Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
Our computer has been running extremely slow the last week or so. There have been lots of pop-ups, etc. I downloaded Windows Live OneCare and ran it 3-4 times back to back. It always had new threats even though it had cleaned up several severe/high/medium risks/viruses. I noticed the last go round that there was one that said it couldn't be cleaned up...I believe it was win/32.Vundo. My computer froze up and I lost the exact description of what it was. I am tired of running that scan, seeing as there must be something it just can't clean, and it taks forever to run. I searched for the virus for solutions and saw a topic from someone that had the same problem that you guys fixed. I am really hoping that you can help me too.
I have read the suggestions and run HiJack this and Deckers, so here they are:
HiJack This:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:45:06 PM, on 10/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
And my Deckers log:
Deckard's System Scanner v20071014.68
Run by office depot on 2007-10-17 20:37:54
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Percentage of Memory in Use: 85% (more than 75%).
Total Physical Memory: 192 MiB (512 MiB recommended).
-- HijackThis (run as office depot.exe) ----------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:39:05 PM, on 10/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\E]
AutoRun\command- E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{04235d60-6c55-11dc-b97d-009096b4c64a}]
AutoRun\command- E:\LaunchU3.exe -a
-- End of Deckard's System Scanner: finished at 2007-10-17 20:42:20 ------------
I am a beginner to doing anything like this but I think I'm a quick learner... hopefully right .
Thanks you guys so much for any help you can give me!
Thanks!
Didn't find the information you thought to find? Check out these Similar Threads
Download VundoFix by Atribune, saving it to your desktop.
Download ComboFix by sUBs from here or here, saving the file to your Desktop.
Right-click on the deldomains.inf file and select Install.
Reboot your computer.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Note: It is possible that VundoFix encounters a file it could not remove. In this case, VundoFix will runonreboot. If that happens, follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.
Finally,
Close all open programs and windows
Double click combofix.exe and follow the prompts.
When finished, it will open a log for you. Post that log, the C:\VundoFix.txt log and a new HijackThis log in your next reply.
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Okay, so I ran everything... and I think that I did it just the way you described. When I right clicked on the DelDomains.inf file and selected install, nothing happened.
Anyways, here is my log created by Combofix:
ComboFix 07-10-17.8@ - office depot 2007-10-17 22:27:49.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.19 [GMT -6:00]
Running from: C:\Documents and Settings\office depot.TOSHIBA-USER\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\check_LSA7.txt
C:\Documents and Settings\office depot.TOSHIBA-USER\Application Data\WinTouch\config.cfg.7768d4c740d5cc464351d089ff54b214
C:\Documents and Settings\office depot.TOSHIBA-USER\Application Data\WinTouch\fusion.cfg.78aa8eaa6307f6940ea031d4e6e92054.9f8dc38b4f6fc0c92 9a7f813cbe25dc8
C:\Documents and Settings\office depot.TOSHIBA-USER\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\office depot.TOSHIBA-USER\Application Data\WinTouch\WinTouch.exe
C:\Documents and Settings\office depot.TOSHIBA-USER\Application Data\WinTouch\WinTouch.exe
C:\Documents and Settings\office depot.TOSHIBA-USER\Application Data\WinTouch\WTUninstaller.exe
C:\Program Files\inetget2
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\iee
C:\Temp\xOe
C:\Temp\xOe\tOasF.log
C:\WINDOWS\b138.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\awtqo.dll
C:\WINDOWS\system32\awtqo.dll
C:\WINDOWS\system32\ccimdecw.dll
C:\WINDOWS\system32\hmntjwqg.dll
C:\WINDOWS\system32\o02PrEz
C:\WINDOWS\system32\oqtwa.bak1
C:\WINDOWS\system32\oqtwa.bak1
C:\WINDOWS\system32\oqtwa.bak2
C:\WINDOWS\system32\oqtwa.bak2
C:\WINDOWS\system32\oqtwa.ini
C:\WINDOWS\system32\oqtwa.ini
C:\WINDOWS\system32\shpisgsj.exe
C:\WINDOWS\system32\vMW02a
C:\WINDOWS\tsitra1000106.exe
C:\WINDOWS\tsitra572.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\E]
AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{04235d60-6c55-11dc-b97d-009096b4c64a}]
AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2007-10-03 21:32:21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-10-18 04:12:06 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
"2007-10-18 04:45:05 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-17 22:42:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-17 22:47:19 - machine was rebooted
.
--- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:13:51 PM, on 10/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
ComboFix 07-10-17.8@ - office depot 2007-10-18 20:16:53.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.43 [GMT -6:00]
Running from: C:\Documents and Settings\office depot.TOSHIBA-USER\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-09-19 to 2007-10-19 )))))))))))))))))))))))))))))))
.
Close all other windows and programs. Now drag the CFScript.txt onto ComboFix.exe and drop it, using the left mouse button. Combofix should run and may reboot the computer when it's done. A log will open when it's complete. Post the contents of that log and a fresh HijackThis log.
Please do not click on the ComboFix window while it is running a scan. This can cause it to stall.
Please note that I have instructed CFScript to collect some files for analysis. This means that at some point, likely after reboot when ComboFix finishes, you will be prompted to allow ComboFix to upload a zip file that was created on your desktop. The zip contains the aforementioned files. Please copy the path shown in the prompt and paste it into the box, then click Send. I'll let you know what to do with them once analyzed. Thanks!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:30:46 PM, on 10/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Here is the Combofix log that was created after it ran when I dropped in the notepad text file you had me create. There was never a zip file that downloaded itself to my desktop and I wasn't prompted to do anything after combofix ran and rebooted...
ComboFix 07-10-17.8@ - office depot 2007-10-18 21:17:06.3 - NTFSx86
Script execution time was exceeded on script "C:\ComboFix\osid.vbs".
Script execution was terminated.
Running from: C:\Documents and Settings\office depot.TOSHIBA-USER\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\office depot.TOSHIBA-USER\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
Please go to jotti and browse to then submit the following file.
C:\Program Files\Common Files\bidispl3.exe
Once submitted, wait for the analysis to complete then copy the results to a blank notepad. Now submit the following file and copy it's results as well.
File: bidispl3.exe
Status: OK
MD5: cb7d341c36079b619c74ea996479ab61
Packers detected: -
Bit9 reports: File not found
Scanner results
Scan taken on 19 Oct 2007 04:13:14 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing
...and the second:
Service
Service load: 0% 100%
File: SM1updtr.dll
Status: OK
MD5: 598fd8a25ab068ef88aac7fcdb6a19e0
Packers detected: -
Bit9 reports: No threat detected (more info)
Scanner results
Scan taken on 19 Oct 2007 04:10:32 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, October 19, 2007 3:47:40 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 19/10/2007
Kaspersky Anti-Virus database records: 439320
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 63933
Number of viruses found: 12
Number of infected objects: 142
Number of suspicious objects: 0
Duration of the scan process: 02:14:34
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-02072007-211553.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_6b8.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Application Data\Microsoft\Windows\rayiou.exe Infected: Trojan-Downloader.Win32.Agent.buo skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{0136BB4A-731D-4010-B006-E6777B17D694} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{06ED1C0E-286B-40FF-9B1B-BE1D88ADF13C} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{0908A7E5-65F8-4A40-903A-FC6C29303E6B} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{093D88D8-9ABB-4C89-B7A6-6B057717119B} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{0A2A2A2D-D2BF-4D80-96D4-24D9B4C965F9} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{0CC1989B-BB99-47CF-9BA2-76F711822FC6} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{11DAB422-8DE2-4542-8784-A48514A32DB3} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{14AE4D86-59D0-428C-8183-AA5C8E3C3FAE} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{16A6E4A6-DC20-40B6-8925-7BEF7BA1ED2F} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{1A5A23A1-E465-43B8-B52C-CB29DEB2F354} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{1CFD6B29-EAB4-40AC-97E6-3C603086B05D} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{1E4C44E9-854D-414A-A091-A53AD81F0317} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{2429A3CF-04EE-402F-86C6-101E2302AA3C} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{26893DEC-4896-4A4B-8227-304B4F751401} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{27C7B74D-E7EA-45D5-93E5-277B360246A2} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{286F184A-2E89-4B1C-BF3F-8B37FB58D847} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{288BA4F2-6C93-42CB-91F4-6366444221CE} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{2C5029F2-AF45-4A8C-A1DB-22A1BC8355D1} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{2E668524-BA1A-48E3-8980-0DA1011ED50E} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{3127E374-6BF4-4269-993D-FE144363FC30} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{31A8F04A-A8A5-45D1-9AC1-19CB974DA110} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{31BF2148-B0CD-48CC-8AEB-9625644C4459} Object is locked skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{32830FF5-0490-488A-ADC4-650273A44C9C} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{3841EBF5-9D1A-41E6-8866-E6A5061DAF7C} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{3878A01E-E800-47EC-B762-D74C2F18BB7B} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{38D224E1-E106-42B2-AAB1-F798BA5483E7} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{38DC6F24-BF8E-49DB-9BD0-F4FBE2701B5A} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{3B76DBA5-1663-4BD0-B847-104152A6A118} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{3C9BDC13-C33A-48DF-BBB9-AB1315048D43} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{3E18DB84-B650-4F21-AF0C-98EC9470BA0B} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{415E1CD3-2BA0-493C-8381-1F6998FC6CEC} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{451FE992-E7BD-4F67-988B-69C398A95D6E} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{47D5E701-56A2-499C-AE05-8B7C9521B08B} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{4DE48971-8A3A-4FA8-AE13-BB58D7F03839} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{506CC36F-394F-4127-AFDA-5F91FFCB475E} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{50B6CC7B-DCB8-413F-83DE-5D4EDD727501} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{5141E9E9-4906-4BF9-AF75-806559D5BB5D} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{52A7668E-33D5-4D76-8BF9-EED7471C0C5C} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{54161AF1-4475-4301-9C01-CD139FD722E3} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{5AED05EE-F401-4985-BF7E-A493AB801D69} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{5B90B6F1-FC5D-479E-973D-9DA748728318} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{5C4EB8DC-ABAD-4DE1-874C-4955F6332F88} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{5EFC5C30-7FDB-467B-919F-689E93953694} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{5F00F9A4-507A-4F23-B2E3-907CB39AAA05} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{629450BE-0D56-43C2-B66B-458E4C43BACD} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{687A2F42-1FAE-4C5D-A07D-DBC4BA4935FA} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{698F57E1-5CBC-4CC6-BF32-A637630E2E06} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{6ADB32E9-EB70-4FE3-85B3-AB31999EEBDD} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{6B2357B0-AAF6-4E3E-AE86-96425304CCCF} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{6B25114F-FEB0-47DD-90FC-81812D56CE67} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{6CEB1DC7-C179-48B1-A1BC-4106612EDFD4} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{6DC6C1DC-A616-4D04-BA6F-905C358AB827} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{6F9D2A48-B86D-4055-A926-429E0F0489C4} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{78C90B12-3394-4D5D-A2D6-E9FB9BE8AFF3} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{79942AE5-13C5-4166-9470-8E87C4D62209} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{7A17C884-1C79-4B48-A772-EFD94AFE9FD9} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{7C000C30-5270-4314-950E-ABEB82833695} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{7D3F1086-5A1E-4178-B1A5-654C6AF4934F} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{7DC4E718-AD65-486C-9233-13C7BCDF6644} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{7EDF6490-1C32-46B6-9244-35745781269F} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{826F723E-B7B7-4E9F-9949-59D564EDC7B8} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{86753E2C-EA0E-499B-89E1-6C888ADE33C4} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{89D67CD2-E03D-4FF4-8199-5FC3894C5C25} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{8A91BD5F-419F-450D-AFDC-CBE2A6B6A98C} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{8BAB3B2C-1756-4DFD-A488-295C78769529} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{8DEB2A25-A5E0-4A0B-B390-6FFE1F0F9F7A} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{8F503393-712B-482A-966A-07267AA214C8} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{924EDEA1-1CF1-4823-9128-4E3E4BBB6971} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{943E4178-2146-462A-B43D-EACF1B496048} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{96FEC635-C862-4A96-82BB-3BCA6EA00802} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{9A3143C9-AD7E-4A70-BCEA-6D9C9989F2BE} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{9B845023-02F1-4921-9D76-6F8D4989FB77} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{9B97C90E-D075-4B82-909A-5D722EFE99C7} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{9CA20025-1135-46AD-8E70-0BBCDB4D2516} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{9E6452CC-A06D-4FA6-BA11-5BE3E4947498} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{9F87368B-09F1-4CE0-9799-DB9C601DD3F2} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{A02C3C5C-A8D7-4ADD-B128-10887E437D57} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{A1465BC4-59D1-421A-8A43-83FE69A1FFC7} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{A5E9ADEB-0FF1-4B17-B112-14A4DE7B97C3} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{A88A50DE-BEBD-4565-90D2-341555B03411} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{A8B8C00E-30CF-4232-BE71-E9C40ACC4165} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{AE4E0062-3B3E-44A5-AFE5-C89B16A691A6} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{B437F49F-FFC6-4402-9298-F687D9871094} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{B4A8AD64-A469-4B74-A536-F6A05AF2896D} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{B6FA1961-3574-4780-8085-32754A9A6B95} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{B73EF7F1-1E21-4F2F-993B-2FA9CF444951} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{B8A14A81-B05C-4A0E-9E3C-5529C7E2FB91} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{BA133754-0BA6-4761-A7E9-BF05A1C40467} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{BB9BC0D4-69B0-4CDB-B034-F5684FAEAFFB} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{BF44C8DD-9CC8-494C-9F2A-5C362A363B01} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{C225908A-E0CC-4891-A389-1F2E3C4FAA35} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{C3DB2DCB-DFA3-4487-801E-638F6599101A} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{C414C02D-0ABA-4D65-BC57-A66FD0AABEE7} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{C51CF59E-B597-4B49-A82E-00EE691154A1} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{C9F42D15-57E6-4C35-8C37-D7A892CEEB84} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{CC6587DA-F6E0-4ABF-8F41-0C26A9F79311} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{CD1C928D-9C5B-4C60-A970-5C2E8F4BD7B5} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{CF99A549-C5CD-4514-8813-470192F865EA} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D06A7893-12DE-4A1F-A877-B44A579A9846} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D0D1A992-C3B1-4A3E-AB7C-277ECCD0E245} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D30EBA05-E6BF-4A09-B744-90C72561A681} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D52A396C-9180-4354-AB78-8BDFBB9DA5A7} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D5C24F1B-A4B9-4306-A6C2-50D7E6AF7265} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D6C302F7-7910-4E5F-907B-0FF559C131D2} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D6F2801B-4027-478D-B8E2-44D7DABC7780} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D7869C8C-F87C-44AE-8C68-EA93758F68D1} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D94EFB67-A00C-42C6-852C-5B5DB48228E0} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{DB9DEFE4-AEED-4F2E-8811-8F7E084C6830} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{DBAA48FE-5405-4CFA-B425-EBA9D4C3556B} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{DD1319EF-0AA3-4D90-93A0-BB5857839809} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{DFDE4427-AB08-4E43-942B-86D54EF6531E} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{E0ADFAB9-A97D-48EA-AEA6-A77BA751E0A1} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{E15ACDBB-763C-43AD-936C-EBFE8B488BEE} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{E1A76A2D-CFA6-4DB6-A727-4CF51A67A74E} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{E244C7A3-DD51-43E9-A929-4B18B8815AC4} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{E3F50071-6FDD-4452-AC30-52898C7EDB69} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{E7F34D49-ABF7-459C-B351-0BF2AD1D64F5} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{EB68F28F-CAA8-4E5E-B2B9-C1E76BF3C244} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{EBA9B984-3E08-44A0-978C-F28F82EEF3B0} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{F61B4177-06B1-4A21-AAB8-514B15BBCA5D} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{F643DC95-949A-488C-964C-22138F4C29A9} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{F7C7AEC5-14D2-4439-84AE-AE3E98BC9D0D} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{FC802548-D094-4282-BE58-AEC1F7D22A87} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{FE720D58-CC6A-4981-91BF-04E03C3D74E9} Infected: Trojan.Win32.Qhost.ha skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Temp\~DF5190.tmp Object is locked skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\office depot.TOSHIBA-USER\ntuser.dat.LOG Object is locked skipped
C:\EXACT.exe Infected: Trojan.Win32.Qhost.bi skipped
C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\master.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\mastlog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\model.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\modellog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdbdata.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdblog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\tempdb.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\templog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\ERRORLOG Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\log_150.trc Object is locked skipped
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\qoobox\Quarantine\C\Documents and Settings\office depot.TOSHIBA-USER\Application Data\WinTouch\WTUninstaller.exe.vir Infected: Trojan-Downloader.Win32.Agent.buo skipped
C:\qoobox\Quarantine\C\Documents and Settings\office depot.TOSHIBA-USER\Application Data\WinTouch.vir\WTUninstaller.exe Infected: Trojan-Downloader.Win32.Agent.buo skipped
C:\qoobox\Quarantine\C\WINDOWS\b138.exe.vir Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\shpisgsj.exe.vir Infected: Trojan.Win32.Agent.bck skipped
C:\qoobox\Quarantine\C\WINDOWS\tsitra1000106.exe.vir Infected: Trojan-Downloader.Win32.Agent.dve skipped
C:\qoobox\Quarantine\C\WINDOWS\tsitra572.exe.vir Infected: Trojan-Downloader.Win32.Agent.ecz skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{28192166-DCD0-4901-AD1A-CB57DD193595}\RP580\A0221503.exe Infected: Trojan-Downloader.Win32.Agent.dve skipped
C:\System Volume Information\_restore{28192166-DCD0-4901-AD1A-CB57DD193595}\RP581\A0221505.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\System Volume Information\_restore{28192166-DCD0-4901-AD1A-CB57DD193595}\RP585\A0222580.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acz skipped
C:\System Volume Information\_restore{28192166-DCD0-4901-AD1A-CB57DD193595}\RP585\A0222583.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acx skipped
C:\System Volume Information\_restore{28192166-DCD0-4901-AD1A-CB57DD193595}\RP585\A0222845.exe Infected: Trojan-Downloader.Win32.Small.fxy skipped
C:\System Volume Information\_restore{28192166-DCD0-4901-AD1A-CB57DD193595}\RP586\A0222991.exe Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\System Volume Information\_restore{28192166-DCD0-4901-AD1A-CB57DD193595}\RP586\A0222992.exe Infected: Trojan-Downloader.Win32.Agent.dve skipped
C:\System Volume Information\_restore{28192166-DCD0-4901-AD1A-CB57DD193595}\RP586\A0222993.exe Infected: Trojan-Downloader.Win32.Agent.ecz skipped
C:\System Volume Information\_restore{28192166-DCD0-4901-AD1A-CB57DD193595}\RP586\A0222994.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{28192166-DCD0-4901-AD1A-CB57DD193595}\RP586\A0222998.exe Infected: Trojan-Downloader.Win32.Agent.buo skipped
C:\System Volume Information\_restore{28192166-DCD0-4901-AD1A-CB57DD193595}\RP587\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallKB822624$\hal.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\user32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\win32k.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\accwiz.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\crypt32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\cryptsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hh.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hhctrl.ocx Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hhsetup.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\html32.cnv Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\itss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\locator.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\magnify.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\migwiz.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\mrxsmb.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\narrator.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\newdev.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ole32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\osk.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\raspptp.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\rpcrt4.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\rpcss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\shell32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\shmedia.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\srrstr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\srv.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\winsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\zipfldr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\dhcpcsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\ndis.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\ndisuio.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\netshell.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\wzcdlg.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\wzcsapi.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\wzcsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828012$\ntkrnlmp.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828012$\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828012$\ntkrnlpa.exe.000 Object is locked skipped
C:\WINDOWS\$NtUninstallKB828012$\ntkrpamp.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828012$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828012$\ntoskrnl.exe.000 Object is locked skipped
C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB830680$\keymgr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB833407$\bssym7.ttf Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
And here is the new HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:50:55 AM, on 10/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Kaspersky scan looks great! Most all of the infected files are either quarantined or in System Restore points, which we will clean up now.
Delete the following files.
C:\EXACT.exe
C:\Documents and Settings\office depot.TOSHIBA-USER\Application Data\Microsoft\Windows\rayiou.exe
C:\WINDOWS\nircmd.exe
Start ComboFix.exe again. At the Disclaimer screen, select option 2. This will uninstall ComboFix and remove the files and folders it created and copied to the system.
Open Windows Defender and remove all of the Quarantined items.
Download ATF Cleaner by Atribune and save it to your Desktop.
Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:
Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Prefetch
Java Cache
Recycle bin
The rest are optional - if you want it to remove everything check "Select All".
Finally, click Empty Selected. When you get the "Done Cleaning" message, click OK.
Reboot
If you're satisfied that the computer is working properly, clear the System Restore points.
Clear past system restore points and create a new one.
Right click My Computer and select Properties. On the System Restore tab, check the box to turn System Restore off. Click Apply. Now, uncheck the box and click Apply. Click OK, then OK to close the System Properties dialog.
Verify a new restore point was created.
Click Start>All Programs>Accessories>System Tools>System Restore
Select 'Restore my computer to an earlier time', then click next.
You should have a newly created System Checkpoint available. If so, click Cancel. If not, click Back and select 'Create a restore point' then click Next. Give the restore point a name and click next.
Were you able to find any information on the 2 files I mentioned in my last post?
Oh yeah, I never did find out anything about those 2 files...because I didn't know how to find out anything. I don't know what my brain is doing, but I know that it's not thinking. I can't for the life of me think how I find those files to delete them.
If you can direct me how to do it, I would love to.
Click Start then My Computer.
Open Local Disk C:
Locate and delete EXACT.exe
Open the Windows folder.
Locate and delete nircmd.exe
Go back to Local Disk C: then open Documents and Settings
Open office depot.TOSHIBA-USER
Open Application Data << if you can't this folder, click here
Open Microsoft
Open Windows
Locate and delete rayiou.exe
Go back to Local Disk C:
Open Program Files
Open Common Files
Locate bidispl3.exe then right click it and select Properties
If there is a Version tab, select it and gather the information for Company, Version, etc.
Close the Properties window then check the properties on SM1updtr.dll