This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] W32.Trats!inf virus removal

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Trevuren,

Here is a new HJT log. I used the link you sent me several days ago to run it…hope that was ok.

Wcosgroj

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:53, on 2008-02-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/ig
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {245DB4E4-0CB1-4EAE-BB59-1D21930920C6} - C:\WINDOWS\system32\jkhfe.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: {471eb341-2be6-e538-29c4-a8997aacbc8d} - {d8cbcaa7-998a-4c92-835e-6eb2143be174} - C:\WINDOWS\system32\jemxwtdj.dll (file missing)
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [winNT updatc] wupgrd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
O4 - HKLM\..\Run: [300c136d] rundll32.exe "C:\WINDOWS\system32\wcvlxhhb.dll",b
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BM333f20f1] Rundll32.exe "C:\WINDOWS\system32\fxmpfxhq.dll",s
O4 - HKLM\..\RunServices: [winNT updatc] wupgrd.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} (LEAD Main Control (14.0)) - http://www.daviencrod.org/controls/LTOCX14N.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1115175111734
O16 - DPF: {9841D1AE-9C0B-11D3-9452-00105A098C21} (Pegasus PrintPRO Control v2.0) - http://www.daviencrod.org/controls/prntpro2.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 7336 bytes
Trevuren, I took the OS disc out, shut down, and restarted. Everything came back. So far I see no trace of the problem. I see my Symantec icon in the startup bar is not there..should I do anything about that yet? I am going to be gone for about 3 hrs. I will shut down for now. I'll check back later. Thanks, wcosgroj
I am currently getting an error message from the link to where you posted the grab zip. If you can not get through right away, please try and try again. We can not proceed without the analysis of those files. Make sure that he knows from what topic each one of them comes, even if you have to add a Notepad file which included the url and Forum of the topic into each zipped file.


A. After talking with the Expert, he needs for you to submit the following files INDIVIDUALLY and ZIPPED:

C:\WINDOWS\system32\config\system.bak

and

B. C:\WINDOWS\system32\config\software.bak


In the mean time, we need the following report:


Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan

C. I would suggest that you start to backup all important data in case we run into major problems. Do not back up any .exe files or screensaver files
Trevuren, Here is the Kaspersky scan record: —————————————————————————– KASPERSKY ONLINE SCANNER REPORT 2008-02-25 22:22 Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 26/02/2008 Kaspersky Anti-Virus database records: 581105 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ Scan Statistics: Total number of scanned objects: 66109 Number of viruses found: 4 Number of infected objects: 97 Number of suspicious objects: 0 Duration of the scan process: 01:02:37 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\00b7fd653ffe34d2c1230a523b90614a_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\06829a974f29634987c1ff8976cca353_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0899bd9bdd3a264997310b2d4537db2f_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\158dc1fd2ab55011f2d1f241eac4578d_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\16251978d974b2067f4017bc8efb5d32_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1818829465f4d47a34229f154380c9dc_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\20d754af1fa299b8c49750e05daf48f4_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\22486206ff0b4f5bb1752a064371316c_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\22abf18b6de84b573ac9df0166a33ff6_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2603633b967222af19cde2822e857f94_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\27fc4c0d05c12cb14591f80cc20a9a32_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2d396efb99df15dfd6e196b1f2b71916_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3076eb63e5f7e8dbf08f1f7ab39f2693_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\32f492be76e7aaf6902e630a223171f5_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\34217c30567755a8e9aa37611fb77ce0_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\35d7074d8db30b9db08c326f48edae16_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3933410f8b02070fccf4b3167f9c4f46_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3b4972c91a1c1e141217e324ffc44f5b_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\48a98cd310358b0eb8e6b5374c8c64fb_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4b862ff08873b114d25d5d5de518e73d_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4d2cf02ae00ebe8e3aba4ad8e1ce512c_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55622f8573215e962782c9513a7b5316_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5761a1ae2ab458b84d6896d0c75ccd10_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a25e5200aeecfd3b6bf92cc0df7eae4_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\65244413fcebd2df7e3da0dfddf05748_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\662158b534601109e6dec4092259952d_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\68a602211f24e634fc9a416cb0d1b171_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\71194a213f8f4cb36d2bc2dab9ed1120_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\732fe23b1a2716699185a5aef3d470f6_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a460f65d40a0e4417c82b60d4a67f81_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b6705b4896991cb9807b9b8710d2d67_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\814480185781216e1e006642c2ac78de_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\82894517ad33263743d69bd6a8ac8a2d_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8ba66b79f9af48159d26452122b31a68_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8cd392f6fe9d32129b35f999ebc430c2_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\944352c41f2a611320386aeda1a9ecf9_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\949879947ba92539e58f6c54e13d2e4b_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9844e38d7963f3fc0be7041a2c1de21e_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\98b8d3d9255658300f5276efdc63d9c5_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c987d65ee4256f3f0fc2cd73421d3e0_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1d7211ab39b6f3616d51147a660971e_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\afd434031435fff2d613966d20eb5c00_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b511fb2698a52a748154a938fade8469_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b7381a51a140e006b60bcbb790580ed9_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b7dcce183fba0e001c81211096684995_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b7ee675b6e80153fb1695f1328d8814b_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c51319ca4f5341fa73c703a4b5a4d72f_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c70f16bfc3e7213cb14795b52d66bc72_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dcb4065ac73e264327b6e12b747f4008_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dfeb553256dbc363cef6af181dca5d9f_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e08725368af8ce48ff20210c62867111_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e6322577bc88d3acd806eefcaa8e6830_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e6912f0099f581056f1861e1d0556d6c_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e74bf309e68eac87f92abd48e57b989b_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea4cd2ecb0918681bb4844379dd36f88_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eaea866dd6b9598880801829eaf18a4a_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f1a80680e1f7f9d4b04888b57220ee53_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fcefd29146da757cf5270970e7764f21_accad57d-b423-4bc7-aea1-32ad231c04c1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-02202008-104804.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01B40000.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01B40001\47B75E4F.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600000\47FC475B.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600001\47FC4786.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600002\47FC4795.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600003\47FC4B3D.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600004\47FC4B63.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600005\47FC4B71.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05D40000\47FCBAAC.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05D40001\47FCBAE7.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05D40004\47FCBC81.VBN Infected: not-virus:Hoax.Win32.Renos.aun skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05D40005\47FCBC8E.VBN Infected: not-virus:Hoax.Win32.Renos.aun skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05D40006\47FCC39C.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05D40007\47FCC3C1.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05D40008\47FCC3CE.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05D40009\47FCD1D3.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05D4000A\47FCD1FC.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05D4000B\47FCD209.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BE80000.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BE80001\4FFE2A43.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BE80002\4FFE2A7E.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BE80003\4FFE2A8A.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C240000.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C240001.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C240002\4FB64FA2.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C540000.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C540001\4FFC4ACD.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C540002\4FFC4AF4.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C540003\4FFC4B01.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C540004\4FFC4C18.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C540005\4FFC4C3C.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C540006\4FFC4C49.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C540007\4FFC4E08.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C540008\4FFC4E2E.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C540009\4FFC4E3B.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C54000A\4FFC4F46.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C54000B\4FFC4F6D.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C54000C\4FFC4F7C.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C54000D\4FFC4FEF.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C54000E\4FFC5013.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C54000F\4FFC5020.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C540010\4FFC543C.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600000.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600001\4FF9E8F4.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600002\4FF9E907.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600003\4FF9E988.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600004\4FF9E9AD.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600005\4FF9E9BB.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600006\4FF9EE21.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600007\4FF9EE46.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600008\4FF9EE52.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600009\4FF9F1CA.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C60000A\4FF9F491.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C60000B\4FF9F4B5.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C60000C\4FF9F4C1.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C60000D\4FFA00A4.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C60000E\4FFA00C8.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C60000F\4FFA00D5.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600010.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C8C0000.VBN Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\mom\Cookies\index.dat Object is locked skipped C:\Documents and Settings\mom\Desktop\catchme.zip/jkhfe.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\Documents and Settings\mom\Desktop\catchme.zip ZIP: infected - 1 skipped C:\Documents and Settings\mom\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\mom\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\mom\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\mom\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\mom\NTUSER.DAT Object is locked skipped C:\Documents and Settings\mom\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0716NAV~.TMP Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0942NAV~.TMP Object is locked skipped C:\QooBox\Quarantine\C\Program Files\Common Files\Yazzle1552OinUninstaller.exe.vir/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped C:\QooBox\Quarantine\C\Program Files\Common Files\Yazzle1552OinUninstaller.exe.vir NSIS: infected - 1 skipped C:\QooBox\Quarantine\C\WINDOWS\system32\bndqnaws.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\daniaaxx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ehvpibbf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ftihbmdl.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\fxmpfxhq.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ineefbpf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\jemxwtdj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\jhnpigbg.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\lmwgrdbq.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\nlaadlbo.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\qiuqjvsx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ujyteqng.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\wcvlxhhb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\xiwixniu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\xkhdlopk.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000028.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000028.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000030.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000031.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000032.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000033.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000034.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000035.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000036.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000037.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000038.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000039.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000040.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000041.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000042.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000043.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000044.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP3\A0000079.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{53A5E5E2-E960-4A34-8A95-587152F69667}\RP4\change.log Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. For the other instructions, I'm not clear how to do the zipping and sending of those two items. Can you bring it down to my (novice/non-tekkie) level please? I am going to bed now…I'll check back in the AM. Thanks, wcosgroj
1. Do you know how to use a Zip tool? 2. Do you use a 3rd Party Zip program like WinZip or 7 Zip or do you use the universal one that comes with your operating system?
Here we go… I'll ask you to try it this way…. I spent part of the night writing down these instructions:


A. Please print out or copy this page to Notepad. It should make my instructions a bit easier to follow

There are different ways of sending and storing files and one of them is called in ZIP format. This is a file compression format. This system is used for many reasons none of which I will get into now. But to open this type of file you need a special program. Many exist on the market but one of the most popular is called WinZip.


Downloading the program

Here is the link to obtain a trial version of this program: WinZip Evaluation
  • Accept the suggested download site
  • Enter an email address
  • Click on "Download Evaluation"
  • This will bring you to the CNet site where you have to click on "Download Now"
  • Make sure that you download WinZip to your Desktop for easy retrieval

WinZip is downloaded as an executable file so you just have to click on it to start the installation process. Install it to the recommended folder (Usually C:\Program Files\System Security Suite) and make sure that you have a link to it on your desktop so you can easily find it again.


B. Zipping a file

1. We have to make all files visible:

To enable the viewing of Hidden files follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and shutdown My Computer.
10. Now your computer is configured to show all hidden files.


2. Next, using Windows Explorer (Windows Key + E), locate the following file:


C:\WINDOWS\system32\config\software.bak


3. Right Click on the file and in the Context Menu that pops up, look for the WinZip symbol which you left click to bring up another context menu. Here, choose "Add Zip to File". This will open another window where you only have to click on "ADD". This will then close this mini windows and leave you with a WinZip window containing the name of the file that you just chose.

4. From the WinZip window toolbar, choose File>>Manage Archive>>Move and select your Desktop as the location.

5. Look now for the zip file on your desktop and rename the file to 2008_02_25-1.zip


C. Now do exactly the same thing with the following file:

C:\WINDOWS\system32\config\system.bak

Make sure that it is on your desktop and rename the file to this: 2008_02_25-2.zip



D. File submission

Copy the url to this topic to Notepad so you can retrieve it easily.

Now we need to submit both of these files, one at a time, to the developer of the tool at the drop of station at Bleeping Computers.
  • Click on the following link which will bring you to the site where the file has to be dropped off: http://www.bleepingcomputer.com/submit-malware.php?channel=4
  • This will take you to a page where you will be required to do the following:
  • In the "Link to Topic where file is found box", copy the link that you copied into Notepad.
  • Click Browse: A windows Explorer-type window will open and locate the first file that you zipped up.
  • Under Comments: Write the following:
  • 1. From WTT/Trevuren/ERDNT Recovery Topic
  • 2. File 1 of 2 as requested.
  • 3. Please confirm reception of files


Now do the same with the second file but change the Comment to read " 2 of 2"


And that should do it.

Good Luck,

Trevuren
Trevuren, Thanks for everything so far…you've done a lot of work! I followed your instructions, did the first submission to Bleepin, and got a message that the file was too large—error#2. I used their "contact us" form and am waiting for a reply. Is there something else I should be doing? I did not bother to do the 2nd submission thinking the same thing would happen. wcosgroj
Just out of curiosity, please right click on both files. A context menu will popup. Choose "Properties" and tell me the size of each file in KB
Trevuren, I just thought better of my last post. I went back on the Bleepin site and tried the 2nd zip file submission…It went through! So, I tried the first submission again, and got the same error message…file too large—exceeded 3mb. I'm going to bed…I'll check in in the AM. Thanks again for everything so far. wcosgroj
I will be sending you instructions for submitting this big file via PM. Once the file has been submiited, it is crucial that you PM me the link that you will get so I can pass it on to the developer. I am off to write up the instructions now, Regards, Trevuren

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI