This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virut.A has my system tied up

159 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello euqruob,

Were you using firefox when you did the Bit Defender scan?

Please zip the following files:

C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\WISPTIS.EXE

Please upload the zipped files to here
Or email it here

STEP 1.
======
Delete Files with Killbox

Download Pocket Killbox from http://www.downloads.subratam.org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\WISPTIS.EXE


In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
  • Click the option to Delete on Reboot
  • Click End Explorer Shell while Killing File
  • Click All Files right of the flashing green "Single files"
  • Click Yes when it asks "Files will be Removed on Reboot, Do you want to reboot now?"
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X …and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.

Then please run the Bit Defender scan again and let's see the results.
I did the deletes, and am running bit defender, but I will have to catch a flight. I'll pick this back up next week thanks for the help so far!
Hi euqruob,

I received information about the two files that you sent. Both files were not infected and therefore considered having "false positives". We both know that your system was infected but I have learned that "false positives" may occur with this infection which is a file infector worm.

I want you do uninstall Firefox and Java. Go to Add/Remove programs and uninstall all versions of Java (look for coffee cup icon) and Mozilla Firefox.

Delete the following:
C:\Program Files\Java<=folder
C:\Program Files\Mozilla Firefox<=folder

Now let's reset your restore points.

Click Start Menu > All Programs > Accessories > System Tools > SystemRestore

Press OK. Choose 'Create a Restore Point' then Next. Name it and press 'Create' then when the confirmation screen shows the restore point has been created click 'Close'

Next go to Start Menu > Run > type

cleanmgr

click OK, when Disk Cleanup opens goto the 'More Options' tab and press 'Cleanup' on the system restore area which will remove all the restore points except the one we just created. To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.

Now we need to run an anti-virus scan but not an online scan. Run your AVG and please in safe mode and please report what it finds.
I tried to install AVG again, no go. I'm gonna do the internet scan tonite and leave it on while I sleep, get us a good view of where we are at.
Do you still have the MWAV by any chance. I hate for you to be connected to the Internet. If you could download the MWAV again and run it, that would be better. Although you may receive pop-ups about being infected and have to close the window, so I do not know if you would want to do this during the night.

STEP 1.
======
MWAV Scan
Please download MWAV to a convenient location.
This scan only produces a report, it doesn't clean your system. I will analyze the report and recommend a course of action depending on the results.
This scan might take around 3+ hours to finish when set to scan everything.

Double-click on mwav.exe.
Put a check next to the below items before scanning:
  • Memory
  • Startup Folders
  • Drive - All Local Drives
  • Folder - then click "browse" to change the directory to C: (default is C:\Windows)
  • Registry
  • System Folders
  • Services
  • Include Sub-Directory
  • Scan All Files
Please make sure ALL of these are checked, then press the Scan button. This typically will take hours to complete.

**NOTE*** Sometimes MWav will pause and it appears to be finished, but it isn't done. Just let it run until it says it's complete.

On the bottom portion of the window, you will see the lower panel where MWav is listing "infected items", please highlight everything in that lower panel and copy them by holding CTRL + C then paste it here. The whole log will be extremely BIG so there is no way to post the log. I just need the infected items list.
File C:\WINDOWS\system32\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\system32\ctfmon.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\system32\ctfmon.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\system32\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Entry "HKCR\WMPShell.HWEventHandler" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken. Entry "HKCR\WMPShell.HWEventHandler.1" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\pxwma.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\WISPTIS.EXE". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\CH Gameport Devices" refers to invalid object "C:\Program Files\CH Products\Gameport Devices\CH Gameport Devices". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe" refers to invalid object "C:\WINDOWS\System32\cmmgr32.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\CTCplFW.exe" refers to invalid object "C:\Program Files\Creative\SBAudigy\Diagnostics\CTCplFW.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\minstall.exe" refers to invalid object "". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Adobe\Acrobat 6.0\TempIccProfiles\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Adobe\Acrobat 6.0\TempIccProfiles\Non-Recommended\". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".mpga". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".part". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rgn". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object "OpenWithList". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{FFB59000-EB47-45BC-842A-EFFBDA635C94}". Action Taken: No Action Taken. File C:\WINDOWS\system32\ctfmon.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\system32\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\Download.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\esupdate.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\Getvlist.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\kavsign.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\MWAVL.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\MWAVReg.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\setpriv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\unregx.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\viewtcp.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\nstmp\uninstall.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\Program Files\WinZip\WZQKPICK.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\SIERRA\Half-Life\hltv.exe tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken. File C:\WINDOWS\system32\ctfmon.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\system32\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\$hf_mig$\KB896423\update\arpidfix.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\update\arpidfix.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2qfe\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2gdr\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Download.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\esupdate.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Getvlist.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\kavsign.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\MWAVL.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\MWAVReg.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\setpriv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\unregx.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\viewtcp.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\nstmp\uninstall.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0010093.exe tagged as "not-a-virus:AdWare.Win32.Agent.y". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010306.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010313.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010330.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010635.exe tagged as "not-a-virus:AdWare.Win32.SurfSide.ay". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011278.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011285.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011289.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011303.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011716.exe tagged as "not-a-virus:AdWare.Win32.SurfSide.ay". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011781.exe tagged as "not-a-virus:AdWare.Win32.Agent.y". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011846.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011853.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011870.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012185.exe tagged as "not-a-virus:AdWare.Win32.SurfSide.ay". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012868.EXE tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0013406.EXE tagged as "not-a-virus:AdWare.Win32.CommAd.a". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014153.exe tagged as not-a-virus:RiskTool.Win32.Reboot.f. No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0015327.EXE tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016110.EXE tagged as "not-a-virus:AdWare.Win32.CommAd.a". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016825.exe tagged as not-a-virus:RiskTool.Win32.Reboot.f. No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0024207.EXE tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025020.EXE tagged as "not-a-virus:AdWare.Win32.SurfSide.ay". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025232.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025237.EXE tagged as "not-a-virus:AdWare.Win32.CommAd.a". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025241.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025246.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025259.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025334.0XE infected by "Trojan-Downloader.Win32.Dyfuca.fb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025349.EXE tagged as "not-a-virus:AdWare.Win32.ZenoSearch.o". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025400.exe tagged as not-a-virus:RiskTool.Win32.Reboot.f. No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE tagged as "not-a-virus:AdWare.Win32.Virtumonde.dr". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025429.0XE infected by "Trojan-Dropper.Win32.Small.qn" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025784.dll tagged as "not-a-virus:AdWare.Win32.CASClient.n". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025785.dll tagged as "not-a-virus:AdWare.Win32.CASClient.n". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025786.exe tagged as "not-a-virus:AdWare.Win32.WebHancer". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025792.dll tagged as "not-a-virus:AdWare.Win32.Mirar.a". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025794.0CX infected by "Trojan-Dropper.Win32.VB.dq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032001.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032006.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032008.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032011.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032316.exe tagged as "not-a-virus:AdWare.Win32.SurfSide.ay". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032785.EXE tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0033005.EXE tagged as "not-a-virus:AdWare.Win32.CommAd.a". Action Taken: No Action Taken. File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0033291.exe tagged as not-a-virus:RiskTool.Win32.Reboot.f. No Action Taken. File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP2\A0001184.EXE tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken. File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP2\A0001624.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP3\A0002561.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP7\A0003268.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP7\A0004128.EXE tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken. File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP7\A0004367.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP7\A0004376.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP7\A0004378.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
Hi euqruob,

Turn off system restore then run housecall.

1. Turn off System Restore. On the Desktop, right-click My Computer.
2. Click Properties.
3. Click the System Restore tab.
4. Check Turn off System Restore.
5. Click Apply, and then click OK.


http://housecall.trendmicro.com/

Please let me know what housecall results are.
I've managed to get the Panda Active Scan running (about 3/4th done), its disinfected 69 of 74 virus so far, and found 1374 spyware (I ran spybot and ad aware today), but its not disinfecting that, or the 12 hacking tools. Is it worth shelling out the 13 dollars for their disinfection service?
Pandasoft report (I'm not showing the adware and spyware stuff as its much too long) Incident Status Location Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0.b64\patchjre.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0.b64\zipper.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0.b64\launcher.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_06.b05\zipper.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_06.b05\launcher.exe Virus:W32/Virutas.B Disinfected C:\Program Files\WinZip\WZQKPICK.EXE Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\java.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\javacpl.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\javaw.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\javaws.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\jucheck.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\jusched.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\keytool.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\kinit.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\klist.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\ktab.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\orbd.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\pack200.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\policytool.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\rmid.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\rmiregistry.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\servertool.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\tnameserv.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\unpack200.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\jusched.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\java.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\javacpl.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\javaw.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\javaws.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\keytool.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\kinit.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\klist.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\ktab.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\orbd.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\pack200.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\policytool.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\rmid.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\rmiregistry.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\servertool.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\tnameserv.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\unpack200.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\ctfmon.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\ActiveScan\pavdr.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\asuninst.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\spoolsv.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\$hf_mig$\KB896423\update\arpidfix.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\update\arpidfix.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2qfe\spoolsv.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2gdr\spoolsv.exe Potentially unwanted tool:Application/PRScheduler Not disinfected C:\undo\backup.cab[\Device\Harddisk0\Partition1\WINDOWS\Start Menu\Programs\StartUp\PowerReg Scheduler.exe] Potentially unwanted tool:Application/PRScheduler Not disinfected C:\undo\backup.cab[\Device\Harddisk0\Partition1\WINDOWS\Start Menu\Programs\Disabled Startup Items\PowerReg Scheduler.exe] Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\kavss.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Download.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\esupdate.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Getvlist.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\kavsign.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\MWAVL.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\MWAVReg.EXE Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\setpriv.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\unregx.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\viewtcp.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\nstmp\uninstall.exe Virus:Trj/PayClicker.EC Disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010315.exe Adware:Adware/DigInk Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010318.exe[²íÇ] Virus:Trj/PayClicker.EC Disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011287.exe Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011290.exe[²íÇ] Virus:Trj/PayClicker.EC Disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011855.exe Adware:Adware/DigInk Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011858.exe[²íÇ] Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014152.exe Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016824.exe Virus:Trj/PayClicker.EC Disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025243.exe Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025247.exe[²íÇ] Spyware:Spyware/7r7t Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025259.exe Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025399.exe Virus:Trj/PayClicker.EC Disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032007.exe Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032009.exe[²íÇ] Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0033290.exe Potentially unwanted tool:Application/PRScheduler Not disinfected D:\Documents and Settings\All Users\Start Menu\Programs\Startup\PowerReg Scheduler.exe Potentially unwanted tool:Application/PRScheduler Not disinfected D:\Documents and Settings\All Users\Start Menu\Programs\Disabled Startup Items\PowerReg Scheduler.exe Potentially unwanted tool:Application/PRScheduler Not disinfected D:\Documents and Settings\Neil Bourque.NEIL\Start Menu\Programs\Startup\PowerReg Scheduler.exe Potentially unwanted tool:Application/PRScheduler Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025470.exe Potentially unwanted tool:Application/PRScheduler Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025471.exe Potentially unwanted tool:Application/PRScheduler Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025522.exe
Hi euqruob,

I am obtaining assistance with your log. Please be sure to Turn Off your system restore.

STEP 1.
======
We need to TURN OFF your System Restore.
  • Turn off System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Run Panda and post the results please.
I'll post the whole panda log, but, only the virus materials Incident Status Location Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0.b64\patchjre.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0.b64\zipper.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0.b64\launcher.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_06.b05\zipper.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_06.b05\launcher.exe Virus:W32/Virutas.B Disinfected C:\Program Files\WinZip\WZQKPICK.EXE Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\java.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\javacpl.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\javaw.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\javaws.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\jucheck.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\keytool.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\kinit.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\klist.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\ktab.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\orbd.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\pack200.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\policytool.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\rmid.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\rmiregistry.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\servertool.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\tnameserv.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\unpack200.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\jusched.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\java.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\javacpl.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\javaw.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\javaws.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\keytool.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\kinit.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\klist.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\ktab.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\orbd.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\pack200.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\policytool.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\rmid.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\rmiregistry.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\servertool.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\tnameserv.exe Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\unpack200.exe Virus:W32/Virutas.B Disinfected C:\Downloads\ATF-Cleaner.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\ActiveScan\pavdr.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\asuninst.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\$hf_mig$\KB896423\update\arpidfix.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\update\arpidfix.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2qfe\spoolsv.exe Virus:W32/Virutas.B Disinfected C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2gdr\spoolsv.exe Potentially unwanted tool:Application/PRScheduler Not disinfected C:\undo\backup.cab[\Device\Harddisk0\Partition1\WINDOWS\Start Menu\Programs\StartUp\PowerReg Scheduler.exe] Potentially unwanted tool:Application/PRScheduler Not disinfected C:\undo\backup.cab[\Device\Harddisk0\Partition1\WINDOWS\Start Menu\Programs\Disabled Startup Items\PowerReg Scheduler.exe] Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\ehm720in.default\cookies.txt[.go.com/] Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Temporary Internet Files\Content.IE5\KT2RCPQF\ATF-Cleaner[1].exe Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@doubleclick[1].txt Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Download.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\esupdate.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Getvlist.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\kavsign.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\MWAVL.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\MWAVReg.EXE Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\setpriv.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\unregx.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\viewtcp.exe Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\nstmp\uninstall.exe Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011290.exe[²íÇ] Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011858.exe[²íÇ] Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014152.exe Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016824.exe Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025247.exe[²íÇ] Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032009.exe[²íÇ] Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0033290.exe Potentially unwanted tool:Application/PRScheduler Not disinfected D:\Documents and Settings\All Users\Start Menu\Programs\Startup\PowerReg Scheduler.exe Potentially unwanted tool:Application/PRScheduler Not disinfected D:\Documents and Settings\All Users\Start Menu\Programs\Disabled Startup Items\PowerReg Scheduler.exe Potentially unwanted tool:Application/PRScheduler Not disinfected D:\Documents and Settings\Neil Bourque.NEIL\Start Menu\Programs\Startup\PowerReg Scheduler.exe Potentially unwanted tool:Application/PRScheduler Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025470.exe Potentially unwanted tool:Application/PRScheduler Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025471.exe Adware:Adware/WurldMedia Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025502.exe Potentially unwanted tool:Application/PRScheduler Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025522.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI