Hello euqruob,
Were you using firefox when you did the Bit Defender scan?
Please zip the following files:
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\WISPTIS.EXE
Please upload the zipped files to
here
Or email it
here
STEP 1.
======
Delete Files with Killbox
Download Pocket Killbox from http://www.downloads.subratam.org/KillBox.zip and unzip it; save it to your Desktop.
DO NOT RUN IT YET .
==========
Double-click on KillBox.exe to launch the program. It is the
red circle with a large white X in it
- Highlight the files in bold
RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\WISPTIS.EXE
In Killbox click on the
File menu and then the
Paste from Clipboard item
in the
Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.) Click the option to Delete on Reboot Click End Explorer Shell while Killing File Click All Files right of the flashing green "Single files" Click Yes when it asks "Files will be Removed on Reboot, Do you want to reboot now?" (Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)
If you have any issues with this method you can copy and paste the lines
one at a time into the killbox top box. Then click the "
Single File " button. Then click the Red
X …and for the confirmation message that will appear, you will need to click
Yes . A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.
Then please run the Bit Defender scan again and let's see the results.
I did the deletes, and am running bit defender, but I will have to catch a flight.
I'll pick this back up next week
thanks for the help so far!
You are welcome. I will look for your reply.
Hi euqruob,
I received information about the two files that you sent. Both files were not infected and therefore considered having "false positives". We both know that your system was infected but I have learned that "false positives" may occur with this infection which is a file infector worm.
I want you do uninstall Firefox and Java. Go to Add/Remove programs and uninstall all versions of Java (look for coffee cup icon) and Mozilla Firefox.
Delete the following:
C:\Program Files\Java <=folder
C:\Program Files\Mozilla Firefox <=folder
Now let's reset your restore points.
Click Start Menu > All Programs > Accessories > System Tools > SystemRestore
Press OK . Choose 'Create a Restore Point ' then Next . Name it and press 'Create ' then when the confirmation screen shows the restore point has been created click 'Close '
Next go to Start Menu > Run > type
cleanmgr
click OK, when Disk Cleanup opens goto the 'More Options ' tab and press 'Cleanup ' on the system restore area which will remove all the restore points except the one we just created. To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.
Now we need to run an anti-virus scan but not an online scan. Run your AVG and please in safe mode and please report what it finds.
My avg is not installed, the virus never allowed an installation, should I try to re-install it?
I tried to install AVG again, no go.
I'm gonna do the internet scan tonite and leave it on while I sleep, get us a good view of where we are at.
Do you still have the MWAV by any chance. I hate for you to be connected to the Internet. If you could download the MWAV again and run it, that would be better. Although you may receive pop-ups about being infected and have to close the window, so I do not know if you would want to do this during the night.
STEP 1.
======
MWAV Scan
Please download
MWAV to a convenient location.
This scan only produces a report, it doesn't clean your system. I will analyze the report and recommend a course of action depending on the results.
This scan might take around 3+ hours to finish when set to scan everything.
Double-click on
mwav.exe .
Put a check next to the below items before scanning:
Memory Startup Folders Drive - All Local Drives Folder - then click "browse" to change the directory to C: (default is C:\Windows) Registry System Folders Services Include Sub-Directory Scan All Files
Please make sure
ALL of these are checked, then press the
Scan button. This typically will take hours to complete.
**NOTE*** Sometimes MWav will pause and it appears to be finished, but it isn't done. Just let it run until it says it's complete.
On the bottom portion of the window, you will see the lower panel where MWav is listing "infected items", please highlight
everything in that lower panel and copy them by holding CTRL + C then paste it here. The whole log will be extremely BIG so there is no way to post the log. I just need the infected items list.
File C:\WINDOWS\system32\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ctfmon.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ctfmon.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPShell.HWEventHandler" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.
Entry "HKCR\WMPShell.HWEventHandler.1" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\pxwma.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\WISPTIS.EXE". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\CH Gameport Devices" refers to invalid object "C:\Program Files\CH Products\Gameport Devices\CH Gameport Devices". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe" refers to invalid object "C:\WINDOWS\System32\cmmgr32.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\CTCplFW.exe" refers to invalid object "C:\Program Files\Creative\SBAudigy\Diagnostics\CTCplFW.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\minstall.exe" refers to invalid object "". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Adobe\Acrobat 6.0\TempIccProfiles\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Adobe\Acrobat 6.0\TempIccProfiles\Non-Recommended\". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".mpga". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".part". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rgn". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object "OpenWithList". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{FFB59000-EB47-45BC-842A-EFFBDA635C94}". Action Taken: No Action Taken.
File C:\WINDOWS\system32\ctfmon.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\Download.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\esupdate.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\Getvlist.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\kavsign.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\MWAVL.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\MWAVReg.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\setpriv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\unregx.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\viewtcp.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\NEILBO~1.000\LOCALS~1\Temp\nstmp\uninstall.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\WinZip\WZQKPICK.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\SIERRA\Half-Life\hltv.exe tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken.
File C:\WINDOWS\system32\ctfmon.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\$hf_mig$\KB896423\update\arpidfix.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\update\arpidfix.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2qfe\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2gdr\spoolsv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Download.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\esupdate.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Getvlist.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\kavsign.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\MWAVL.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\MWAVReg.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\setpriv.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\unregx.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\viewtcp.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\nstmp\uninstall.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0010093.exe tagged as "not-a-virus:AdWare.Win32.Agent.y". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010306.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010313.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010330.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010635.exe tagged as "not-a-virus:AdWare.Win32.SurfSide.ay". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011278.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011285.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011289.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011303.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011716.exe tagged as "not-a-virus:AdWare.Win32.SurfSide.ay". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011781.exe tagged as "not-a-virus:AdWare.Win32.Agent.y". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011846.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011853.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011870.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012185.exe tagged as "not-a-virus:AdWare.Win32.SurfSide.ay". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012868.EXE tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0013406.EXE tagged as "not-a-virus:AdWare.Win32.CommAd.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014153.exe tagged as not-a-virus:RiskTool.Win32.Reboot.f. No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0015327.EXE tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016110.EXE tagged as "not-a-virus:AdWare.Win32.CommAd.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016825.exe tagged as not-a-virus:RiskTool.Win32.Reboot.f. No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0024207.EXE tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025020.EXE tagged as "not-a-virus:AdWare.Win32.SurfSide.ay". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025232.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025237.EXE tagged as "not-a-virus:AdWare.Win32.CommAd.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025241.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025246.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025259.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025334.0XE infected by "Trojan-Downloader.Win32.Dyfuca.fb" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025349.EXE tagged as "not-a-virus:AdWare.Win32.ZenoSearch.o". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025400.exe tagged as not-a-virus:RiskTool.Win32.Reboot.f. No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE tagged as "not-a-virus:AdWare.Win32.Virtumonde.dr". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025429.0XE infected by "Trojan-Dropper.Win32.Small.qn" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025784.dll tagged as "not-a-virus:AdWare.Win32.CASClient.n". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025785.dll tagged as "not-a-virus:AdWare.Win32.CASClient.n". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025786.exe tagged as "not-a-virus:AdWare.Win32.WebHancer". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025792.dll tagged as "not-a-virus:AdWare.Win32.Mirar.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025794.0CX infected by "Trojan-Dropper.Win32.VB.dq" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032001.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032006.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032008.exe infected by "Trojan.Win32.VB.tg" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032011.exe tagged as "not-a-virus:AdWare.Win32.PurityScan.es". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032316.exe tagged as "not-a-virus:AdWare.Win32.SurfSide.ay". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032785.EXE tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0033005.EXE tagged as "not-a-virus:AdWare.Win32.CommAd.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0033291.exe tagged as not-a-virus:RiskTool.Win32.Reboot.f. No Action Taken.
File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP2\A0001184.EXE tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken.
File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP2\A0001624.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP3\A0002561.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP7\A0003268.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP7\A0004128.EXE tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken.
File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP7\A0004367.exe infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP7\A0004376.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{650427B5-CE35-4646-96DD-620550237E51}\RP7\A0004378.EXE infected by "Virus.Win32.Virut.a" Virus! Action Taken: No Action Taken.
Hi euqruob,
Turn off system restore then run housecall.
1. Turn off System Restore. On the Desktop, right-click My Computer.
2. Click Properties.
3. Click the System Restore tab.
4. Check Turn off System Restore.
5. Click Apply, and then click OK.
http://housecall.trendmicro.com/
Please let me know what housecall results are.
same old stuff, it got halfway through and it suddenly turned off the browser.
This happened before.
I've managed to get the Panda Active Scan running (about 3/4th done), its disinfected 69 of 74 virus so far, and found 1374 spyware (I ran spybot and ad aware today), but its not disinfecting that, or the 12 hacking tools.
Is it worth shelling out the 13 dollars for their disinfection service?
Pandasoft report
(I'm not showing the adware and spyware stuff as its much too long)
Incident Status Location
Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0.b64\patchjre.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0.b64\zipper.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0.b64\launcher.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_06.b05\zipper.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_06.b05\launcher.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\WinZip\WZQKPICK.EXE
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\java.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\javacpl.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\javaw.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\javaws.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\jusched.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\keytool.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\kinit.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\klist.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\ktab.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\orbd.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\pack200.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\policytool.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\rmid.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\rmiregistry.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\servertool.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\tnameserv.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\unpack200.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\jusched.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\java.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\javacpl.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\javaw.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\javaws.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\keytool.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\kinit.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\klist.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\ktab.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\orbd.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\pack200.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\policytool.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\rmid.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\rmiregistry.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\servertool.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\tnameserv.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\unpack200.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\ctfmon.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\ActiveScan\pavdr.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\asuninst.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\spoolsv.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\$hf_mig$\KB896423\update\arpidfix.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\update\arpidfix.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2qfe\spoolsv.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2gdr\spoolsv.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected C:\undo\backup.cab[\Device\Harddisk0\Partition1\WINDOWS\Start Menu\Programs\StartUp\PowerReg Scheduler.exe]
Potentially unwanted tool:Application/PRScheduler Not disinfected C:\undo\backup.cab[\Device\Harddisk0\Partition1\WINDOWS\Start Menu\Programs\Disabled Startup Items\PowerReg Scheduler.exe]
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\kavss.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Download.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\esupdate.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Getvlist.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\kavsign.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\MWAVL.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\MWAVReg.EXE
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\setpriv.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\unregx.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\viewtcp.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\nstmp\uninstall.exe
Virus:Trj/PayClicker.EC Disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010315.exe
Adware:Adware/DigInk Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe
Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010318.exe[²íÇ]
Virus:Trj/PayClicker.EC Disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011287.exe
Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011290.exe[²íÇ]
Virus:Trj/PayClicker.EC Disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011855.exe
Adware:Adware/DigInk Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe
Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011858.exe[²íÇ]
Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014152.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016824.exe
Virus:Trj/PayClicker.EC Disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025243.exe
Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025247.exe[²íÇ]
Spyware:Spyware/7r7t Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025259.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025399.exe
Virus:Trj/PayClicker.EC Disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032007.exe
Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032009.exe[²íÇ]
Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0033290.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected D:\Documents and Settings\All Users\Start Menu\Programs\Startup\PowerReg Scheduler.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected D:\Documents and Settings\All Users\Start Menu\Programs\Disabled Startup Items\PowerReg Scheduler.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected D:\Documents and Settings\Neil Bourque.NEIL\Start Menu\Programs\Startup\PowerReg Scheduler.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025470.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025471.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025522.exe
Hi euqruob,
I am obtaining assistance with your log. Please be sure to Turn Off your system restore.
STEP 1.
======
We need to TURN OFF your System Restore.
Turn off System Restore. On the Desktop, right-click My Computer. Click Properties . Click the System Restore tab. Check Turn off System Restore . Click Apply , and then click OK .
Please download
ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button. If you use Firefox browser Click Firefox at the top and choose:Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. If you use Opera browser Click Opera at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. Click
Exit on the Main menu to close the program.
For
Technical Support , double-click the e-mail address located at the bottom of each menu.
Run Panda and post the results please.
I'll post the whole panda log, but, only the virus materials
Incident Status Location
Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0.b64\patchjre.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0.b64\zipper.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0.b64\launcher.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_06.b05\zipper.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_06.b05\launcher.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\WinZip\WZQKPICK.EXE
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\java.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\javacpl.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\javaw.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\javaws.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\keytool.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\kinit.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\klist.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\ktab.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\orbd.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\pack200.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\policytool.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\rmid.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\rmiregistry.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\servertool.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\tnameserv.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\unpack200.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0\bin\jusched.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\java.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\javacpl.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\javaw.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\javaws.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\keytool.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\kinit.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\klist.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\ktab.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\orbd.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\pack200.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\policytool.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\rmid.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\rmiregistry.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\servertool.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\tnameserv.exe
Virus:W32/Virutas.B Disinfected C:\Program Files\Java\jre1.5.0_06\bin\unpack200.exe
Virus:W32/Virutas.B Disinfected C:\Downloads\ATF-Cleaner.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\ActiveScan\pavdr.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\asuninst.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\$hf_mig$\KB896423\update\arpidfix.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\update\arpidfix.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2qfe\spoolsv.exe
Virus:W32/Virutas.B Disinfected C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2gdr\spoolsv.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected C:\undo\backup.cab[\Device\Harddisk0\Partition1\WINDOWS\Start Menu\Programs\StartUp\PowerReg Scheduler.exe]
Potentially unwanted tool:Application/PRScheduler Not disinfected C:\undo\backup.cab[\Device\Harddisk0\Partition1\WINDOWS\Start Menu\Programs\Disabled Startup Items\PowerReg Scheduler.exe]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Neil\Application Data\Mozilla\Firefox\Profiles\ehm720in.default\cookies.txt[.go.com/]
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Temporary Internet Files\Content.IE5\KT2RCPQF\ATF-Cleaner[1].exe
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@doubleclick[1].txt
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Download.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\esupdate.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Getvlist.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\kavsign.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\MWAVL.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\MWAVReg.EXE
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\setpriv.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\unregx.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\viewtcp.exe
Virus:W32/Virutas.B Disinfected C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\nstmp\uninstall.exe
Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011290.exe[²íÇ]
Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011858.exe[²íÇ]
Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014152.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016824.exe
Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025247.exe[²íÇ]
Virus:Trj/PayClicker.EC Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032009.exe[²íÇ]
Potentially unwanted tool:Application/Processor Not disinfected C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0033290.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected D:\Documents and Settings\All Users\Start Menu\Programs\Startup\PowerReg Scheduler.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected D:\Documents and Settings\All Users\Start Menu\Programs\Disabled Startup Items\PowerReg Scheduler.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected D:\Documents and Settings\Neil Bourque.NEIL\Start Menu\Programs\Startup\PowerReg Scheduler.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025470.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025471.exe
Adware:Adware/WurldMedia Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025502.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected D:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025522.exe