Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Spyware Infected [RESOLVED]


  • This topic is locked This topic is locked

#16
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
==============================
Please do an online scan with Kaspersky WebScanner
(This scanner is for use with internet explorer only)
Click on "Accept"

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as button:
  • Save the file in txt format to your desktop.
  • Post that information in your next post.

  • 0

Advertisements


#17
kommie

kommie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Cleaned the Computer
  • 0

#18
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
What do you mean?
  • 0

#19
kommie

kommie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Sorry I was writing quickly. I cleaned my computer using ATF Cleaner. Everything seems to be working now.
  • 0

#20
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Okay but since you had some bad infections I would like to check for leftovers so please go ahead with the Kaspersky scanner.
Post that log when you are done and we will wrap it up.
  • 0

#21
kommie

kommie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Thanks for your Help Kahdah. I really appricate what you are doing. You saved me from having to do a reformat. Thank You!!!
  • 0

#22
kommie

kommie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Sunday, June 08, 2008 9:15 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 8/06/2008
Kaspersky Anti-Virus database records: 840603


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target Folders
C:\

Scan Statistics
Total number of scanned objects 79121
Number of viruses found 8
Number of infected objects 24
Number of suspicious objects 0
Duration of the scan process 01:47:51

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped

C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{FC7EAC43-62F2-4CF7-B5C0-A243371ED360}.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR1.tmp Object is locked skipped

C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\Dominik\Application Data\acccore\nss\cert8.db Object is locked skipped

C:\Documents and Settings\Dominik\Application Data\acccore\nss\key3.db Object is locked skipped

C:\Documents and Settings\Dominik\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\AOL OCP\AIM\Storage\data\bogii27\localStorage\common.cls Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\ApplicationHistory\hpqimzone.exe.3204510e.ini.inuse Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\dbc2e.ht1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\dbdam Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\dbdao Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\dbeam Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\dbeao Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\dbm Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\dbu2d.ht1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\dbvm.cf1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\dbvmh.ht1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\fii.cf1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\fiih.ht1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\fim1i.cf1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\fim1ih.ht1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\hp Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\hpt2i.ht1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\rpm.cf1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\rpm1m.cf1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\rpm1mh.ht1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\rpmh.ht1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\safeweb\goog-black-enchashm.cf1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\safeweb\goog-black-enchashmh.ht1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\safeweb\goog-black-urlm.cf1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\safeweb\goog-black-urlmh.ht1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\safeweb\goog-malware-domainm.cf1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\safeweb\goog-malware-domainmh.ht1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\safeweb\goog-white-domainm.cf1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Google\Google Desktop\62866134fc8d\safeweb\goog-white-domainmh.ht1 Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.cdx Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.dbf Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\pending.dat Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_24EC_ECA_EC0E_9668\dfsr.db Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_24EC_ECA_EC0E_9668\fsr.log Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_24EC_ECA_EC0E_9668\fsrtmp.log Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_24EC_ECA_EC0E_9668\tmp.edb Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Application Data\Microsoft\Windows Live Contacts\[email protected]\real\members.stg Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\History\History.IE5\MSHist012008060820080609\index.dat Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\temp\mirc631.exe/stream/data0014 Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped

C:\Documents and Settings\Dominik\Local Settings\temp\mirc631.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped

C:\Documents and Settings\Dominik\Local Settings\temp\mirc631.exe NSIS: infected - 2 skipped

C:\Documents and Settings\Dominik\Local Settings\temp\Perflib_Perfdata_d4c.dat Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\temp\~DF428D.tmp Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\temp\~DF687C.tmp Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\temp\~DF69DE.tmp Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\temp\~DF91ED.tmp Object is locked skipped

C:\Documents and Settings\Dominik\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Dominik\My Documents\mirc621.exe/stream/data0008 Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped

C:\Documents and Settings\Dominik\My Documents\mirc621.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped

C:\Documents and Settings\Dominik\My Documents\mirc621.exe NSIS: infected - 2 skipped

C:\Documents and Settings\Dominik\ntuser.dat Object is locked skipped

C:\Documents and Settings\Dominik\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\temp\Perflib_Perfdata_d58.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Program Files\DAP\DAP.exe Infected: Trojan-Spy.Win32.Banker.fzf skipped

C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\master.mdf Object is locked skipped

C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\mastlog.ldf Object is locked skipped

C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\model.mdf Object is locked skipped

C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\modellog.ldf Object is locked skipped

C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdbdata.mdf Object is locked skipped

C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdblog.ldf Object is locked skipped

C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\tempdb.mdf Object is locked skipped

C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\templog.ldf Object is locked skipped

C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\ERRORLOG Object is locked skipped

C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\log_69.trc Object is locked skipped

C:\Program Files\mIRC\logs\status.Coldfront.log Object is locked skipped

C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped

C:\Program Files\OpenSSH\var\log\OpenSSHd.log Object is locked skipped

C:\QooBox\Quarantine\C\WINDOWS\h8907435.exe.vir Infected: Trojan-Downloader.Win32.VB.euf skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\iftuyszv.exe.vir Infected: not-virus:Hoax.Win32.Renos.cvz skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\irhwwtgo.dll.vir Infected: Trojan.Win32.Agent.reo skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP1\A0003327.exe/data0000.cab/LimeWireWin.exe/data0000.cab/LimeWireWin.exe/data0000.cab/DO NOT CLICK ITS A VIRUS!!!.exe Infected: Trojan.Win32.Monder.gen skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP1\A0003327.exe/data0000.cab/LimeWireWin.exe/data0000.cab/LimeWireWin.exe/data0000.cab/_launcher.exe Infected: Trojan-Clicker.MSIL.Xone.r skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP1\A0003327.exe/data0000.cab/LimeWireWin.exe/data0000.cab/LimeWireWin.exe/data0000.cab/_1.exe Infected: Trojan.Win32.Monder.gen skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP1\A0003327.exe/data0000.cab/LimeWireWin.exe/data0000.cab/LimeWireWin.exe/data0000.cab Infected: Trojan.Win32.Monder.gen skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP1\A0003327.exe/data0000.cab/LimeWireWin.exe/data0000.cab/LimeWireWin.exe Infected: Trojan.Win32.Monder.gen skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP1\A0003327.exe/data0000.cab/LimeWireWin.exe/data0000.cab/is202172.exe Infected: Trojan.Win32.Monder.gen skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP1\A0003327.exe/data0000.cab/LimeWireWin.exe/data0000.cab Infected: Trojan.Win32.Monder.gen skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP1\A0003327.exe/data0000.cab/LimeWireWin.exe Infected: Trojan.Win32.Monder.gen skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP1\A0003327.exe/data0000.cab/is202172.exe Infected: Trojan.Win32.Monder.gen skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP1\A0003327.exe/data0000.cab Infected: Trojan.Win32.Monder.gen skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP1\A0003327.exe Rsrc-Package: infected - 10 skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP3\A0004311.dll Infected: Trojan.Win32.Agent.reo skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP4\A0005450.exe Infected: Trojan-Downloader.Win32.VB.euf skipped

C:\System Volume Information\_restore{95292604-CB0B-4F7E-995A-B50C63416FD2}\RP5\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\ModemLog_AC97 Soft Data Fax Modem with SmartCP.txt Object is locked skipped

C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{5BD39F83-5FF9-4A4E-A959-BCE673FF8893}.crmlog Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{5CF68D8B-03D0-4FF5-94AA-3C46D6E4B9CE}.bin Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped

C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped

C:\WINDOWS\system32\config\OSession.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\temp\mcmsc_b3hbqOM7ck7B066 Object is locked skipped

C:\WINDOWS\temp\mcmsc_CrvhceNzuvuSGkP Object is locked skipped

C:\WINDOWS\temp\mcmsc_HYIqt8RkRrZD7F5 Object is locked skipped

C:\WINDOWS\temp\mcmsc_LeXDnKbx7bEskBd Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
  • 0

#23
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
You are welcome :)
====================
Cleanup::
  • Make sure you have an Internet Connection.
  • Double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OtMoveit2 to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
===============
After that Upgrading Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u6-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.

=============================
Delete\uninstall anything else that we have used.

System Restore
Then I will need you to reset your System Restore points.
The link below shows how to create a clean restore point.
How to Turn On and Turn Off System Restore in Windows XP
http://support.micro...kb/310405/en-us
=====================================
After that your log is clean. :)

The following is a list of tools and utilities that I like to suggest to people.
You do not have to have all or any of them they are only suggestions.
This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.

Spybot Search & Destroy-Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.

Spyware Blaster - Great prevention tool to keep nasties from installing on your system.

Spywareguard-Works as a Spyware "Shield" to protect your computer from getting malware in the first place.

IE-SPYAD- puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

Tony Klein article To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.
  • 0

#24
kommie

kommie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Thanks I have completed these steps.
  • 0

#25
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
You are welcome :)


Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

Advertisements


#26
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP