CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[DONE]Need Help - Possible Rootkit
Goto page Previous  1, 2
 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
ED_H

Trooper
Trooper


Joined: Jul 22, 2006
Posts: 19
Location: USA

PostPosted: Wed Aug 08, 2007 6:14 pm    Post subject:
Reply with quote

PCBruiser here is the link you requested -
http://www.castlecops.com/p977552-Unknown_File_Please_Analyze.html#977552
I will proceed with the other scans and post soon.
Thank you
Ed

Back to top
View users profile Send private message
ED_H

Trooper
Trooper


Joined: Jul 22, 2006
Posts: 19
Location: USA

PostPosted: Wed Aug 08, 2007 10:54 pm    Post subject:
Reply with quote

I can't seem to get Panda to run, I keep getting script errors.
Here are the other logs you asked for.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/08/2007 at 05:28 PM

Application Version : 3.9.1008

Core Rules Database Version : 3281
Trace Rules Database Version: 1292

Scan type : Complete Scan
Total Scan Time : 02:28:33

Memory items scanned : 156
Memory threats detected : 0
Registry items scanned : 6644
Registry threats detected : 0
File items scanned : 50804
File threats detected : 0

Back to top
View users profile Send private message
ED_H

Trooper
Trooper


Joined: Jul 22, 2006
Posts: 19
Location: USA

PostPosted: Wed Aug 08, 2007 10:56 pm    Post subject:
Reply with quote

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:45:08 PM, on 8/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\SageTV\SageTV\SageTVService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Presorium\Frontgate MX\frntgate.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\system32\wwSecure.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.netscape.com/index2.psp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.netscape.com/home/winsearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.netscape.com/index2.psp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [FG1_00] "C:\Program Files\Presorium\Frontgate MX\frntgate.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Search with &Google - C:\Documents and Settings\Ed\Application Data\TuneUp Software\TuneUp Utilities\Web\gsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O16 - DPF: SEAGULL J Walk Java Client 3_3C10 - http://njraccount.njresources.com/jwalk/jwalk_ie.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {38F5F92F-BD40-40DF-A569-6C1FCB638190} (InSPECS3_0 Control) - http://www.mushkin.com/_detect/InSPECS3_0.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1184172650796
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1184172620718
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {9C024426-7859-4B2D-AB4C-B1E370AE7549} - http://us.mcafee.com/Apps/WSC/en-us/WscWlanScannerCtrl.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://americaschoice.lifepics.com/net/Uploader/ImageUploader3.cab
O16 - DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} (Image Uploader Control) - http://americaschoice.lifepics.com/net/Uploader/LPUploader45.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\System32\CTsvcCDA.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: SageTV - SageTV, LLC - C:\Program Files\SageTV\SageTV\SageTVService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

--
End of file - 8421 bytes

Back to top
View users profile Send private message
ED_H

Trooper
Trooper


Joined: Jul 22, 2006
Posts: 19
Location: USA

PostPosted: Wed Aug 08, 2007 11:04 pm    Post subject:
Reply with quote

nosirrah has replied to the other thread about that unknown file.
http://www.castlecops.com/p977552-Unknown_File_Please_Analyze.html#977552

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Fri Aug 10, 2007 2:55 pm    Post subject:
Reply with quote

Hi,

I'm sorry for the delay. We had heavy storms and power problems all day yesterday.

I'm inclined at the moment to leave that file, and assume it is part of TuneUp which it is reported to be, and since it does not execute.

Panda - lots of people have issues running it for some reason - probably several security programs. Let's use this instead.

Download Sysclean Package & save it to your desktop.

  • Create a new folder on drive "C:\" and rename it Sysclean - (C:\Sysclean).
  • Place the sysclean.com inside that folder.
  • Then download the latest Virus Pattern Files - (Pattern files are usually named lptxxx.zip, where xxx is the pattern file number)
  • Extract (unzip) the lptxxx.zip pattern file into the Sysclean folder where you put sysclean.com. (Click here for information on how to extract a file if your not sure how to do this. DO NOT scan yet.
Reboot your computer in SAFE MODE" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Note: Some anti-virus programs such as Avast will alert you to a virus attack when running sysclean so it's best to disable them before going to the next step.

Scan with Sysclean as follows:
  • Open the Sysclean folder and double-click on sysclean.com to start the scanning process.
  • Put a check mark on the "Automatically clean or delete infected files" option by clicking in the checkbox.
  • Click the Advanced >> button.
  • The scan options appear. Select the "Scan all local fixed drives".
  • Click the "Scan button" on the Trend Micro System Cleaner console.
  • It will take some time to complete. Be patient and let it clean whatever it finds.
  • Another MS-DOS window appears containing the log file generated in the System Cleaner folder.
  • To view the log, click the "View button" on the Trend Micro System Cleaner console. The Trend Micro Sysclean Package - Log window appears.
    • The Files Detected section shows the viruses that were detected by System Cleaner.
    • The Files Clean section shows the viruses that were cleaned.
    • The Clean Fail section shows the viruses that were not cleaned.
  • Exit when done, reboot normally and re-enable your anti-virus program.
Instructions with screenshots are here if you need them.

[i]This tool generates a log file (sysclean.log) in the same folder where the scan is completed. When using Sysclean its best to use the Administrator's account or an account with Administrative rights otherwise you will not have the rights to scan some locations. The scanning process may result in "Access Denied" messages for some files. This is normal because these files are protected by the system.


You really need to install a software firewall. This exposes you to many malware exploits you really don't want to have on your system. Please download and install ZoneAlarm Free from here:

http://www.zonealarm.com/store/content/company/products/znalm/freeDownload.jsp

The download you want is the one near the bottom of the page accessed by the radio button called "I only want ZoneAlarm basic protection".

If you would prefer to use a different firewall, two other equally good free ones are Comodo and Sunbelt Personal Firewall (Free). If one of those do not meet your needs, you can try a different one, but check it with me first to make sure it is legitimate firewall software. Given your experience you might prefer to try Comodo or Sunbelt over ZA if you are comfortable using firewalls.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Fri Aug 10, 2007 3:41 pm    Post subject:
Reply with quote

Idea: Change the name of TUKernel.exe to TUKernel.exe.bak and then run TuneUp and let's see if it either complains about the missing file, or creates a new one. If it complains, just close it and change the file name back.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
ED_H

Trooper
Trooper


Joined: Jul 22, 2006
Posts: 19
Location: USA

PostPosted: Fri Aug 10, 2007 4:51 pm    Post subject:
Reply with quote

My boot loader used to have a reference to a Tuneup backup copy of XP. I never used the program to make a backup unless it does it upon installation. I edited the boot.ini file a long while ago to remove it as I use True Image weekly to run a full backup. I keep the last three weeks good backups. I renamed the Tuneup file and rebooted, I started Tuneup and ran several of the sub programs, Tuneup didn't complain nor did it rewrite the .exe. Last evening when I couldn't get Panda to run I did get Kaspersky online to run, and I also ran AVG Anti-Spy in safe mode. Neither found anything. I will post logs from all, including Sysclean. Thanks again for your time and effort! If you are in Ohio or PA. I'm getting your rain today.

KASPERSKY ONLINE SCANNER REPORT
Thursday, August 09, 2007 4:34:46 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 9/08/2007
Kaspersky Anti-Virus database records: 377697


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics
Total number of scanned objects 54673
Number of viruses found 0
Number of infected objects 0
Number of suspicious objects 0
Duration of the scan process 00:43:27

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Avg7\Log\emc.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\Ed\Application Data\Presorium\Frontgate MX\logs\POP3.log Object is locked skipped

C:\Documents and Settings\Ed\Application Data\Webroot\Spy Sweeper\Logs\070808190639.ses Object is locked skipped

C:\Documents and Settings\Ed\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Ed\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped

C:\Documents and Settings\Ed\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped

C:\Documents and Settings\Ed\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Ed\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Ed\Local Settings\Application Data\Yahoo\Widget Engine\Widget Data\Yahoo! Weather\location data.db Object is locked skipped

C:\Documents and Settings\Ed\Local Settings\Application Data\Yahoo\Widget Engine\Widgets DB\widgets.db Object is locked skipped

C:\Documents and Settings\Ed\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Ed\Local Settings\History\History.IE5\MSHist012007080920070810\index.dat Object is locked skipped

C:\Documents and Settings\Ed\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Ed\ntuser.dat Object is locked skipped

C:\Documents and Settings\Ed\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS01C84F28-9125-41F3-AED4-61EAAFE17485.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS03360B4D-991C-4CC5-B665-42C264A5E1AA.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS045F8CCC-C257-4F3C-9269-2A510EBC0B8D.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS05DC84A6-E9D0-4205-96CD-3303F4A3ABF6.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS08B60046-35DF-4910-91AD-839C040FD449.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS09ED3B75-B693-48E7-8763-F3A2EFAE0B59.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0D603C54-788F-4E16-B5C8-B1BD35DA4249.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS15A820D3-A58B-4733-8A75-26213D87D221.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS18020EE9-2DEA-4EE9-A0BD-281743569B6E.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS187F2AF3-7842-4016-8A70-CD1D477DBFC8.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS19F45AE3-3C80-46CB-956B-B870D32CC6B6.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1ACBF890-72EB-4413-8F8C-D5ED114BF7BB.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1D0380F2-97BE-493E-B19B-5C88FC88D6A3.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS219398C1-9061-46D1-ABF2-A581A25D53FA.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2233CC37-2475-49B0-B110-2A3AE879B75B.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS23B048C6-180F-42A9-96BC-FF45C9D49A1A.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS257CF4A2-B28F-4DDD-B904-A48425DCC22F.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS29009B78-5D32-4502-BAD3-3E7B67DF3C1B.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2FCA8C95-E3A7-4207-8F71-5C6C29BB32EA.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS33DDF3A7-17CC-460F-BFEF-57D7FEB48608.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3A1BA5D8-04A7-4EFD-907E-622E078ABF0C.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3F028401-FA33-46DC-8D9C-49B16A452D2B.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4046E2EA-EA79-4FCC-9220-48CEDC69BA17.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS42B6F3AA-1E0E-4E92-9710-4FE995F99F14.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4311FE12-44E7-4A30-A721-AC0538B85A09.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS460BD30C-4D8D-45F4-9770-3BEDED5B9EF5.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4679114B-3BC1-4313-9235-056023E5C28C.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS483BDBDC-65BD-4AF2-A608-50B9442B651E.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS48D506DB-7D1D-4FB3-A905-9864650FF897.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4972187C-A031-4813-AC92-CEFED4C99CDB.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4A2047F0-45AB-46C3-ACCF-E226D41080B7.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4A6134A4-B089-4084-B609-B609E7BC22DD.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4E96653B-3C94-490D-BF28-EFA614D7EBC1.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4EAD9BB2-6FC3-4C89-9573-F0D7325C417A.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5093C89E-0E7F-4B49-8CA3-CC5A02D476E9.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5291DF86-9342-4CA1-8B90-DD3A4AA86D9E.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5726754E-E8BA-41AA-BB40-1516529F4AD0.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5870D6F4-BCD9-4D78-B457-CC4891641437.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5A51EB32-2F3F-401D-87A3-9DEB67E32199.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5A8CA30B-1D3B-4919-8159-825E60FB592D.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5C152DB4-4991-489A-8590-5D10BF8A2617.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS608B522C-08A7-4A08-911A-8723AC0C3F73.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS630B0945-7BBE-46BA-8E87-918829BCB995.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS69320FA2-46C6-4233-B120-014938640220.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS69B37539-CAE0-4759-8779-FE3E5503EECE.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6C30FF65-2504-46BC-88DE-3E97ACDC157D.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7005684A-4DAB-4FBA-AC68-826539954C2A.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7898E5D2-52B2-48EC-9B64-07B7EF9D03F3.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7C4358D6-6223-4DBE-84DE-2C4085EAF435.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7FC1180B-73C4-4C04-9973-9680641F92DB.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS80297C6C-C296-40DE-B079-7B0E0BB8E686.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS806C580B-266D-49CC-917F-809C504482B0.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS808B9144-B118-46A8-9735-CF8A4B8FA5E6.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS80DC9A5F-AA23-4BC3-BA04-E9B5784CD67A.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS81C92DAD-093E-4E40-A1FD-F2F3200353D8.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS81C98E60-8DDF-4722-9744-3C62CD7F657F.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS874CE3D1-79E8-4114-8812-52BE617A7292.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8C78FABC-02C5-4D10-977D-8A380DD21FE6.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8E616BD0-BB4E-4D37-B0E8-796B7D131624.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS93F42407-C2E1-4791-A620-D9C23F86CE5A.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS97E0F4D5-CA56-4918-8A96-1A4DB44BB0D9.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9B6F962C-CCA4-437D-9277-31D4A3F3ABB1.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9C654483-E3C4-46B9-B773-A6C4E968FBC0.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9E84D56C-243E-48B0-A743-1107125607D3.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA5380034-DAF4-4FCB-AA13-E0FCB05625BD.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA6E97DD0-0D87-4870-A0F1-A186BC693FB9.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA7CF17B9-2603-49FB-A46B-04F9F996F6ED.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA8928273-26FF-4F66-B6C6-16C684C0D6F6.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA8B4BB9C-A2B4-4478-84E1-4A35DF7D5915.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAAD3AECB-7E63-4F76-B91B-F161AC0DEBB8.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAAD3E55E-2165-4EBC-B1E0-D55EA7724229.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAD4F3406-3813-4B0A-A9EF-56B928B521CA.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAFAC8902-BA55-4A1A-9657-0117BB8AC760.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB064DA17-C1A3-4CD6-9E20-562FB35C7124.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB6FCA77D-96E1-4A45-BC09-7F963215CBFE.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB8AA74C8-CBC6-4D18-B4DA-960261FAE2F7.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB8FC52BE-30D8-4DFF-897B-0077DF0F6192.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBB2C2CC8-BA23-40F6-B2F0-C7BABA08534B.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC04893FD-0CF9-4BC1-A489-C28D92E91AD5.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC1823243-08ED-42D6-A9BB-056D9CB0D872.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC3B700D9-2F49-4831-9283-65CC27A4AA1C.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC934AFCA-78AD-44B2-B688-3FF226B9337E.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD107B1B5-6515-447D-A660-643D7CECF04C.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDEB3073B-9E23-4392-BE45-0E321D234412.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE38096D6-51E8-4E08-ADC2-6F2DCC49EFCC.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE3A87AD5-6996-474E-946C-14E440B0E617.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE3FE55C3-6F20-4138-BDC3-7FA4C0E1B4EF.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSED608DCC-27DB-4428-BB47-496B048C6DD2.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEDAFDAF1-0AFD-4FBE-9F3F-426E0DE48E64.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF25A59E3-49A8-4AFA-8D12-7736683448BA.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFA2EAC3C-6297-4754-89A4-6EFACD256C69.tmp Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Program Files\SageTV\SageTV\Wiz.bin Object is locked skipped

C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped

C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped

C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped

C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{E29705CB-BA82-4026-80FF-11205BA30858}\RP44\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\DEFAULT Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SYSTEM Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\drivers\atapi.sys Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\Temp\hsperfdata_SYSTEM\1636 Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.

Back to top
View users profile Send private message
ED_H

Trooper
Trooper


Joined: Jul 22, 2006
Posts: 19
Location: USA

PostPosted: Fri Aug 10, 2007 4:56 pm    Post subject:
Reply with quote

I guess I forgot to save the AVG report but it did come up clean. Here is the Sysclean report.



/--------------------------------------------------------------\
| Trend Micro System Cleaner |
| Copyright 2006, Trend Micro, Inc. |
| http://www.antivirus.com |
\--------------------------------------------------------------/


2007-08-10, 11:29:25, Auto-clean mode specified.
2007-08-10, 11:29:25, Running scanner "C:\Sysclean\TSC.BIN"...
2007-08-10, 11:31:03, Scanner "C:\Sysclean\TSC.BIN" has finished running.
2007-08-10, 11:31:03, TSC Log:

2007-08-10, 11:31:27, An error was detected on "C:\System Volume Information\*.*": Access is denied.
2007-08-10, 11:31:43, An error was detected on "D:\System Volume Information\*.*": Access is denied.
2007-08-10, 11:31:44, An error was detected on "E:\System Volume Information\*.*": Access is denied.
2007-08-10, 11:31:44, An error was detected on "F:\System Volume Information\*.*": Access is denied.
2007-08-10, 11:31:44, An error was detected on "G:\System Volume Information\*.*": Access is denied.
2007-08-10, 11:55:27, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 11:31:45
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Sysclean

43165 files have been read.
43165 files have been checked.
39359 files have been scanned.
114615 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 11:55:27
---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 11:55:27, Files Clean:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 11:31:45
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Sysclean

43165 files have been read.
43165 files have been checked.
39359 files have been scanned.
114615 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 11:55:27 23 minutes 31 seconds (1410.81 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 11:55:27, Clean Fail:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 11:31:45
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Sysclean

43165 files have been read.
43165 files have been checked.
39359 files have been scanned.
114615 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 11:55:27 23 minutes 31 seconds (1410.81 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 11:55:27, Scanner "C:\Sysclean\VSCANTM.BIN" has finished running.
2007-08-10, 11:58:07, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 11:55:28
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Sysclean

5122 files have been read.
5122 files have been checked.
5019 files have been scanned.
5082 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 11:58:07
---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 11:58:07, Files Clean:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 11:55:28
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Sysclean

5122 files have been read.
5122 files have been checked.
5019 files have been scanned.
5082 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 11:58:07 2 minutes 29 seconds (148.55 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 11:58:07, Clean Fail:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 11:55:28
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Sysclean

5122 files have been read.
5122 files have been checked.
5019 files have been scanned.
5082 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 11:58:07 2 minutes 29 seconds (148.55 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 11:58:07, Scanner "C:\Sysclean\VSCANTM.BIN" has finished running.
2007-08-10, 12:17:22, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 11:58:07
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 E:\*.* /P=C:\Sysclean

2528 files have been read.
2528 files have been checked.
2059 files have been scanned.
15711 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 12:17:22
---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 12:17:22, Files Clean:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 11:58:07
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 E:\*.* /P=C:\Sysclean

2528 files have been read.
2528 files have been checked.
2059 files have been scanned.
15711 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 12:17:22 19 minutes 15 seconds (1154.31 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 12:17:22, Clean Fail:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 11:58:07
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 E:\*.* /P=C:\Sysclean

2528 files have been read.
2528 files have been checked.
2059 files have been scanned.
15711 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 12:17:22 19 minutes 15 seconds (1154.31 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 12:17:22, Scanner "C:\Sysclean\VSCANTM.BIN" has finished running.
2007-08-10, 12:17:33, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 12:17:22
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 F:\*.* /P=C:\Sysclean

5 files have been read.
5 files have been checked.
2 files have been scanned.
2 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 12:17:33
---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 12:17:33, Files Clean:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 12:17:22
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 F:\*.* /P=C:\Sysclean

5 files have been read.
5 files have been checked.
2 files have been scanned.
2 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 12:17:33 1 second (0.14 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 12:17:33, Clean Fail:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 12:17:22
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 F:\*.* /P=C:\Sysclean

5 files have been read.
5 files have been checked.
2 files have been scanned.
2 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 12:17:33 1 second (0.14 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 12:17:33, Scanner "C:\Sysclean\VSCANTM.BIN" has finished running.
2007-08-10, 12:17:35, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 12:17:33
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 G:\*.* /P=C:\Sysclean

42 files have been read.
42 files have been checked.
5 files have been scanned.
5 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 12:17:35
---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 12:17:35, Files Clean:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 12:17:33
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 G:\*.* /P=C:\Sysclean

42 files have been read.
42 files have been checked.
5 files have been scanned.
5 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 12:17:35 2 seconds (1.95 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 12:17:35, Clean Fail:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 8/10/2007 12:17:33
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 643 (214465 Patterns) (2007/08/09) (464300)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 G:\*.* /P=C:\Sysclean

42 files have been read.
42 files have been checked.
5 files have been scanned.
5 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 8/10/2007 12:17:35 2 seconds (1.95 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2007-08-10, 12:17:35, Scanner "C:\Sysclean\VSCANTM.BIN" has finished running.

Back to top
View users profile Send private message
ED_H

Trooper
Trooper


Joined: Jul 22, 2006
Posts: 19
Location: USA

PostPosted: Fri Aug 10, 2007 4:59 pm    Post subject:
Reply with quote

I need to get cleaned up and go to a wake today and a funeral tomorrow. So I will be out of touch till at least tomorrow night if not Sunday morning. Thank you again and I will check back ASAP.

Ed

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Fri Aug 10, 2007 5:21 pm    Post subject:
Reply with quote

It's all clean, totally clean. There's no evidence of any malware including a rootkit. How is your system working now? Has the speed improved since we uninstalled Alcohol?


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
ED_H

Trooper
Trooper


Joined: Jul 22, 2006
Posts: 19
Location: USA

PostPosted: Sun Aug 12, 2007 11:09 pm    Post subject:
Reply with quote

PCBruiser,
I would like to thank you again for your time and patience helping me.
My system is a little faster, not a huge difference. I probably should consider reloading windows sometime in the not too distant future, the last time I did a reload was quite some time ago. I will reinstall Zone Alarm in the meantime. I used to use it and ended up removing it due to too many conflicts. I'll try it again. Working with you on this has allowed me to find some good scanning software and although I still have no idea what I'm looking at as far as the HJT and RKU logs I know where to look for help.
Thanks again,
Ed

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer