Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Hello can someone check my Hijack log please [RESOLVED]


  • This topic is locked This topic is locked

#16
PK.

PK.

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Hello there , is my compute free from virtumonde and antispyware ? , i have done all the task u ask me to do.

THanks
  • 0

Advertisements


#17
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please re-open Hijackthis and click on "Do a system scan only"
Then place a check mark next to these entries below:

O4 - HKLM\..\Run: [245c77d8] rundll32.exe "C:\WINDOWS\system32\crgrttpn.dll",b
O4 - HKCU\..\Run: [Mp3 grey] C:\DOCUME~1\Owner\APPLIC~1\SOFTWA~1\DateAimBook.exe
O4 - HKCU\..\Run: [warez] "C:\Program Files\Warez P2P Client\warez.exe" -h



Now click on Fix Checked and then close Hijackthis.
==================================
Please do an online scan with Kaspersky WebScanner
(This scanner is for use with internet explorer only)
Click on "Accept"

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

  • 0

#18
PK.

PK.

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Scan Statistics
Total number of scanned objects 114561
Number of viruses found 26
Number of infected objects 129
Number of suspicious objects 0
Duration of the scan process 02:39:45

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-02-19_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped

C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\0OMA8LNC\calc[2] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\0OMA8LNC\scnd[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Owner\ntuser.dat Object is locked skipped

C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2008-02-19.08-37-55.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped

C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped

C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped

C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped

C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\01E41F8B.exe Infected: Trojan-Spy.Win32.Banker.alr skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\024A1593.exe Infected: Trojan-Spy.Win32.Banker.alr skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\02DA21BB.tmp Infected: Trojan.Java.ClassLoader.d skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\053176A9.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\05863A4C.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\05A00A2F.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\0AB24F8B.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\12633514.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\24C97068.exe Infected: Trojan-Spy.Win32.Banker.alr skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\24ED3E40.exe Infected: Trojan-Spy.Win32.Banker.alr skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\250A3820.exe Infected: Trojan-Spy.Win32.Banker.alr skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\263A161A.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2CC501C4.exe Infected: Trojan-Downloader.Win32.Small.on skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\311E29F0.exe Infected: Trojan-Spy.Win32.Banker.alr skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\340520D7.exe Infected: P2P-Worm.Win32.Krepper.c skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\35B30713.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\43285721.exe Infected: Trojan-Downloader.Win32.Small.on skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\483E21ED.exe Infected: Trojan-Spy.Win32.Banker.alr skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4F09399F.exe Infected: Trojan-Spy.Win32.Banker.alr skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\50494C3F.exe Infected: Trojan-Spy.Win32.Banker.alr skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\50567431.exe Infected: Trojan-Spy.Win32.Banker.alr skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5107242E.tmp Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\552373A8.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\55546972.tmp Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\58497631.tmp Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5E991EEF.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5E9C48EC.exe Infected: not-a-virus:Downloader.Win32.WinFixer.d skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5F0E4682.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5F2F6A5E.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5F5D362B.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5FC91FB5.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\6027614D.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\6038333B.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\605C0113.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\608378E8.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\61983183.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\67BC73EE.tmp Infected: Trojan.Java.ClassLoader.h skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\6B973EF7.tmp Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\6B9E12F0.tmp Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\7064695A.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\75EE6D85.exe Infected: Trojan-Spy.Win32.Banker.alr skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\7A7D2E33.exe Infected: Trojan-Spy.Win32.Banker.alr skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\7D230168.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\7DAF0ECD.exe Infected: Worm.Win32.VB.an skipped

C:\Program Files\World of Warcraft\Logs\gx.log Object is locked skipped

C:\Program Files\World of Warcraft\Logs\SESound.log Object is locked skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\jhbbgjew.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\sysreset\backup\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.614 skipped

C:\sysreset\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP262\A0376450.exe/data.rar/mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.614 skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP262\A0376450.exe/data.rar Infected: not-a-virus:Client-IRC.Win32.mIRC.614 skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP262\A0376450.exe RarSFX: infected - 2 skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP377\A0442485.dll Infected: Trojan.Win32.Pakes.bsn skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP377\A0442486.dll Infected: Backdoor.Win32.Rbot.hdj skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP377\A0442503.dll Infected: Trojan.Win32.Pakes.bsn skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP377\A0442504.dll Infected: Backdoor.Win32.Rbot.hdj skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP377\A0442534.dll Infected: Trojan.Win32.Pakes.bsn skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP377\A0442535.dll Infected: Backdoor.Win32.Rbot.hdj skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP377\A0442570.dll Infected: Trojan.Win32.Pakes.bsn skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP377\A0442571.dll Infected: Backdoor.Win32.Rbot.hdj skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP377\A0442580.exe Infected: Trojan.Win32.Pakes.bsn skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP379\A0453668.exe Infected: Trojan-Downloader.Win32.Agent.ftu skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP388\A0459900.exe Infected: Trojan.Win32.Agent.efi skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP388\A0459908.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ebw skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP388\A0459927.exe Infected: Trojan.Win32.Agent.efi skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP389\A0459954.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.eby skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP389\A0459968.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP391\A0460111.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP391\A0461311.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP391\A0461427.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ebx skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP391\A0461428.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP391\A0461429.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ebx skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP392\A0461537.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP394\A0461686.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gip skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP394\A0461759.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP394\A0462824.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP394\A0462839.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0462914.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0463861.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0463862.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0463863.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0463864.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0463950.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0463951.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0463953.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0464038.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0464180.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0464181.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0464182.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.auj skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0464183.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0464184.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0464185.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.edw skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP396\A0464188.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP398\A0464234.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP398\A0464235.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP398\A0464237.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP398\A0464252.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP398\A0464262.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP399\A0464336.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP400\A0464471.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP401\A0465474.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP401\A0465507.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP401\A0465508.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP401\A0465513.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP402\A0465530.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP404\A0467602.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP404\A0467603.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP404\A0467604.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP404\A0467605.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP405\A0468235.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP406\A0468288.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP406\A0468289.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP412\A0473370.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP417\A0474541.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP417\A0474542.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP417\A0474543.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP417\A0474544.exe Infected: not-virus:Hoax.Win32.Renos.avw skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP417\A0474545.dll Infected: not-virus:Hoax.Win32.Renos.asm skipped

C:\System Volume Information\_restore{04DF63AB-4BAD-451F-943D-D10224FC08A5}\RP417\change.log Object is locked skipped

C:\VundoFix Backups\aeqesrwy.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\VundoFix Backups\awtrpqq.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ebz skipped

C:\VundoFix Backups\brtdnctd.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\VundoFix Backups\mmdqkblo.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\VundoFix Backups\nkrepqmi.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\VundoFix Backups\nwwfmuvf.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\VundoFix Backups\qbsiehbi.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\VundoFix Backups\vgiuaoey.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Downloaded Program Files\CleanerInstall.exe Infected: not-a-virus:AdWare.Win32.WebSearch.br skipped

C:\WINDOWS\pfirewall.log Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

C:\_OTMoveIt\MovedFiles\02172008_150011\WINDOWS\system32\awtrpqq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ebz skipped

C:\_OTMoveIt\MovedFiles\02172008_150011\WINDOWS\system32\pmwlbaer.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.kp skipped

Scan process completed.
  • 0

#19
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

You can delete this program after you run it.
================================
Please empty your Norton System works qurantine.

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK


    • Posted Image

    The above procedure will delete and do the following:

    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Clean System Restore points.

Also delete\uninstall anything that we used that is left over.
====================================
After that Your log is clean. :)

To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein ->Here
  • 0

#20
PK.

PK.

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Thank you guys <3 , i have found no threat anymore in my compute . You guys are so helpful .

Thx alot
  • 0

#21
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
You are welcome :)

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

#22
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP