This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help Needed Pop Ups, Winantivirus, & Software In S

53 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

9/6/07 I can't tell I'm making any progress. I hope I am conducting the scans correctly. Since Kaspersky has been giving trouble I will run as well and post results. ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Thursday, September 06, 2007 6:49:09 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.93.0 Kaspersky Anti-Virus database last update: 6/09/2007 Kaspersky Anti-Virus database records: 409664 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 100617 Number of viruses found: 9 Number of infected objects: 74 Number of suspicious objects: 0 Duration of the scan process: 02:43:37 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\BOPDATA\_Date-20070906_Time-140801937_EnterceptExceptions.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\BOPDATA\_Date-20070906_Time-140801937_EnterceptRules.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_D69R9941.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_D69R9941.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\AccessProtectionLog.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\BufferOverflowProtectionLog.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\OnAccessScanLog.txt Object is locked skipped C:\Documents and Settings\David\Cookies\INDEX.DAT Object is locked skipped C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\David\Local Settings\Application Data\SupportSoft\HelpCenter\David\state\logs\sprtcmd.log Object is locked skipped C:\Documents and Settings\David\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\David\Local Settings\History\History.IE5\MSHist012007090620070907\index.dat Object is locked skipped C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\David\NTUSER.DAT Object is locked skipped C:\Documents and Settings\David\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\System Volume Information\catalog.wci\000002.ps1 Object is locked skipped C:\System Volume Information\catalog.wci\000002.ps2 Object is locked skipped C:\System Volume Information\catalog.wci\010006.ci Object is locked skipped C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1305\A0291392.exe/file2 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1305\A0291392.exe Inno: infected - 1 skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1312\A0299613.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1312\A0299614.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1312\A0299615.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1312\A0299616.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299666.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299740.EXE/WISE0008.BIN/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299740.EXE/WISE0008.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299740.EXE WiseSFX: infected - 2 skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299740.EXE WiseSFX Dropper: infected - 2 skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299741.EXE/WISE0008.BIN/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299741.EXE/WISE0008.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299741.EXE WiseSFX: infected - 2 skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299741.EXE WiseSFX Dropper: infected - 2 skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299884.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299885.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299886.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307073.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307074.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307074.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307078.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307079.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307080.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307081.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307082.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307083.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307084.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307085.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307086.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307087.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307088.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307089.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307090.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307091.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307092.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307093.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307094.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307095.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307096.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307097.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307098.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307099.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307100.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307101.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307102.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.r skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307103.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307104.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307105.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307106.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307107.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307108.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307109.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307110.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307111.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307112.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307114.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307115.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307116.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307117.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307118.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307119.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307120.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307121.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307122.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307123.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307124.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307125.exe/Acm.dll Infected: not-a-virus:AdTool.Win32.WhenU.i skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307125.exe/Save.exe Infected: not-a-virus:AdTool.Win32.WhenU.i skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307125.exe CAB: infected - 2 skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307126.exe Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307127.exe Infected: not-a-virus:Downloader.Win32.WinFixer.x skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307139.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307140.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.r skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Internet Logs\D69R9941.ldb Object is locked skipped C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped C:\WINDOWS\ModemLog_Intel® 537EP V9x DF PCI Modem.txt Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{472CA1E8-9429-455A-864A-F345D7F28202}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat Object is locked skipped C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx Object is locked skipped C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\ZLT002b2.TMP Object is locked skipped C:\WINDOWS\Temp\ZLT002b8.TMP Object is locked skipped C:\WINDOWS\WIADEBUG.LOG Object is locked skipped C:\WINDOWS\WIASERVC.LOG Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
9/6/07

Damage Cleanup Engine (DCE) 5.3(Build 1103)
Windows XP(Build 2600: Service Pack 2)

Start time : Thu Sep 06 2007 19:51:44

Load Damage Cleanup Template (DCT) "C:\Documents and Settings\David\Desktop\Sysclean\TMRDCT.ptn" (version ) [fail]
Load Damage Cleanup Template (DCT) "C:\Documents and Settings\David\Desktop\Sysclean\tsc.ptn" (version 894) [success]

Complete time : Thu Sep 06 2007 19:52:26
Execute pattern count(2908), Virus found count(0), Virus clean count(0), Clean failed count(0)


I found this file
TSCDebug.txt
Debug Information Level=0


********************************************************************************
*************************************************************
Then the program ran the following program: It found 3 files containing viruses. WERE THEY REMOVED?
********************************************************************************
*************************************************************


/————————————————————–\
| Trend Micro System Cleaner |
| Copyright 2006, Trend Micro, Inc. |
| http://www.antivirus.com |
\————————————————————–/


2007-09-06, 19:51:42, Auto-clean mode specified.
2007-09-06, 19:51:42, Running scanner "C:\Documents and Settings\David\Desktop\Sysclean\TSC.BIN"…
2007-09-06, 19:52:56, Scanner "C:\Documents and Settings\David\Desktop\Sysclean\TSC.BIN" has finished running.
2007-09-06, 19:52:56, TSC Log:

2007-09-06, 20:59:11, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 9/6/2007 19:55:59
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 699 (223633 Patterns) (2007/09/06) (469900)
Command Line: C:\Documents and Settings\David\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\David\Desktop\Sysclean

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307074.exe [TROJ_PURITYSC.AX]
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307126.exe [TROJ_FAKEALER.X]
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307127.exe [TROJ_DLOADER.NUU]
100948 files have been read.
100948 files have been checked.
90041 files have been scanned.
116766 files have been scanned. (including files in archived)
3 files containing viruses.
Found 3 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/6/2007 20:59:11
———*———*———*———*———*———*———*———*
2007-09-06, 20:59:11, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 9/6/2007 19:55:59
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 699 (223633 Patterns) (2007/09/06) (469900)
Command Line: C:\Documents and Settings\David\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\David\Desktop\Sysclean

Success Clean [TROJ_PURITYSC.AX]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307074.exe
Success Clean [ TROJ_FAKEALER.X]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307126.exe
Success Clean [TROJ_DLOADER.NUU]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307127.exe
100948 files have been read.
100948 files have been checked.
90041 files have been scanned.
116766 files have been scanned. (including files in archived)
3 files containing viruses.
Found 3 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/6/2007 20:59:11 1 hour 3 minutes 12 seconds (3791.19 seconds) has elapsed.

———*———*———*———*———*———*———*———*
2007-09-06, 20:59:11, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 9/6/2007 19:55:59
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 699 (223633 Patterns) (2007/09/06) (469900)
Command Line: C:\Documents and Settings\David\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\David\Desktop\Sysclean

100948 files have been read.
100948 files have been checked.
90041 files have been scanned.
116766 files have been scanned. (including files in archived)
3 files containing viruses.
Found 3 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/6/2007 20:59:11 1 hour 3 minutes 12 seconds (3791.19 seconds) has elapsed.

———*———*———*———*———*———*———*———*
2007-09-06, 20:59:11, Scanner "C:\Documents and Settings\David\Desktop\Sysclean\VSCANTM.BIN" has finished running.

catcher33
Hi catcher33,

OK good news, both your scans have come back clean.

The "infections" found by both are in your System Restore files, the only way those files can re-infect you is if you do a System Restore. We'll remove them in a minute to take away that possibility.

I've known about the infected RPs since the first Kaspersky scan, but the reason we don't remove them straight away is that it would take away your restore points. If we had any problems during the cleaning of your computer it's better to have an infected RP than no RP. We always clean them out last of all when there's no longer a chance of there being any unforseen problems.

OK, little bit of cleaning up to do now.

Let's clear out the programmes we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately. Besides they're updated regularly so won't be of any use against future infections.
  • Double click OTMoveIt.exe to launch the programme.
  • Click on the CleanUp! button.
  • OTMoveIt will download a list from the Internet, if your firewall or other defensive programmes alerts you, allow it access.
  • You will be prompted to allow the clean up procedure, click Yes
  • When finished exit out of OTMoveIt
  • Now delete OTMoveIt.exe (if present).
You can delete the Sysclean folder as well, since that isn't removed by OTMoveIt's clean up procedure.

As far as I can see, your computer looks clear of infection now.

Are you still noticing any problems ?
  • If you are let me know about them.
  • If not it's time to make your computer more secure.
Below are a series of recommendations which will help you keep more secure online.

THESE STEPS ARE VERY IMPORTANT

Lets reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which we know are infected. Please note you need Administrator Access to clean the restore points.
  • Turn off System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • Check Turn off System Restore.
    • Click Apply, and then click OK.
  • Reboot.
  • Turn ON System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • UN-Check *Turn off System Restore*.
    • Click Apply, and then click OK.
  • NOTE: only do this once, NOT on a regular basis.
Update your Java.
Older versions have vulnerabilities that malware can and are using to infect systems.

Please follow these steps to remove older version Java components. This is important as it's still possible to get infected through an old install even if you're using the latest version of Java.
  • Close any programmes you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Check any item with Java Runtime Environment (JRE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer once all Java components are removed.
Download the latest version of Java Runtime Environment (JRE) 6u2, and install it to your computer.

Updating Windows and Internet Explorer
It is essential you keep your Operating System up to date with all the latest patches. The bad guys watch for the latest exploits, as soon as Microsoft brings out a patch, the bad guys will bring out an infection to exploit that vulnerability. If you don't have all the latest patches your computer is vulnerable. Please go to the windows update site and get the critical updates.

Use a "secure" browser
Install Internet Explorer 7 or an alternative browser like Firefox or Opera for more secure surfing.
Please remember that there is no such thing as a totally secure browser. Your browsing habits will be the major factor in determining just how safe you are online. If you visit, Crack/Warez sites, Porn sites, or other sites of a questionable nature, you still run a severe risk of getting infected.

The following are free programs that are designed to keep your computer clean. A brief description is included with each item, click on name to go to download site.
  • Adaware SE Personal
    Adaware is a free program. It scans for known spyware on your computer. These scans should be run at least once every two weeks. For more information, see this tutorial
  • Spybot S & D
    Spybot is a scanner like Adaware. It scans for spyware and other malicious programs. It is important to have both Adaware and Spybot on your computer because each program provides unique detection and protection measures. Spybot has preventitive tools that stop programs from even installing on your computer.
    To see how to set this up as well as more spybot features, see here
  • SpywareBlaster
    Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes "kill bits" in the registry, so that certain activex controls can't install.
    If you don't know what activex controls are, see here
  • IE Spyad
    It puts many bad webpages on your restricted zones LIST. This means that you can still view the "bad" webpages, but the webpages can't do certain things (such as use javascripts and cookies). Use IE Spyad for single account computers, and IE Spyad 2 for multi account computers.
  • Hosts file:
  • Make sure you read the instructions on how to install the hosts file, here.
    • Every version of windows has a hosts file as part of them.
    • In a very basic sense, they are used to locate webpages.
    • We can customize a hosts file so that it blocks certain webpages.
    • However, it can slow down certain computers.
  • If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    • Click the start button (at the lower left hand corner of your screen)
    • Click run
    • In the dialog box, type services.msc
    • hit enter, then locate dns client
    • Highlight it, then double-click it.
    • On the dropdown box, change the setting from automatic to manual.
    • Click ok
  • Use an Anti Virus Software - It's very important that your computer has an anti-virus software running. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
    Computer Safety On line - LIST of free Anti virus programs
  • Use a Firewall - I cannot stress enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
    See here to choose one.
  • Site Advisor This is a utility that can be downloaded and installed. It loads an icon to the taskbar of your browser (versions for IE and Firefox), indicating the trustworthiness of the site you are on. Green for safe, Red for suspicious. Click on the icon to access details that SiteAdvisor has about the site.
Obviously you have already taken care of some of the issues mentioned, but it is important that you read through them, and address any that you may have missed.

Here's links to a few articles which are well worth reading Finally

NOW is the time you can start to hit back at the people who infected you.
[external image: Posted Image]
Please take the time to go and complain - that forum has a topic for your infection which is Vundo…… (if not, post in the Is your infection not listed here? topic). Please post as a reply, you do not need to register to do so (but you can if you wish). It will also have a list of other places you can go to to register your complaint, depending on the country you are resident in. Please read the topics and complain, it is only with such complaints to goverment or government agencies that something will get done.

Gary R. You have been great! The system seems to be running faster and much better. NO Pop-ups! I did complete the following and had a few questions: Per your instriuctions "Let's clear out the programmes we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately. Besides they're updated regularly so won't be of any use against future infections. Double click OTMoveIt.exe to launch the programme. Click on the CleanUp! button. OTMoveIt will download a list from the Internet, if your firewall or other defensive programmes alerts you, allow it access. You will be prompted to allow the clean up procedure, click Yes When finished exit out of OTMoveIt Now delete OTMoveIt.exe (if present). You can delete the Sysclean folder as well, since that isn't removed by OTMoveIt's clean up procedure." 1. Do I delete all HJT application & files? 2. I have the following zipped folders & files on my desktop: VSE80iLEN, VSE80P11, backups, log, and Q3. Do I delete these folders and files? 3. I still get the runtime error message I mentions initially when I log into my account for Sonic RecordNOW. I have found the update manager and the file file "sgtray.exe". The message says to contact the support team. They no longer suport the product. On their web page I found a patch for my version (version6.5) and downloaded the patch. No help - I still get the same message. Should I delete the file sgtray.exe in the update manager? I thought I better get clarification then continue with "Lets Reset system Restore" per your instructions. Thanks again, catcher33
1. No need to delete the HJT folder if you wish to keep it for future use, but you can otherwise.

2. From what I can find, the files and folders VSE80iLEN, VSE80P11, backups, log, and Q3 seem to be connected with Virus Scan by Mc Afee, if you're not using that programme delete them.

3.The sgtray entry in HJT is not necessary for the running of Sonic Record now.

Run a scan with HJT and when finished check the following items (if found).

O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

Now close all open windows and click Fix Checked to remove them.

Don't delete the file.

Reboot your computer.

By removing the HJT entry you will prevent it loading at startup, which should remove the problem.

If it doesn't, I'm afraid you'll need to seek help within Sonic or any forums associated with their products. This is not malware related, and so is outside my area of expertise.

Hope this helps.

Gary
Gary It worked. Removing the file eliminated the runtime error. I will proceed with your earlier instructions. Thanks for all your help. I will let you know when I complete the task. catcher33
Since updating to IE ver. 7, sometimes if I open IE and close, but later reopen to visit the internet, it won't open without re-booting the computer. catcher33
I don't use IE7 and have no experience with this programme, so can't really help you with this problem, I'm fairly certain it's not Malware related.

Try going to http://www.ie-vista.com/index.html a site by Sandi Hardmeier who specialises in IE problems.

After first installing IE7 did you reboot twice before trying to use it, Sandi seems to think it is important that you do. If not, try Uninstalling IE7 http://www.ie-vista.com/kbase2.html then re-installing using the advice on this page. http://www.ie-vista.com/known_issues.html#pre-install




Also try the Internet Explore Community at Microsoft http://www.microsoft.com/windows/using/com…ie/default.mspx there are people there with a great deal of IE7 troubleshooting experience.

Either that or Uninstall IE7 http://www.ie-vista.com/kbase2.html and use another browser like Firefox.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI