Anyway I think I have gotten past that point, and now I am able to use my computer a bit, however at random seeming times, I feel another virus is kicking in. Task Manager no longer opens (although I can see it in the system tray) and the internet crashes. I have a HJT log for when this point happens, as well as from when I originally start up the computer. Any helpwould be greatly appreciaed. Thanks.
HJT Log immediatly after reboot:
Logfile of HijackThis v1.99.1
Scan saved at 7:10:16 AM, on 10/7/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\taskmgr.exe
C:\WINDOWS\System32\devldr32.exe
D:\Spyware\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1128608455867
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1128608908913
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
HJT Log after problems began (could no longer open websites/ task manager would not open. In fact, HJT crashes as it writes the log file, but I still get all of it I think)
Logfile of HijackThis v1.99.1
Scan saved at 7:05:58 AM, on 10/7/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\taskmgr.exe
D:\Spyware\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1128608455867
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1128608908913
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Thanks.
I have since had AVG and Norton detect viruses called "setup_22748.exe" and "eraseme_80274.exe" in my Windows/System32 folder.
I also ran Trend Microsystem's scanner and this is the log:
/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/
2005-10-06, 00:13:39, Auto-clean mode specified.
2005-10-06, 00:13:39, Running scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN"...
2005-10-06, 00:13:52, Scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN" has finished running.
2005-10-06, 00:13:52, TSC Log:
Damage Cleanup Engine (DCE) 3.9(Build 1020)
Windows XP(Build 2600: )
Start time : Thu Oct 06 2005 00:13:39
Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Administrator\Desktop\tsc.ptn" (version 660) [success]
TROJ_ROOTKIT.N[virus found]
-->delete registry key("HKEY_LOCAL_MACHINE","SYSTEM\CurrentControlSet\Services\hpdriver","") success
-->reboot delete file("C:\WINDOWS\system32\hpdriver.sys","","") success
TROJ_ROOTKIT.S[virus found]
-->delete registry key("HKEY_LOCAL_MACHINE","SYSTEM\CurrentControlSet\Services\remon","") success
-->reboot delete file("C:\WINDOWS\system32\remon.sys","","") success
Complete time : Thu Oct 06 2005 00:13:46
Execute pattern count(4419), Virus found count(2), Virus clean count(2), Clean failed count(0)
2005-10-06, 00:13:52, An error occurred while scanning file "C:\Documents and Settings\Administrator\NTUSER.DAT": Access is denied.
2005-10-06, 00:13:52, An error occurred while scanning file "C:\Documents and Settings\Administrator\ntuser.dat.LOG": Access is denied.
2005-10-06, 00:13:53, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 00:13:53, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\NTUSER.DAT": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\ntuser.dat.LOG": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\NTUSER.DAT": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\ntuser.dat.LOG": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-06, 00:14:37, An error was detected on "C:\System Volume Information\*.*": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\AVG70FREE_344A618.EXE-08078EF3.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\CHCP.COM-18156052.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\EDJGZIBPCZH.EXE-2B50515D.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-0637684A.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MMC.EXE-04908CDF.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\ROOTKITREVEALER.EXE-2DB196BC.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-42C4EDF2.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.COM-34F56E5D.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.EXE-22393993.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\TSC.BIN-34D78FF4.pf": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\default": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\default.LOG": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM.LOG": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY.LOG": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\software": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\software.LOG": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\system": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\system.LOG": Access is denied.
2005-10-06, 00:19:22, Running scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN"...
2005-10-06, 00:25:27, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 00:19:23
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop
C:\WINDOWS\system32\eraseme_04542.exe [WORM_SDBOT.CGY]
C:\WINDOWS\system32\eraseme_07708.exe [WORM_SDBOT.CGY]
C:\WINDOWS\system32\hpdriver.sys [TROJ_ROOTKIT.N]
C:\WINDOWS\system32\remon.sys [TROJ_ROOTKIT.S]
12997 files have been read.
12997 files have been checked.
11093 files have been scanned.
12426 files have been scanned. (including files in archived)
4 files containing viruses.
Found 4 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 00:25:27
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 00:25:27, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 00:19:23
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop
Success Clean [ WORM_SDBOT.CGY]( 1) from C:\WINDOWS\system32\eraseme_04542.exe
Success Clean [ WORM_SDBOT.CGY]( 1) from C:\WINDOWS\system32\eraseme_07708.exe
Success Clean [ TROJ_ROOTKIT.N]( 1) from C:\WINDOWS\system32\hpdriver.sys
Success Clean [ TROJ_ROOTKIT.S]( 1) from C:\WINDOWS\system32\remon.sys
12997 files have been read.
12997 files have been checked.
11093 files have been scanned.
12426 files have been scanned. (including files in archived)
4 files containing viruses.
Found 4 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 00:25:27 6 minutes 3 seconds (362.86 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 00:25:27, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 00:19:23
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop
12997 files have been read.
12997 files have been checked.
11093 files have been scanned.
12426 files have been scanned. (including files in archived)
4 files containing viruses.
Found 4 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 00:25:27 6 minutes 3 seconds (362.86 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 00:25:27, Scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN" has finished running.
2005-10-06, 01:07:51, An error was detected on "D:\System Volume Information\*.*": Access is denied.
2005-10-06, 01:19:13, Running scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN"...
2005-10-06, 01:22:41, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 01:19:14
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop
11910 files have been read.
11910 files have been checked.
10638 files have been scanned.
12014 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 01:22:41
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 01:22:41, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 01:19:14
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop
11910 files have been read.
11910 files have been checked.
10638 files have been scanned.
12014 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 01:22:41 3 minutes 26 seconds (206.84 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 01:22:41, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 01:19:14
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop
11910 files have been read.
11910 files have been checked.
10638 files have been scanned.
12014 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 01:22:41 3 minutes 26 seconds (206.84 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 01:22:41, Scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN" has finished running.
/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/
2005-10-06, 20:01:32, Auto-clean mode specified.
2005-10-06, 20:01:32, Running scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN"...
2005-10-06, 20:02:35, Scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN" has finished running.
2005-10-06, 20:02:35, TSC Log:
2005-10-06, 20:02:39, An error occurred while scanning file "C:\Documents and Settings\Administrator\NTUSER.DAT": Access is denied.
2005-10-06, 20:02:39, An error occurred while scanning file "C:\Documents and Settings\Administrator\ntuser.dat.LOG": Access is denied.
2005-10-06, 20:04:27, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 20:04:27, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/
2005-10-07, 07:25:50, Auto-clean mode specified.
2005-10-07, 07:25:50, Running scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN"...
2005-10-07, 07:26:19, Scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN" has finished running.
2005-10-07, 07:26:19, TSC Log:
Damage Cleanup Engine (DCE) 3.9(Build 1020)
Windows XP(Build 2600: )
Start time : Fri Oct 07 2005 07:25:54
Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Administrator\Desktop\tsc.ptn" (version 660) [success]
Complete time : Fri Oct 07 2005 07:26:18
Execute pattern count(4419), Virus found count(0), Virus clean count(0), Clean failed count(0)
2005-10-07, 07:26:19, An error occurred while scanning file "C:\Documents and Settings\Administrator\NTUSER.DAT": Access is denied.
2005-10-07, 07:26:19, An error occurred while scanning file "C:\Documents and Settings\Administrator\ntuser.dat.LOG": Access is denied.
2005-10-07, 07:26:24, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-07, 07:26:24, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\LocalService\NTUSER.DAT": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\LocalService\ntuser.dat.LOG": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\NTUSER.DAT": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\ntuser.dat.LOG": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-07, 07:30:32, Could not set file for reading on "C:\Program Files\Symantec AntiVirus\SAVRT\0391NAV~.TMP": Access is denied.
2005-10-07, 07:30:35, An error was detected on "C:\System Volume Information\*.*": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVG70FREE_344A618.EXE-08078EF3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGAMSVR.EXE-13835775.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGCC.EXE-12C08071.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGEMC.EXE-0BA2F01F.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGINET.EXE-3038B75E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGINET.EXE-3B0744C3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGSETUP.EXE-1C44C95B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGUPSVC.EXE-28C59C55.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGW.EXE-00A2F684.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGW.EXE-011FD837.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGWB.DAT-01D5CE53.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGWB.DAT-25B8DD3B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\BITSINST.EXE-2CB4826B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CCAPP.EXE-1207B2A5.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CCEVTMGR.EXE-24B7A008.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CCSETMGR.EXE-399BF976.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CHCP.COM-18156052.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DEFRAG.EXE-273F131E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DEFWATCH.EXE-072A5A71.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DEVLDR32.EXE-2CF621DF.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DRMUPGDS.EXE-145D2D37.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DWHWIZRD.EXE-1D638167.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\EDJGZIBPCZH.EXE-2B50515D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\FTP.EXE-0FFFB5A3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\GMAILINSTALLER.EXE-316701F3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\GNOTIFY.EXE-12E1F66C.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-0637684A.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IDRIVER.EXE-20D017F5.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IDRIVERT.EXE-28903C83.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IE6.0-KB834707-WINDOWSXP-X86--3A7EF1B6.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IPODSERVICE.EXE-3192DE38.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IS-SPILK.TMP-01BADAB9.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ITUNES.EXE-1A268432.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ITUNESSETUP.EXE-0365EDA1.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ITUNESSETUP.EXE-374DDAC8.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\JS56NEN.EXE-192922DD.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\KLMCODEC138.EXE-0C640055.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Layout.ini": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGAGENT.EXE-027AF92B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGON.SCR-151EFAEA.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LSETUP.EXE-0800EE26.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LUALL.EXE-2BCC229F.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LUCOMS~1.EXE-02DB5950.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LUSETUP.EXE-3175C013.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MIGRATE.EXE-3A41124D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MMC.EXE-04908CDF.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MP10SETUP.EXE-2AD31E6C.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MPLAYERC.EXE-06A9CBF3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSI76.TMP-30842353.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSI7D.TMP-28483EC4.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSIEXEC.EXE-2F8A8CAE.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q323255_X86_EN.EXE-18BCF5B9.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329048_XP.EXE-0C05766F.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329115_WXP_SP2_X86_ENU.EXE-041C661A.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329170_WXP_SP2_EN.EXE-0893FBE2.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329390_WXP.EXE-37C51BF6.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329834_WXP_SP2_EN.EXE-05608540.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q810577_WXP_EN.EXE-15E35A2A.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q810833_WXP_SP2_X86_ENU.EXE-194F31C6.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q811630_WXP_SP2_EN.EXE-1E639A55.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q817606_WXP_SP2_X86_ENU.EXE-0907B567.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QTPLUGININSTALLER.EXE-30539ABC.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QTTASK.EXE-085F7C4C.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QTTASK.EXE-2FCE56F5.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QUICKTIMEINSTALLER.EXE-17CE5FD7.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QUICKTIMEPLAYER.EXE-221AD8B3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ROOTKITREVEALER.EXE-2DB196BC.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RTVSCAN.EXE-1D887DCC.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-26DA8C9B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-28EEC8F7.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-3DB12343.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-42C4EDF2.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-445649BB.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SAVCE_10.EXE-1F243F40.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP.EXE-02182199.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP_WM.EXE-0AB3B7DA.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SEVINST.EXE-1B62D49D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.COM-34F56E5D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.EXE-22393993.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\TASKMGR.EXE-20256C55.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\TSC.BIN-34D78FF4.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UNREGMP2.EXE-2D619A25.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-01EA7A76.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-06AB547E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-103B105E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-108BE778.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1129BF8E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1339A893.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1D175346.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1DA3AB04.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1E4F605C.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-252B7790.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2726CBE7.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2A7C8836.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2BE3980D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-32F25CFE.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-35BBDDD6.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-3B194009.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VIDCCLEANER.EXE-305CB5C8.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VPC32.EXE-2E9C8D92.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VPDN_LU.EXE-0A29B4CE.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VPTRAY.EXE-2D128BA2.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VSCANTM.BIN-0E7AF771.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSXP-KB329441-X86-ENU.EX-32632D31.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSXP-KB823559-X86-ENU.EX-1F644FC0.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSXP-KB828741-X86-ENU.EX-0E012BC9.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSXP-KB835732-X86-ENU.EX-1F4E66F5.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WINPFIND.EXE-21186B3E.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-05601BEB.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-05CE4FB0.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-062AED92.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-06565957.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-08DB1F21.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-0AB8F0BC.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-12C8D73B.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-1580BBB0.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-27C02FA0.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-2A55B041.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-31E61C88.pf": Access is denied.
2005-10-07, 07:33:30, An error occurred while scanning file "C:\WINDOWS\system32\eraseme_80274.exe": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\default": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\default.LOG": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM.LOG": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY.LOG": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\software": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\software.LOG": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\system": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\system.LOG": Access is denied.
2005-10-07, 07:42:23, Running scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN"...
2005-10-07, 07:57:06, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 07:42:24
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop
18618 files have been read.
18618 files have been checked.
15818 files have been scanned.
18209 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 07:57:06
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 07:57:06, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 07:42:24
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop
18618 files have been read.
18618 files have been checked.
15818 files have been scanned.
18209 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 07:57:06 14 minutes 41 seconds (881.35 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 07:57:06, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 07:42:24
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop
18618 files have been read.
18618 files have been checked.
15818 files have been scanned.
18209 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 07:57:06 14 minutes 41 seconds (881.35 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 07:57:06, Scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN" has finished running.
2005-10-07, 09:20:06, An error was detected on "D:\System Volume Information\*.*": Access is denied.
2005-10-07, 09:31:41, Running scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN"...
2005-10-07, 09:36:23, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 09:31:43
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop
11911 files have been read.
11911 files have been checked.
10639 files have been scanned.
12015 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 09:36:23
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 09:36:23, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 09:31:43
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop
11911 files have been read.
11911 files have been checked.
10639 files have been scanned.
12015 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 09:36:23 4 minutes 40 seconds (279.86 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 09:36:23, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 09:31:43
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop
11911 files have been read.
11911 files have been checked.
10639 files have been scanned.
12015 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 09:36:23 4 minutes 40 seconds (279.86 seconds) has elapsed.