Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.
MalwareByte's Anti-Malware Download

> Forum Guidelines

Read this topic before posting a log.


DO NOT post a ComboFix log unless requested to.


Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.

2 Pages V  < 1 2  
Closed TopicStart new topic
> Two Trojans - Cannot Remove
steamwiz
post Jun 7 2008, 04:15 PM
Post #16


Distinguished Member
*****

Group: HJT Team
Posts: 755
Joined: 14-February 08
Member No.: 190,186



Hi

Number of viruses found: 17
Number of infected objects: 73

All the infected objects are in System Restore ... Combofix should have reset System Restore & therefore deleted all those infected restore points, as it didn't you'll have to do it yourself smile.gif

This will clear all your infected restore points...

Turn off (Disable) System Restore in XP :-

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer.

Then...

Turn on (enable) System Restore :-

Follow the same procedure, but this time uncheck Turn off System Restore

if you have any problem with this... here's a link to instructions :-


Disabling or enabling Windows XP System Restore >

http://service1.symantec.com/SUPPORT/tsgen...src=sec_doc_nam

THEN Please run & post a new KASPERSKY ONLINE SCANNER REPORT (this should be the last one) smile.gif I promise laugh.gif

steam


--------------------
MICROSOFT MVP - Windows Security 2004/9
member of ASAP since 2004
member of U.N.I.T.E

If I have helped you, please consider a small donation to help me continue my online fight in the war against malware
Go to the top of the page
 
+Quote Post
matt8188
post Jun 8 2008, 01:09 PM
Post #17


New Member
*

Group: Members
Posts: 11
Joined: 29-May 08
Member No.: 212,625



Thanks Steam, I followed the instructions, it's reduced it but there still is a few left.

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 08, 2008 7:06:29 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 8/06/2008
Kaspersky Anti-Virus database records: 839368
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 55657
Number of viruses found: 3
Number of infected objects: 34
Number of suspicious objects: 0
Duration of the scan process: 01:56:46

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012008060820080609\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\UserData\index.dat Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS.0\Application Data\avg8\Log\avgcore.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS.0\Application Data\avg8\Log\avglng.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS.0\Application Data\avg8\Log\avgrs.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS.0\Application Data\avg8\Log\avgsched.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS.0\Application Data\avg8\Log\avgui.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS.0\Application Data\avg8\Log\commonpriv.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Kontiki\error.log Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005580.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005581.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005582.sys Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005583.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005584.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005585.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005586.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005587.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005588.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005589.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005590.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005591.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005592.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005593.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005594.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005595.sys Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005596.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005597.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005598.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005599.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP30\A0005600.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005609.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005610.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005611.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005612.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005613.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005614.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005615.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005616.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005617.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005618.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005619.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005620.sys Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005621.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005622.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005623.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005624.sys Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005625.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005626.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005627.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005628.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP31\A0005629.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005638.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005639.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005640.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005641.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005642.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005643.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005644.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005645.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005646.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005647.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005648.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005649.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005650.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005651.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005652.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005653.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005654.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005655.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005656.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005657.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP32\A0005658.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005671.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005672.ocx Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005673.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005674.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005675.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005676.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005677.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005678.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005679.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005680.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005681.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005682.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005683.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005684.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005685.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005686.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005687.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005688.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005689.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005690.ocx Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005691.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005692.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005693.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005694.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005695.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005696.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005697.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005698.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP33\A0005699.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005707.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005708.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005709.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005710.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005711.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005712.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005713.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005714.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005715.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005716.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005717.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005718.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005719.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005720.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005721.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005722.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005723.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005724.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005725.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005726.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP34\A0005727.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005735.sys Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005736.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005737.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005738.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005739.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005740.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005741.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005742.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005743.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005744.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005745.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005746.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005747.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005748.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005749.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005750.sys Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005751.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005752.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005753.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005754.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP35\A0005755.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005782.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005783.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005784.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005785.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005786.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005787.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005788.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005789.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005790.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005791.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005792.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005793.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005794.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005795.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005796.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005797.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005798.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005799.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005800.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP36\A0005801.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP37\A0005813.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP37\A0005814.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP37\A0005815.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP37\A0005816.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP37\A0005817.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP37\A0005818.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP37\A0005819.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP37\A0005820.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP37\A0005821.cnv Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005864.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005865.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005866.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005867.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005868.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005869.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005870.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005871.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005872.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005873.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005874.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005875.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005876.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005877.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005878.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005879.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005880.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005881.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005882.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005883.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005884.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005885.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005886.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005887.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005888.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005889.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005890.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005891.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005892.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005893.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005894.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005895.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005896.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005897.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005898.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005899.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005900.tsp Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005901.TSP Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005902.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005903.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005904.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005905.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005906.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005907.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005908.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005909.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005910.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005911.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005912.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005913.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005914.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005915.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP38\A0005916.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005961.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005962.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005963.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005964.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005965.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005966.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005967.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005968.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005969.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005970.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005971.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005972.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005973.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005974.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005975.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005976.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005977.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005978.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005979.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005980.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005981.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005982.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005983.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005984.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005985.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005986.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005987.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005988.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005989.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005990.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005991.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005992.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005993.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005994.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005995.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005996.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005997.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005998.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0005999.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006000.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006001.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006002.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006003.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006004.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006005.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006006.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006007.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006008.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006009.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006010.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006011.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006012.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006013.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006014.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006015.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006016.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006017.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006018.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP39\A0006019.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000335.exe/EXE-file/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000335.exe/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000335.exe Alloy: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000335.exe ASPack: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000336.exe/EXE-file/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000336.exe/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000336.exe Alloy: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000336.exe ASPack: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000337.exe/EXE-file/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000337.exe/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000337.exe Alloy: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000337.exe ASPack: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000338.exe/EXE-file/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000338.exe/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000338.exe Alloy: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000338.exe ASPack: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000339.exe/EXE-file/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000339.exe/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000339.exe Alloy: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000339.exe ASPack: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000340.exe/EXE-file/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000340.exe/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000340.exe Alloy: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000340.exe ASPack: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000341.exe/data0023/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000341.exe/data0023/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000341.exe/data0023 Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000341.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000345.exe/EXE-file/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000345.exe/EXE-file Infected: not-a-virus:AdWare.Win32.SaveNow.bz skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000345.exe Alloy: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP7\A0000345.exe ASPack: infected - 2 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP72\A0020821.exe/stream Infected: not-a-virus:AdWare.Win32.404Search.h skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP72\A0020821.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000407.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000408.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000409.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000410.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000411.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000412.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000413.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000414.ver Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000415.inf Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000416.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000417.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000418.cat Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000419.exe Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000420.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000421.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000422.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000423.dll Object is locked skipped
C:\System Volume Information\_restore{23BE2802-86DC-4256-A7CD-E40A69872BF0}\RP8\A0000424.cat Object is locked skipped
C:\System Volume Information\_restore{24B0EF11-F7CC-4D8E-BB4F-30C4CCBB5278}\RP1\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\browser.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped
C:\WINDOWS.0\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS.0\Internet Logs\2AF9EE24A8C3405.ldb Object is locked skipped
C:\WINDOWS.0\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS.0\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS.0\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS.0\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS.0\SchedLgU.Txt Object is locked skipped
C:\WINDOWS.0\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS.0\Sti_Trace.log Object is locked skipped
C:\WINDOWS.0\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS.0\system32\config\default Object is locked skipped
C:\WINDOWS.0\system32\config\default.LOG Object is locked skipped
C:\WINDOWS.0\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS.0\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS.0\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS.0\system32\config\SAM Object is locked skipped
C:\WINDOWS.0\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS.0\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS.0\system32\config\SECURITY Object is locked skipped
C:\WINDOWS.0\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS.0\system32\config\software Object is locked skipped
C:\WINDOWS.0\system32\config\software.LOG Object is locked skipped
C:\WINDOWS.0\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS.0\system32\config\system Object is locked skipped
C:\WINDOWS.0\system32\config\system.LOG Object is locked skipped
C:\WINDOWS.0\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS.0\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS.0\system32\drivers\lfhboxfp.dat Object is locked skipped
C:\WINDOWS.0\system32\h323log.txt Object is locked skipped
C:\WINDOWS.0\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS.0\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS.0\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS.0\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS.0\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS.0\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS.0\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS.0\Temp\Perflib_Perfdata_75c.dat Object is locked skipped
C:\WINDOWS.0\Temp\ZLT047a2.TMP Object is locked skipped
C:\WINDOWS.0\Temp\ZLT047af.TMP Object is locked skipped
C:\WINDOWS.0\wiadebug.log Object is locked skipped
C:\WINDOWS.0\wiaservc.log Object is locked skipped
C:\WINDOWS.0\WindowsUpdate.log Object is locked skipped

Scan process completed.
Go to the top of the page
 
+Quote Post
steamwiz
post Jun 8 2008, 04:48 PM
Post #18


Distinguished Member
*****

Group: HJT Team
Posts: 755
Joined: 14-February 08
Member No.: 190,186



Hi

They are all still in system restore ...

There were a lot of infected restore points, now there are just 2 (restore point 7 & 72) all the others were deleted + the first one in restore point7 & the first one in restore point72 ... weird why it didn't purge them all ...

Would you go through the process of turning system restore off & on again please ... then post another KASPERSKY ONLINE SCANNER REPORT ...

steam


--------------------
MICROSOFT MVP - Windows Security 2004/9
member of ASAP since 2004
member of U.N.I.T.E

If I have helped you, please consider a small donation to help me continue my online fight in the war against malware
Go to the top of the page
 
+Quote Post
matt8188
post Jun 9 2008, 07:11 PM
Post #19


New Member
*

Group: Members
Posts: 11
Joined: 29-May 08
Member No.: 212,625



Hi Steam,

I think everything's gone now!! Please let me know if I need to do anything else. Thankyou for your patience and expertise, once I get paid next week I will send you a paypal donation. Many thanks, Matt.

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, June 10, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, June 09, 2008 19:26:50
Records in database: 844518
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Files scanned: 51005
Threat name: 0
Infected objects: 0
Suspicious objects: 0
Duration of the scan: 02:35:01

No malware has been detected. The scan area is clean.

The selected area was scanned.
Go to the top of the page
 
+Quote Post
steamwiz
post Jun 11 2008, 02:56 PM
Post #20


Distinguished Member
*****

Group: HJT Team
Posts: 755
Joined: 14-February 08
Member No.: 190,186



HI Matt

Excellent ... that's what I like to see :-

Infected objects: 0
Suspicious objects: 0

QUOTE
Please let me know if I need to do anything else.


Just follow the recommendations in those links I gave you earlier thumbup2.gif

Simple steps to keep your computer secure! By Grinler > http://www.bleepingcomputer.com/forums/topic1628.html

& here :-

So how did I get infected in the first place? By TonyKlein > http://forums.spybot.info/showthread.php?t=279

Happy surfing smile.gif

steam


--------------------
MICROSOFT MVP - Windows Security 2004/9
member of ASAP since 2004
member of U.N.I.T.E

If I have helped you, please consider a small donation to help me continue my online fight in the war against malware
Go to the top of the page
 
+Quote Post
steamwiz
post Jul 24 2008, 02:35 PM
Post #21


Distinguished Member
*****

Group: HJT Team
Posts: 755
Joined: 14-February 08
Member No.: 190,186



As this thread is resolved, smile.gif it is now locked.

If the original poster would like it re-opened, please send me a PM with a link to this thread.

cheers

steam


--------------------
MICROSOFT MVP - Windows Security 2004/9
member of ASAP since 2004
member of U.N.I.T.E

If I have helped you, please consider a small donation to help me continue my online fight in the war against malware
Go to the top of the page
 
+Quote Post

2 Pages V  < 1 2
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 6th September 2008 - 02:30 AM


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums