Kaspersky just finished, hooray! F-Secure was unable to download the needed components to run the scan.
Thanks so much for your help thus far, I have seen a great improvement. The "VIRUS ALERT!" text appears to be gone for good, however windows validation still does not complete.
As far as other issues with the computer that I'm aware of:
CA Internet Security Suite attempts to reinstall something at each boot. It cannot find the file CAPF.msi I believe this to be a known issue with a windows update, and I've attempted the solution described by CA here
http://home3.ca.com/...x?sc_lang=es-ESUnfortunately I believe running recent Windows updates will likely fix this, but as the validation has not been working, I haven't been able to proceed. According to my father this has been a long-time issue, and is probably not related to the virus/malware issues my lovely relatives managed to cause.
Log results to follow.
Please find the requested OTScanIt log (post virus scan) attached
Logfile of The Avenger Version 2.0, © by Swandog46http://swandog46.geekstogo.comPlatform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
File "C:\345543.bat" deleted successfully.
File "C:\818646.bat" deleted successfully.
File "c:\documents and settings\all users.windows\application data\microsoft\network\downloader\qmgr0.dat" deleted successfully.
File "c:\documents and settings\all users.windows\application data\microsoft\network\downloader\qmgr1.dat" deleted successfully.
Folder "C:\WINDOWS.0" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
OTScanIT fix logExplorer killed successfully
[Registry - Additional Scans - Non-Microsoft Only]
Registry value HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\\DisableCMD deleted successfully.
[Files/Folders - Created Within 30 days]
File C:\345543.bat not found!
File C:\818646.bat not found!
[Files/Folders - Modified Within 30 days]
File C:\345543.bat not found!
File C:\818646.bat not found!
File C:\WINDOWS.0 not found!
File move failed. C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat scheduled to be moved on reboot.
[Extra Registry Entries]
HKEY_CURRENT_USER\Control Panel\International\\sTimeFormat|reg_sz:hh:mm:ss tt /e : value set successfully!
[Empty Temp Folders]
File delete failed. C:\Documents and Settings\Paul\Local Settings\Temp\~DF7BE2.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Paul\Local Settings\Temp\~DFC4F7.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
RecycleBin -> emptied.
Explorer started successfully
< End of fix log >
OTScanIt by OldTimer - Version 1.0.15.4 fix logfile created on 05292008_212504
Files moved on Reboot...
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat moved successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat moved successfully.
C:\Documents and Settings\Paul\Local Settings\Temp\~DF7BE2.tmp moved successfully.
C:\Documents and Settings\Paul\Local Settings\Temp\~DFC4F7.tmp moved successfully.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT Thursday, May 29, 2008 11:51:51 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 30/05/2008
Kaspersky Anti-Virus database records: 813686
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
F:\
G:\
H:\
I:\
J:\
K:\
Scan Statistics:
Total number of scanned objects: 101601
Number of viruses found: 10
Number of infected objects: 26
Number of suspicious objects: 0
Duration of the scan process: 01:59:58
Infected Object Name / Virus Name / Last Action
C:\4995adeb1a5e89bf6831\msxml4-KB927978-enu.log Object is locked skipped
C:\Config.Msi\1b5ef.rbs Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Paul\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Paul\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Paul\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Paul\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Paul\Local Settings\Temp\~DF78A0.tmp Object is locked skipped
C:\Documents and Settings\Paul\Local Settings\Temp\~DFFDF9.tmp Object is locked skipped
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Paul\ntuser.dat Object is locked skipped
C:\Documents and Settings\Paul\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\Paul Mankus\Local Settings\Application Data\Identities\{2F7BE642-488A-4C90-AC6B-6DBF3B702EF8}\Microsoft\Outlook Express\Inbox.dbx/[From <
[email protected]>][Date Thu, 26 Jun 2003 22:51:34 --0500]/your_details.zi/details.pif Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\Paul Mankus\Local Settings\Application Data\Identities\{2F7BE642-488A-4C90-AC6B-6DBF3B702EF8}\Microsoft\Outlook Express\Inbox.dbx/[From <
[email protected]>][Date Thu, 26 Jun 2003 22:51:34 --0500]/your_details.zi Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\Paul Mankus\Local Settings\Application Data\Identities\{2F7BE642-488A-4C90-AC6B-6DBF3B702EF8}\Microsoft\Outlook Express\Inbox.dbx/[From <
[email protected]>][Date Thu, 26 Jun 2003 22:51:26 --0500]/UNNAMED/your_details.zi/details.pif Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\Paul Mankus\Local Settings\Application Data\Identities\{2F7BE642-488A-4C90-AC6B-6DBF3B702EF8}\Microsoft\Outlook Express\Inbox.dbx/[From <
[email protected]>][Date Thu, 26 Jun 2003 22:51:26 --0500]/UNNAMED/your_details.zi Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\Paul Mankus\Local Settings\Application Data\Identities\{2F7BE642-488A-4C90-AC6B-6DBF3B702EF8}\Microsoft\Outlook Express\Inbox.dbx/[From <
[email protected]>][Date Thu, 26 Jun 2003 22:51:26 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\Paul Mankus\Local Settings\Application Data\Identities\{2F7BE642-488A-4C90-AC6B-6DBF3B702EF8}\Microsoft\Outlook Express\Inbox.dbx MailMSOutlook5: infected - 5 skipped
C:\Downloads\ToyTanksSetup-dm[1].exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Program Files\CA\SharedComponents\PPRT\logs\2008-05-29.csv Object is locked skipped
C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped
C:\Program Files\Microsoft AntiSpyware\Quarantine\952F40FC-8C96-4E9E-8F2E-DF780A\B438855A-E91B-4120-BB77-C9F795 Infected: not-a-virus:AdWare.Win32.MyWay.b skipped
C:\Program Files\Microsoft AntiSpyware\Quarantine\952F40FC-8C96-4E9E-8F2E-DF780A\C34E54A9-DADA-4D3B-ACCF-12850A Infected: not-a-virus:AdWare.Win32.MyWay.c skipped
C:\Program Files\Norton AntiVirus\Quarantine\0128659F.dll Infected: Trojan.Win32.Delf.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\0AF44322.dll Infected: Trojan.Win32.Delf.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\0AF76D1F.exe Infected: Email-Worm.Win32.Sobig.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\0CB32AE2.dll Infected: Trojan.Win32.Delf.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\112D3BF5 Infected: Email-Worm.Win32.Sobig.e skipped
C:\Program Files\Norton AntiVirus\Quarantine\114C0EAF.exe Infected: Backdoor.Win32.Delf.da skipped
C:\Program Files\Norton AntiVirus\Quarantine\25DB0287.exe Infected: Trojan-Proxy.Win32.WinGater skipped
C:\Program Files\Norton AntiVirus\Quarantine\27C61DF7.dll Infected: Trojan.Win32.Delf.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\288819FB.dll Infected: Trojan.Win32.Delf.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\2A37361F.dll Infected: Trojan.Win32.Delf.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\51B142F9.dll Infected: Trojan.Win32.Delf.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\53006E1A.dll Infected: Trojan.Win32.Delf.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\58214238 Infected: Trojan.Win32.Delf.r skipped
C:\Program Files\Norton AntiVirus\Quarantine\67866D41.dll Infected: Trojan.Win32.Delf.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\6B3D2324.dll Infected: Trojan.Win32.Delf.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\75785F54.dll Infected: Trojan.Win32.Delf.d skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{D1567126-26A0-42B9-A807-E3A68CB76E51}\RP633\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINNT\system32\trlacert.exe Infected: not-a-virus:AdWare.Win32.Connector skipped
Scan process completed.