Firefox\xpicleanup.exe
Disinfected
C:\Program Files\Mozilla Firefox\extensions\[removed]\components\talkback.exe
Infected with: Win32.Virtob.C
C:\Program Files\Mozilla Firefox\extensions\[removed]\components\talkback.exe
Disinfected
C:\Program Files\Mozilla Firefox\uninstall\uninstall.exe
Infected with: Win32.Virtob.C
C:\Program Files\Mozilla Firefox\uninstall\uninstall.exe
Disinfected
C:\Program Files\Mozilla Firefox\firefox.exe
Infected with: Win32.Virtob.C
C:\Program Files\Mozilla Firefox\firefox.exe
Disinfection failed
C:\Program Files\Mozilla Firefox\firefox.exe
Delete failed
C:\Program Files\Magellan\MapSend DirectRoute NA\MapSend.exe
Infected with: Win32.Virtob.C
C:\Program Files\Magellan\MapSend DirectRoute NA\MapSend.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\java.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\java.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\javacpl.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\javacpl.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\javaw.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\javaw.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\javaws.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\javaws.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\jucheck.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\jucheck.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\keytool.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\keytool.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\kinit.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\kinit.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\klist.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\klist.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\ktab.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\ktab.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\orbd.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\orbd.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\pack200.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\pack200.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\policytool.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\policytool.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\rmid.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\rmid.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\rmiregistry.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\rmiregistry.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\servertool.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\servertool.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\tnameserv.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\tnameserv.exe
Disinfected
C:\Program Files\Java\jre1.5.0_08\bin\unpack200.exe
Infected with: Win32.Virtob.C
C:\Program Files\Java\jre1.5.0_08\bin\unpack200.exe
Disinfected
C:\Downloads\ATF-Cleaner.exe
Infected with: Win32.Virtob.C
C:\Downloads\ATF-Cleaner.exe
Disinfected
C:\WINDOWS\system32\WISPTIS.EXE
Infected with: Win32.Virtob.C
C:\WINDOWS\system32\WISPTIS.EXE
Disinfection failed
C:\WINDOWS\system32\WISPTIS.EXE
Delete failed
C:\WINDOWS\system32\java.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\system32\java.exe
Disinfected
C:\WINDOWS\system32\javaw.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\system32\javaw.exe
Disinfected
C:\WINDOWS\system32\javaws.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\system32\javaws.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
Disinfected
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
Infected with: Win32.Virtob.C
C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
Disinfected
C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\OnlineScanner\Anti-Virus\fsgk32.exe
Infected with: Win32.Virtob.C
C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\OnlineScanner\Anti-Virus\fsgk32.exe
Disinfected
C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\OnlineScanner\Anti-Virus\fssm32.exe
Infected with: Win32.Virtob.C
C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\OnlineScanner\Anti-Virus\fssm32.exe
Disinfected
C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\mexe.com
Infected with: BehavesLike:Win32.FileInfector
C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\mexe.com
Disinfection failed
C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\mexe.com
Deleted
C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\mwavscan.com
Infected with: BehavesLike:Win32.FileInfector
C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\mwavscan.com
Disinfection failed
C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\mwavscan.com
Deleted
C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)=>mexe.com
Infected with: BehavesLike:Win32.FileInfector
C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)=>mexe.com
Disinfection failed
C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)=>mexe.com
Deleted
C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)
Update failed
C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)=>mwavscan.com
Infected with: BehavesLike:Win32.FileInfector
C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)=>mwavscan.com
Disinfection failed
C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)=>mwavscan.com
Deleted
C:\Documents and Settings\Neil Bourque.NEIL.000\Desktop\mwav.exe=>(RAR Sfx o)
Update failed
C:\Documents and Settings\Neil Bourque.NEIL.000\.housecall6.6\getMac.exe
Infected with: Win32.Virtob.C
C:\Documents and Settings\Neil Bourque.NEIL.000\.housecall6.6\getMac.exe
Disinfected
C:\Documents and Settings\Neil Bourque.NEIL.000\.housecall6.6\tsc.exe
Infected with: Win32.Virtob.C
C:\Documents and Settings\Neil Bourque.NEIL.000\.housecall6.6\tsc.exe
Disinfected
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010306.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Downloader.VB.TX
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010306.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010306.exe=>(NSIS o)=>lzma_nsis0001
Deleted
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010306.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Downloader.VB.TX
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe=>(NSIS o)=>lzma_nsis0001
Deleted
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011278.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Downloader.VB.TX
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011278.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011278.exe=>(NSIS o)=>lzma_nsis0001
Deleted
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011278.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011289.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Downloader.VB.TX
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011289.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011289.exe=>(NSIS o)=>lzma_nsis0001
Deleted
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011289.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011846.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Downloader.VB.TX
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011846.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011846.exe=>(NSIS o)=>lzma_nsis0001
Deleted
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011846.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Downloader.VB.TX
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe=>(NSIS o)=>lzma_nsis0001
Deleted
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025232.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Downloader.VB.TX
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025232.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025232.exe=>(NSIS o)=>lzma_nsis0001
Deleted
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025232.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025246.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Downloader.VB.TX
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025246.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025246.exe=>(NSIS o)=>lzma_nsis0001
Deleted
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025246.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)=>drxvp.exe
Infected with: GenPack:Trojan.DollarRevenue.B
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)=>drxvp.exe
Disinfection failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)=>drxvp.exe
Deleted
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)=>pnky.exe
Infected with: Trojan.Vundo.K
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)=>pnky.exe
Disinfection failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)=>pnky.exe
Deleted
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032001.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Downloader.VB.TX
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032001.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032001.exe=>(NSIS o)=>lzma_nsis0001
Deleted
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032001.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032008.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Downloader.VB.TX
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032008.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032008.exe=>(NSIS o)=>lzma_nsis0001
Deleted
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032008.exe=>(NSIS o)
Update failed
Hi euqruob,
Thanks for the log. I noticed that two files could not be cleaned and deleted. I will get back to you but at least the other files were disenfected or deleted.