Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [FIXED] Yet more malware.... Anyone have time to help delete it?

[Fixed] Hijackthis! Logs - [FIXED] Yet more malware.... Anyone have time to help delete it? posted in the Security & Safety forums; OK, I will follow those steps. Here is the Kaspersky log: ------------------------------------------------------------------------------- KASPERSKY ON-LINE SCANNER REPORT Wednesday, September 21, 2005 13:55:22 Operating System: Microsoft Windows XP Professional, Service Pack 2 ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #7  
Old 09-21-2005
conversee's Avatar
Bronze Member
 
Join Date: Aug 2005
Posts: 74
conversee - See this Members User comments on their Profile page
Default Re: Yet more malware.... Anyone have time to help delete it?

OK, I will follow those steps.

Here is the Kaspersky log:

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, September 21, 2005 13:55:22
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 21/09/2005
Kaspersky Anti-Virus database records: 141384
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 92310
Number of viruses found: 27
Number of infected objects: 432
Number of suspicious objects: 0
Duration of the scan process: 4278 sec

Infected Object Name - Virus Name
C:\RECYCLER\NPROTECT\00515640 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515642 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515643 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515644 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515645/data0000 Infected: Trojan.Win32.SecondThought.aa
C:\RECYCLER\NPROTECT\00515645 Infected: Trojan.Win32.SecondThought.aa
C:\RECYCLER\NPROTECT\00515646 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515647 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515648 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515649 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515650 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515651 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515653 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515654 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515656 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515657 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515658 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515659 Infected: Trojan-Downloader.Win32.Agent.ap
C:\RECYCLER\NPROTECT\00515660 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515661 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515662 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515663 Infected: Trojan.Win32.HideProc.a
C:\RECYCLER\NPROTECT\00515664 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515666 Infected: Trojan-Downloader.Win32.IstBar.fr
C:\RECYCLER\NPROTECT\00515669 Infected: Trojan-Downloader.Win32.IstBar.gen
C:\RECYCLER\NPROTECT\00515670 Infected: Trojan-Downloader.Win32.Agent.an
C:\RECYCLER\NPROTECT\00515671 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515672 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515673 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515674 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515675 Infected: Trojan.Win32.HideProc.a
C:\RECYCLER\NPROTECT\00515676 Infected: Trojan-Downloader.Win32.Agent.ck
C:\RECYCLER\NPROTECT\00515677 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515678 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515679 Infected: Trojan-Downloader.Win32.VB.em
C:\RECYCLER\NPROTECT\00515680 Infected: Trojan-Downloader.Win32.Agent.bc
C:\RECYCLER\NPROTECT\00515681 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515682 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515683 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515684 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515685 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515686 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515687 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515688 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515689 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515690 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515691 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515692 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515693 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515694 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515695 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515696 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515697 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515698 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515699 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515701 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515702 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515703 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515705 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515706 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515707 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515708 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515709 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515710 Infected: Trojan-Downloader.Win32.VB.em
C:\RECYCLER\NPROTECT\00515711 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515712 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515713 Infected: Trojan-Downloader.Win32.Agent.an
C:\RECYCLER\NPROTECT\00515716 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515717 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515718 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515719 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515720 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515721 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515722 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515725 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515727 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515728 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515729 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515730 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515731 Infected: Trojan-Downloader.Win32.Agent.bc
C:\RECYCLER\NPROTECT\00515732 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515733 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515734 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515736/data0002 Infected: Trojan.Win32.Septic.a
C:\RECYCLER\NPROTECT\00515736 Infected: Trojan.Win32.Septic.a
C:\RECYCLER\NPROTECT\00515738 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515739 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515740 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515741 Infected: Trojan-Downloader.Win32.Agent.ck
C:\RECYCLER\NPROTECT\00515743 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515744 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515746 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515747 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515748 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515749 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515750 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515751 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515752 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515753 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515755 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515756 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515757 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515758 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515759 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515760 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515761 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515763 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515764 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515765 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515766 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515767.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c
C:\RECYCLER\NPROTECT\00515767.zip/InsecureClassLoader.class Infected: Exploit.Java.Bytverify
C:\RECYCLER\NPROTECT\00515767.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a
C:\RECYCLER\NPROTECT\00515767.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v
C:\RECYCLER\NPROTECT\00515767.zip Infected: Trojan-Downloader.Java.OpenConnection.v
C:\RECYCLER\NPROTECT\00515768 Infected: Trojan-Downloader.Win32.VB.em
C:\RECYCLER\NPROTECT\00515769 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515770 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515771 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515772 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515773 Infected: Trojan-Downloader.Win32.Agent.an
C:\RECYCLER\NPROTECT\00515774 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515775 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515777 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515778 Infected: Trojan-Downloader.Win32.Agent.ap
C:\RECYCLER\NPROTECT\00515779 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515781 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515782 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515783 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515784 Infected: Trojan-Downloader.Win32.Agent.ap
C:\RECYCLER\NPROTECT\00515785 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515786 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515787 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515788 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515789/data0002 Infected: Trojan.Win32.Agent.az
C:\RECYCLER\NPROTECT\00515789 Infected: Trojan.Win32.Agent.az
C:\RECYCLER\NPROTECT\00515790 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515791 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515792 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515793 Infected: Trojan-Downloader.Win32.Agent.ap
C:\RECYCLER\NPROTECT\00515794 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515795 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515796 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515797 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515798 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515799 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515800 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515801 Infected: Trojan-Downloader.Win32.Agent.ap
C:\RECYCLER\NPROTECT\00515802 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515803 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515804 Infected: Trojan.Win32.SecondThought.aa
C:\RECYCLER\NPROTECT\00515805 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515806 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515807 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515808 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515809 Infected: Trojan-Downloader.Win32.Agent.cd
C:\RECYCLER\NPROTECT\00515810 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515811 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515812 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515813 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515814 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515816 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515817 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515818 Infected: Trojan-Downloader.Win32.VB.em
C:\RECYCLER\NPROTECT\00515819 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515820 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515821 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515822 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515823 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515824 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515825 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515826 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515827 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515828 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515829 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515830 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515831 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515832 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515833 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515834 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515835 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515836 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515838 Infected: Trojan-Downloader.Win32.Agent.ap
C:\RECYCLER\NPROTECT\00515839 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515840 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515841 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515842 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515843 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515844 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515845 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515846 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515847 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515848 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515849 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515850 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515851 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515852 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515853 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515854 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515855 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515856 Infected: Trojan-Downloader.Win32.IstBar.ga
C:\RECYCLER\NPROTECT\00515857 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515858 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515859 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515860 Infected: Trojan-Downloader.Win32.Agent.ap
C:\RECYCLER\NPROTECT\00515861 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515862 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515863 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515864 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515865 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515866 Infected: Backdoor.Win32.VB.oq
C:\RECYCLER\NPROTECT\00515867 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515868 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515869 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515870 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515871 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515872 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515873 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515874 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515875 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515876 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515877 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515878 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515879 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515880 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515881 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515882 Infected: Trojan-Downloader.Win32.Agent.ae
C:\RECYCLER\NPROTECT\00515883 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515884 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515885 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515886 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515887 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515888 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515889 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515890 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515891 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515893 Infected: Trojan.Win32.Agent.az
C:\RECYCLER\NPROTECT\00515894 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515895 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515896 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515897 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515898 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515899 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515900 Infected: Trojan.Win32.HideProc.a
C:\RECYCLER\NPROTECT\00515901 Infected: Backdoor.Win32.VB.oq
C:\RECYCLER\NPROTECT\00515903 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515904 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515905 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515906 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515908 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515909 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515910 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515912 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515913 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515914 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515915 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515916 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515917 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515918 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515919 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515920 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515921 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515922 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515923 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515924 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515925 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515926 Infected: Trojan-Downloader.Win32.Agent.ck
C:\RECYCLER\NPROTECT\00515927 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515928 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515929 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515930 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515931 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515932 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515933 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515934 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515935 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515938 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515939 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515940 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515941 Infected: Trojan-Downloader.Win32.VB.em
C:\RECYCLER\NPROTECT\00515942 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515943 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515945 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515946 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515947 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515948 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515949 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515950 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515952 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515953 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515954 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515955 Infected: Trojan-Downloader.Win32.Agent.an
C:\RECYCLER\NPROTECT\00515956 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515957 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515959 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515960 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515961 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515962/data0002/data0004 Infected: Backdoor.Win32.VB.oq
C:\RECYCLER\NPROTECT\00515962/data0002/data0006 Infected: Backdoor.Win32.VB.nb
C:\RECYCLER\NPROTECT\00515962/data0002 Infected: Backdoor.Win32.VB.nb
C:\RECYCLER\NPROTECT\00515962/data0010/data0002 Infected: Trojan.Win32.Septic.a
C:\RECYCLER\NPROTECT\00515962/data0010 Infected: Trojan.Win32.Septic.a
C:\RECYCLER\NPROTECT\00515962/data0005/data0010 Infected: Trojan.Win32.Runner.d
C:\RECYCLER\NPROTECT\00515962/data0005/data0012 Infected: Trojan.Win32.VB.od
C:\RECYCLER\NPROTECT\00515962/data0005 Infected: Trojan.Win32.VB.od
C:\RECYCLER\NPROTECT\00515962 Infected: Trojan.Win32.VB.od
C:\RECYCLER\NPROTECT\00515963 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515964 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515965 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515966 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515967 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515968/data0002 Infected: Trojan.Win32.Septic.a
C:\RECYCLER\NPROTECT\00515968 Infected: Trojan.Win32.Septic.a
C:\RECYCLER\NPROTECT\00515969 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515970 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515971 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515972 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515973 Infected: Trojan-Downloader.Win32.Agent.an
C:\RECYCLER\NPROTECT\00515974 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515975 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515976 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515977 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515978 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515979 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515980 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515981 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515982 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515983 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00515984 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515985 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515986 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515987 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00515988 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515989 Infected: Trojan-Downloader.Win32.VB.em
C:\RECYCLER\NPROTECT\00515990 Infected: Trojan-Downloader.Win32.IstBar.gen
C:\RECYCLER\NPROTECT\00515991 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515992 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515993 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515994 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515995 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00515996 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515997 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515998 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00515999 Infected: Trojan-Downloader.Win32.Agent.ap
C:\RECYCLER\NPROTECT\00516000 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00516001 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00516002 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00516003 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00516004 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00516005 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00516006 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516007 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516008 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516009 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00516010 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00516011 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516012 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516013 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00516014 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00516015 Infected: Trojan-Downloader.Win32.Agent.ap
C:\RECYCLER\NPROTECT\00516016 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516017 Infected: Backdoor.Win32.VB.oq
C:\RECYCLER\NPROTECT\00516018 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00516020 Infected: Trojan.Win32.HideProc.a
C:\RECYCLER\NPROTECT\00516021 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516022 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516023 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516025 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516026 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516027 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516028 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516029 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516030 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516031 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516032 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516033 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00516034 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516035 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516036 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516039 Infected: Trojan-Downloader.Win32.Agent.cd
C:\RECYCLER\NPROTECT\00516040 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00516041 Infected: Trojan-Downloader.Win32.Agent.cd
C:\RECYCLER\NPROTECT\00516042 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00516043 Infected: Trojan-Downloader.Win32.Agent.al
C:\RECYCLER\NPROTECT\00516044 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00516045 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00516046 Infected: Trojan-Downloader.Win32.Agent.bq
C:\RECYCLER\NPROTECT\00516047 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00516048 Infected: Trojan-Downloader.Win32.Agent.bc
C:\RECYCLER\NPROTECT\00516049 Infected: Backdoor.Win32.Small.dc
C:\RECYCLER\NPROTECT\00516051 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516052 Infected: Trojan-Downloader.Win32.Agent.ap
C:\RECYCLER\NPROTECT\00516053 Infected: Trojan.Win32.Agent.bi
C:\RECYCLER\NPROTECT\00516054 Infected: Trojan-Downloader.Win32.Agent.al
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007552.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007553.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007554.INI:hunojv:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007554.INI:zmmgxw:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007555.exe:obnriw:$DATA Infected: Trojan-Downloader.Win32.Agent.al
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007556.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007557.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007558.EXE:wvnwn:$DATA Infected: Trojan-Downloader.Win32.Agent.al
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007560.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007561.INI:esbkt:$DATA Infected: Trojan-Downloader.Win32.Agent.al
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007562.INI:yyain:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007563.INI:onpdec:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007564.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007565.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007566.exe Infected: Trojan.Win32.Pakes
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007567.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007568.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007569.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007570.exe:exoeho:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007571.INI:vkujf:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007572.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007573.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{4C64E8AF-F2CF-431D-8183-D12CF3F8050F}\RP21\A0007574.PIF:kvdhko:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\Active Setup Log.txt:cwrln:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\DESKTOP.INI:hunojv:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\KB828741.log:vctsw:$DATA Infected: Trojan-Downloader.Win32.Agent.an
C:\WINDOWS\KB832418.log:tmmdc:$DATA Infected: Trojan-Downloader.Win32.Agent.an
C:\WINDOWS\KB842773.log:enfiw:$DATA Infected: Trojan-Downloader.Win32.Agent.al
C:\WINDOWS\KB893803.log:xtalca:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\logfile.txt:salwac:$DATA Infected: Trojan-Downloader.Win32.Agent.al
C:\WINDOWS\ntdtcsetup.log:hpcnp:$DATA Infected: Trojan-Downloader.Win32.Agent.an
C:\WINDOWS\n_elqhzr.log Infected: Trojan-Downloader.Win32.Agent.bq
C:\WINDOWS\n_ikmezs.txt:enoprq:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\ORUN32.ISU:zrqpi:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\Q327979.log:jhjar:$DATA Infected: Trojan-Downloader.Win32.Agent.al
C:\WINDOWS\vminst.log:fkyom:$DATA Infected: Trojan-Downloader.Win32.Agent.bq
C:\WINDOWS\WindowsUpdate.log:eugpq:$DATA Infected: Trojan-Downloader.Win32.Agent.an
C:\WINDOWS\WMSETUP.LOG:sbnwjf:$DATA Infected: Trojan.Win32.Agent.bi

Scan process completed.


__________________
Patti
  #8  
Old 09-21-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: Yet more malware.... Anyone have time to help delete it?



Its not so bad as it looks , most of them are files in Norton nprotect or files in system restore points.
The system restore points are deleted by now i think?

And to disable Nprotect or delete those files:


Empty:

On your desktop, right-click the Norton Protected Recycle Bin, and then click Properties.
On the Recycle Bin tab, Click Empty Protected Files.
Click Purge All.
Click OK.



Or Disable:

On your desktop, right-click the Norton Protected Recycle Bin, and then click Properties.
On the Recycle Bin tab, in the Title field, change the text to "Recycle Bin."
On the Norton Protection tab, uncheck Enable protection.
Click Empty Protected Files.
Click Purge All.
Click OK.

After that manually delete these files:

C:\WINDOWS\Active Setup Log.txt:cwrln:$DATA
C:\WINDOWS\DESKTOP.INI:hunojv:$DATA
C:\WINDOWS\KB828741.log:vctsw:$DATA
C:\WINDOWS\KB832418.log:tmmdc:$DATA
C:\WINDOWS\KB842773.log:enfiw:$DATA
C:\WINDOWS\KB893803.log:xtalca:$DATA
C:\WINDOWS\logfile.txt:salwac:$DATA
C:\WINDOWS\ntdtcsetup.log:hpcnp:$DATA
C:\WINDOWS\n_elqhzr.log
C:\WINDOWS\n_ikmezs.txt:enoprq:$DATA
C:\WINDOWS\ORUN32.ISU:zrqpi:$DATA
C:\WINDOWS\Q327979.log:jhjar:$DATA
C:\WINDOWS\vminst.log:fkyom:$DATA
C:\WINDOWS\WindowsUpdate.log:eugpq:$DATA
C:\WINDOWS\WMSETUP.LOG:sbnwjf:$DATA


and then run an other scan to see if youre clean.



__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #9  
Old 09-22-2005
conversee's Avatar
Bronze Member
 
Join Date: Aug 2005
Posts: 74
conversee - See this Members User comments on their Profile page
Default Re: Yet more malware.... Anyone have time to help delete it?

Okey Dokey- Heres where I am :

I undestand how to delete the restore points from the active scan, but can find no program on my hard disk called System Volume Restore (I looked in My computer/Hard Disk) .

I got rid of the the two items from HJT using Safe Mode:
O4 - Global Startup: hpoddt01.exe.lnk = ?
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD

Hidden files and folders are set to shown, but still can not locate:
C:\PROGRAM FILES\QuickSearch ? ? ? ? ? ? ? ?
C:\WINDOWS\sdkub32.exe ? ?

I did try to fix some of this stuff before asking for help (Thought I remembered enoutgh to do it myself- NOPE) and was success ful in deleting a couple of items, these were probobly them

Back to the Restore points for the Activescan, I am not sure how locate the exactsearch or memorywatcher. They both just show location as Windows Registry


I followed your last set of instructions. I think because I removed Norton a while back that I no longer have a Norton Recycle Bin. When I open the recycle bin on the desktop, it is just a normal windows one and has no protected tab so I was unable to purge those protected files. I did however empty what was there.

I manually deleted the files you set out, but coudl not find one of them : C:\WINDOWS\n_elqhzr.log ?

Also, the itme: ?C:\WINDOWS\WindowsUpdate.log:eugpq:$DATA ?could not be deleted because it was being used by a nothe person or program. (However I did not have anything else running) so I am not sure what was using it)










__________________
Patti
  #10  
Old 09-22-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: Yet more malware.... Anyone have time to help delete it?


System restore is part of windows and if you have followed all the instructions i posted then they should be deleted by now , to disable system restore:

And to remove those restore points:

Click the Start button.
Right-click My Computer, and then click Properties.
On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.

After youre done with the cleanup you can enable it again.
When you disable system restore then the restore points get deleted automaticly.


Lets see if we can delete those Nprotect files manually:

1.On the Tools menu in Windows Explorer, click Folder Options.
2.Click the View tab.
3.Remove the check in front of "hide protected operating system files"
4.If you see a warning message, click Yes.
5.Click Apply.
6.Click OK.

Then go to :

C:\RECYCLER

and delete the folder "Nprotect" inside.

(and then "hide" the protected system files again.)


And then run an other KASPERSKY scan to see whats left.




__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #11  
Old 09-22-2005
conversee's Avatar
Bronze Member
 
Join Date: Aug 2005
Posts: 74
conversee - See this Members User comments on their Profile page
Default Re: Yet more malware.... Anyone have time to help delete it?

Ok, Yes I did turn off system restore I while ago. I did not get that the points are automatically deleted at that time.


I was unable to dlete the N protect file. I got the error message below whne I tried to do it.


I will wait to run another Kaspersky until I can delet the file.

Thank you!

Patti


__________________
Patti
  #12  
Old 09-22-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: Yet more malware.... Anyone have time to help delete it?



See if you can delete the Nprotect folder when youre in safemode , or if that doesnt work try this:

download KillBox by Option^Explicit from HERE


Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box


C:\RECYCLER\NPROTECT


Click the red circle with the white x and allow your computer to reboot.




__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks