Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Lurking Virus


  • Please log in to reply

#1
DanSun1222

DanSun1222

    New Member

  • Member
  • Pip
  • 2 posts
I have just spent a week trying to rid my computer of a virus that woudl survive a reformat of my computer. I woudl reformat it (using teh XP disc and deleting the C partition and installing a new in the empty spot) and when I booted up there would be the same virus/hacker tool. I had TASKESV and "windows drivers32" as services and my windows task manager would not work and the internet would not work.

Anyway I think I have gotten past that point, and now I am able to use my computer a bit, however at random seeming times, I feel another virus is kicking in. Task Manager no longer opens (although I can see it in the system tray) and the internet crashes. I have a HJT log for when this point happens, as well as from when I originally start up the computer. Any helpwould be greatly appreciaed. Thanks.

HJT Log immediatly after reboot:

Logfile of HijackThis v1.99.1
Scan saved at 7:10:16 AM, on 10/7/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\taskmgr.exe
C:\WINDOWS\System32\devldr32.exe
D:\Spyware\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1128608455867
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1128608908913
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

HJT Log after problems began (could no longer open websites/ task manager would not open. In fact, HJT crashes as it writes the log file, but I still get all of it I think)

Logfile of HijackThis v1.99.1
Scan saved at 7:05:58 AM, on 10/7/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\taskmgr.exe
D:\Spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1128608455867
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1128608908913
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

Thanks.



I have since had AVG and Norton detect viruses called "setup_22748.exe" and "eraseme_80274.exe" in my Windows/System32 folder.

I also ran Trend Microsystem's scanner and this is the log:


/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/


2005-10-06, 00:13:39, Auto-clean mode specified.
2005-10-06, 00:13:39, Running scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN"...
2005-10-06, 00:13:52, Scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN" has finished running.
2005-10-06, 00:13:52, TSC Log:

Damage Cleanup Engine (DCE) 3.9(Build 1020)
Windows XP(Build 2600: )

Start time : Thu Oct 06 2005 00:13:39

Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Administrator\Desktop\tsc.ptn" (version 660) [success]
TROJ_ROOTKIT.N[virus found]
-->delete registry key("HKEY_LOCAL_MACHINE","SYSTEM\CurrentControlSet\Services\hpdriver","") success
-->reboot delete file("C:\WINDOWS\system32\hpdriver.sys","","") success
TROJ_ROOTKIT.S[virus found]
-->delete registry key("HKEY_LOCAL_MACHINE","SYSTEM\CurrentControlSet\Services\remon","") success
-->reboot delete file("C:\WINDOWS\system32\remon.sys","","") success

Complete time : Thu Oct 06 2005 00:13:46
Execute pattern count(4419), Virus found count(2), Virus clean count(2), Clean failed count(0)

2005-10-06, 00:13:52, An error occurred while scanning file "C:\Documents and Settings\Administrator\NTUSER.DAT": Access is denied.
2005-10-06, 00:13:52, An error occurred while scanning file "C:\Documents and Settings\Administrator\ntuser.dat.LOG": Access is denied.
2005-10-06, 00:13:53, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 00:13:53, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\NTUSER.DAT": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\ntuser.dat.LOG": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\NTUSER.DAT": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\ntuser.dat.LOG": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 00:14:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-06, 00:14:37, An error was detected on "C:\System Volume Information\*.*": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\AVG70FREE_344A618.EXE-08078EF3.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\CHCP.COM-18156052.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\EDJGZIBPCZH.EXE-2B50515D.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-0637684A.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MMC.EXE-04908CDF.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\ROOTKITREVEALER.EXE-2DB196BC.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-42C4EDF2.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.COM-34F56E5D.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.EXE-22393993.pf": Access is denied.
2005-10-06, 00:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\TSC.BIN-34D78FF4.pf": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\default": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\default.LOG": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM.LOG": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY.LOG": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\software": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\software.LOG": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\system": Access is denied.
2005-10-06, 00:16:48, An error occurred while scanning file "C:\WINDOWS\system32\config\system.LOG": Access is denied.
2005-10-06, 00:19:22, Running scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN"...
2005-10-06, 00:25:27, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 00:19:23
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop

C:\WINDOWS\system32\eraseme_04542.exe [WORM_SDBOT.CGY]
C:\WINDOWS\system32\eraseme_07708.exe [WORM_SDBOT.CGY]
C:\WINDOWS\system32\hpdriver.sys [TROJ_ROOTKIT.N]
C:\WINDOWS\system32\remon.sys [TROJ_ROOTKIT.S]
12997 files have been read.
12997 files have been checked.
11093 files have been scanned.
12426 files have been scanned. (including files in archived)
4 files containing viruses.
Found 4 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 00:25:27
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 00:25:27, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 00:19:23
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop

Success Clean [ WORM_SDBOT.CGY]( 1) from C:\WINDOWS\system32\eraseme_04542.exe
Success Clean [ WORM_SDBOT.CGY]( 1) from C:\WINDOWS\system32\eraseme_07708.exe
Success Clean [ TROJ_ROOTKIT.N]( 1) from C:\WINDOWS\system32\hpdriver.sys
Success Clean [ TROJ_ROOTKIT.S]( 1) from C:\WINDOWS\system32\remon.sys
12997 files have been read.
12997 files have been checked.
11093 files have been scanned.
12426 files have been scanned. (including files in archived)
4 files containing viruses.
Found 4 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 00:25:27 6 minutes 3 seconds (362.86 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 00:25:27, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 00:19:23
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop

12997 files have been read.
12997 files have been checked.
11093 files have been scanned.
12426 files have been scanned. (including files in archived)
4 files containing viruses.
Found 4 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 00:25:27 6 minutes 3 seconds (362.86 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 00:25:27, Scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN" has finished running.
2005-10-06, 01:07:51, An error was detected on "D:\System Volume Information\*.*": Access is denied.
2005-10-06, 01:19:13, Running scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN"...
2005-10-06, 01:22:41, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 01:19:14
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop

11910 files have been read.
11910 files have been checked.
10638 files have been scanned.
12014 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 01:22:41
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 01:22:41, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 01:19:14
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop

11910 files have been read.
11910 files have been checked.
10638 files have been scanned.
12014 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 01:22:41 3 minutes 26 seconds (206.84 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 01:22:41, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 01:19:14
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop

11910 files have been read.
11910 files have been checked.
10638 files have been scanned.
12014 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 01:22:41 3 minutes 26 seconds (206.84 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 01:22:41, Scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN" has finished running.


/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/


2005-10-06, 20:01:32, Auto-clean mode specified.
2005-10-06, 20:01:32, Running scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN"...
2005-10-06, 20:02:35, Scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN" has finished running.
2005-10-06, 20:02:35, TSC Log:

2005-10-06, 20:02:39, An error occurred while scanning file "C:\Documents and Settings\Administrator\NTUSER.DAT": Access is denied.
2005-10-06, 20:02:39, An error occurred while scanning file "C:\Documents and Settings\Administrator\ntuser.dat.LOG": Access is denied.
2005-10-06, 20:04:27, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 20:04:27, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.


/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/


2005-10-07, 07:25:50, Auto-clean mode specified.
2005-10-07, 07:25:50, Running scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN"...
2005-10-07, 07:26:19, Scanner "C:\Documents and Settings\Administrator\Desktop\TSC.BIN" has finished running.
2005-10-07, 07:26:19, TSC Log:

Damage Cleanup Engine (DCE) 3.9(Build 1020)
Windows XP(Build 2600: )

Start time : Fri Oct 07 2005 07:25:54

Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Administrator\Desktop\tsc.ptn" (version 660) [success]

Complete time : Fri Oct 07 2005 07:26:18
Execute pattern count(4419), Virus found count(0), Virus clean count(0), Clean failed count(0)

2005-10-07, 07:26:19, An error occurred while scanning file "C:\Documents and Settings\Administrator\NTUSER.DAT": Access is denied.
2005-10-07, 07:26:19, An error occurred while scanning file "C:\Documents and Settings\Administrator\ntuser.dat.LOG": Access is denied.
2005-10-07, 07:26:24, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-07, 07:26:24, An error occurred while scanning file "C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\LocalService\NTUSER.DAT": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\LocalService\ntuser.dat.LOG": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\NTUSER.DAT": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\ntuser.dat.LOG": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-07, 07:28:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-07, 07:30:32, Could not set file for reading on "C:\Program Files\Symantec AntiVirus\SAVRT\0391NAV~.TMP": Access is denied.
2005-10-07, 07:30:35, An error was detected on "C:\System Volume Information\*.*": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVG70FREE_344A618.EXE-08078EF3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGAMSVR.EXE-13835775.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGCC.EXE-12C08071.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGEMC.EXE-0BA2F01F.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGINET.EXE-3038B75E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGINET.EXE-3B0744C3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGSETUP.EXE-1C44C95B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGUPSVC.EXE-28C59C55.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGW.EXE-00A2F684.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGW.EXE-011FD837.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGWB.DAT-01D5CE53.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGWB.DAT-25B8DD3B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\BITSINST.EXE-2CB4826B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CCAPP.EXE-1207B2A5.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CCEVTMGR.EXE-24B7A008.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CCSETMGR.EXE-399BF976.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CHCP.COM-18156052.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DEFRAG.EXE-273F131E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DEFWATCH.EXE-072A5A71.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DEVLDR32.EXE-2CF621DF.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DRMUPGDS.EXE-145D2D37.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DWHWIZRD.EXE-1D638167.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\EDJGZIBPCZH.EXE-2B50515D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\FTP.EXE-0FFFB5A3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\GMAILINSTALLER.EXE-316701F3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\GNOTIFY.EXE-12E1F66C.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-0637684A.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IDRIVER.EXE-20D017F5.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IDRIVERT.EXE-28903C83.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IE6.0-KB834707-WINDOWSXP-X86--3A7EF1B6.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IPODSERVICE.EXE-3192DE38.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IS-SPILK.TMP-01BADAB9.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ITUNES.EXE-1A268432.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ITUNESSETUP.EXE-0365EDA1.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ITUNESSETUP.EXE-374DDAC8.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\JS56NEN.EXE-192922DD.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\KLMCODEC138.EXE-0C640055.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Layout.ini": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGAGENT.EXE-027AF92B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGON.SCR-151EFAEA.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LSETUP.EXE-0800EE26.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LUALL.EXE-2BCC229F.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LUCOMS~1.EXE-02DB5950.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LUSETUP.EXE-3175C013.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MIGRATE.EXE-3A41124D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MMC.EXE-04908CDF.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MP10SETUP.EXE-2AD31E6C.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MPLAYERC.EXE-06A9CBF3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSI76.TMP-30842353.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSI7D.TMP-28483EC4.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSIEXEC.EXE-2F8A8CAE.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q323255_X86_EN.EXE-18BCF5B9.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329048_XP.EXE-0C05766F.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329115_WXP_SP2_X86_ENU.EXE-041C661A.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329170_WXP_SP2_EN.EXE-0893FBE2.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329390_WXP.EXE-37C51BF6.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q329834_WXP_SP2_EN.EXE-05608540.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q810577_WXP_EN.EXE-15E35A2A.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q810833_WXP_SP2_X86_ENU.EXE-194F31C6.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q811630_WXP_SP2_EN.EXE-1E639A55.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Q817606_WXP_SP2_X86_ENU.EXE-0907B567.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QTPLUGININSTALLER.EXE-30539ABC.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QTTASK.EXE-085F7C4C.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QTTASK.EXE-2FCE56F5.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QUICKTIMEINSTALLER.EXE-17CE5FD7.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\QUICKTIMEPLAYER.EXE-221AD8B3.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ROOTKITREVEALER.EXE-2DB196BC.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RTVSCAN.EXE-1D887DCC.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-26DA8C9B.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-28EEC8F7.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-3DB12343.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-42C4EDF2.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-445649BB.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SAVCE_10.EXE-1F243F40.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP.EXE-02182199.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP_WM.EXE-0AB3B7DA.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SEVINST.EXE-1B62D49D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.COM-34F56E5D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.EXE-22393993.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\TASKMGR.EXE-20256C55.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\TSC.BIN-34D78FF4.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UNREGMP2.EXE-2D619A25.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-01EA7A76.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-06AB547E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-103B105E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-108BE778.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1129BF8E.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1339A893.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1D175346.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1DA3AB04.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1E4F605C.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-252B7790.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2726CBE7.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2A7C8836.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2BE3980D.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-32F25CFE.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-35BBDDD6.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-3B194009.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VIDCCLEANER.EXE-305CB5C8.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VPC32.EXE-2E9C8D92.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VPDN_LU.EXE-0A29B4CE.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VPTRAY.EXE-2D128BA2.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\VSCANTM.BIN-0E7AF771.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSXP-KB329441-X86-ENU.EX-32632D31.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSXP-KB823559-X86-ENU.EX-1F644FC0.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSXP-KB828741-X86-ENU.EX-0E012BC9.pf": Access is denied.
2005-10-07, 07:32:47, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSXP-KB835732-X86-ENU.EX-1F4E66F5.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WINPFIND.EXE-21186B3E.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-05601BEB.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-05CE4FB0.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-062AED92.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-06565957.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-08DB1F21.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-0AB8F0BC.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-12C8D73B.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-1580BBB0.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-27C02FA0.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-2A55B041.pf": Access is denied.
2005-10-07, 07:32:48, Could not set file for reading on "C:\WINDOWS\Prefetch\XPSP1HFM.EXE-31E61C88.pf": Access is denied.
2005-10-07, 07:33:30, An error occurred while scanning file "C:\WINDOWS\system32\eraseme_80274.exe": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\default": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\default.LOG": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM.LOG": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY.LOG": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\software": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\software.LOG": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\system": Access is denied.
2005-10-07, 07:36:06, An error occurred while scanning file "C:\WINDOWS\system32\config\system.LOG": Access is denied.
2005-10-07, 07:42:23, Running scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN"...
2005-10-07, 07:57:06, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 07:42:24
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop

18618 files have been read.
18618 files have been checked.
15818 files have been scanned.
18209 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 07:57:06
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 07:57:06, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 07:42:24
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop

18618 files have been read.
18618 files have been checked.
15818 files have been scanned.
18209 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 07:57:06 14 minutes 41 seconds (881.35 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 07:57:06, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 07:42:24
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Administrator\Desktop

18618 files have been read.
18618 files have been checked.
15818 files have been scanned.
18209 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 07:57:06 14 minutes 41 seconds (881.35 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 07:57:06, Scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN" has finished running.
2005-10-07, 09:20:06, An error was detected on "D:\System Volume Information\*.*": Access is denied.
2005-10-07, 09:31:41, Running scanner "C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN"...
2005-10-07, 09:36:23, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 09:31:43
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop

11911 files have been read.
11911 files have been checked.
10639 files have been scanned.
12015 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 09:36:23
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 09:36:23, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 09:31:43
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop

11911 files have been read.
11911 files have been checked.
10639 files have been scanned.
12015 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 09:36:23 4 minutes 40 seconds (279.86 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-07, 09:36:23, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/7/2005 09:31:43
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 875 (109647 Patterns) (2005/10/05) (287500)
Command Line: C:\Documents and Settings\Administrator\Desktop\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Documents and Settings\Administrator\Desktop

11911 files have been read.
11911 files have been checked.
10639 files have been scanned.
12015 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/7/2005 09:36:23 4 minutes 40 seconds (279.86 seconds) has elapsed.
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP