AndyManchesta, on Jun 29 2007, 03:12 AM, said:
Hi Concie.
That's looking much better but its likely there's more files on your system that will not show in tools like HijackThis so its best to run a online scanner next, you really need to consider upgrading your version of XP as its well out of date, running Windows without any service packs is very risky as there is far too many security holes which attackers can use to get trojans on your system, if the version of Windows isnt legit then you should look at ways of getting a genuine installation so that you can get it fully updated as it will keep getting infected in its current state, if the version of Windows is legit then visit
http://windowsupdate.microsoft.com/ and get all the available updates then reboot when prompted and keep revisiting until there is no more high priority updates available.
Oh, I did not know that it was that dangerous to not-upgrade. Thing is tho, as of September I can buy winXP cheap, from a student-site. (as my study-year hasnt started yet) So I am going to wait for that. You have certainly convinced me of getting the legit windows, cause I do ofcourse want a save system, and now that I have seen what kind of trouble I can get into without it...
Here are the reports. Before I ran AVG Anti-spyware and Kaspersky, I also ran AVG (free edition). Which Changed and Deleted the following 2 files.
D:\WindowsSystem32\drovers\etc\hosts -> Changed.
D:\System Volume Information\_restore{1F84C355-C0AB..etc}\RP515\A0152687.exe (Trojan horse Generic5.BKW) -> Deleted.
Here's the AVG Anti-Spyware report
----
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 13:47:21 29-6-2007
+ Scan result:
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153123.dll -> Adware.Agent : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153124.dll -> Adware.Agent : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Error during cleaning.
HKU\S-1-5-21-1085031214-725345543-839522115-1003\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153122.exe -> Downloader.Agent.bjc : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153160.exe -> Downloader.Small.tc : Cleaned with backup (quarantined).
D:\Documents and Settings\ernst gooris\Cookies\ernst gooris@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
D:\Documents and Settings\ernst gooris\Cookies\ernst gooris@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
D:\Documents and Settings\ernst gooris\Cookies\ernst gooris@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.7:D:\Documents and Settings\ernst gooris\Application Data\Mozilla\Firefox\Profiles\xzrsivw4.Ernst\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.8:D:\Documents and Settings\ernst gooris\Application Data\Mozilla\Firefox\Profiles\xzrsivw4.Ernst\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.9:D:\Documents and Settings\ernst gooris\Application Data\Mozilla\Firefox\Profiles\xzrsivw4.Ernst\cookies.txt -> TrackingCookie.Netflame : Cleaned.
D:\Documents and Settings\ernst gooris\Cookies\ernst gooris@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Cleaned.
D:\Documents and Settings\ernst gooris\Cookies\ernst gooris@weborama[1].txt -> TrackingCookie.Weborama : Cleaned.
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153142.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153143.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153144.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153145.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153146.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153147.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153148.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153149.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153150.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153151.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153152.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153153.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153154.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153155.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153156.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153157.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153158.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153159.exe -> Trojan.DNSChanger.hd : Cleaned with backup (quarantined).
D:\Program Files\BitLord\Downloads\SONY.Vegas.6.0c.FULL.Include.Keymaker-PDX.zip/KEYGEN/SONYkeygen.exe -> Trojan.Pakes.edg : Cleaned with backup (quarantined).
D:\Vegas install\KEYGEN\SONYkeygen.exe -> Trojan.Pakes.edg : Cleaned with backup (quarantined).
::Report end
----
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, June 29, 2007 3:24:41 PM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 29/06/2007
Kaspersky Anti-Virus database records: 355352
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 69882
Number of viruses found: 11
Number of infected objects: 70 / 0
Number of suspicious objects: 0
Duration of the scan process: 01:02:50
Infected Object Name / Virus Name / Last Action
C:\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\SmitfraudFix.exe RarSFX: infected - 2 skipped
D:\WINDOWS\system32\config\SECURITY Object is locked skipped
D:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
D:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
D:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
D:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
D:\WINDOWS\system32\config\SAM Object is locked skipped
D:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
D:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
D:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
D:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
D:\WINDOWS\system32\config\system Object is locked skipped
D:\WINDOWS\system32\config\software Object is locked skipped
D:\WINDOWS\system32\config\default Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
D:\WINDOWS\system32\lmpuy.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\WINDOWS\Temp\ZLT020b2.TMP Object is locked skipped
D:\WINDOWS\Temp\ZLT020c9.TMP Object is locked skipped
D:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
D:\WINDOWS\Debug\oakley.log Object is locked skipped
D:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
D:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
D:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
D:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
D:\WINDOWS\Internet Logs\ERNST.ldb Object is locked skipped
D:\WINDOWS\SchedLgU.Txt Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
D:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
D:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
D:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
D:\Documents and Settings\ernst gooris\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\ernst gooris\NTUSER.DAT.LOG Object is locked skipped
D:\Documents and Settings\ernst gooris\Local Settings\Temp\~DFBAF6.tmp Object is locked skipped
D:\Documents and Settings\ernst gooris\Local Settings\Temp\Perflib_Perfdata_d8.dat Object is locked skipped
D:\Documents and Settings\ernst gooris\Local Settings\Temp\Perflib_Perfdata_af0.dat Object is locked skipped
D:\Documents and Settings\ernst gooris\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
D:\Documents and Settings\ernst gooris\Local Settings\Geschiedenis\History.IE5\MSHist012007062920070630\index.dat Object is locked skipped
D:\Documents and Settings\ernst gooris\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Documents and Settings\ernst gooris\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\ernst gooris\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\ernst gooris\Mijn documenten\other stuff\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
D:\Documents and Settings\ernst gooris\Mijn documenten\other stuff\mirc616.exe mIRC: infected - 1 skipped
D:\Documents and Settings\ernst gooris\Bureaublad\Security\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
D:\Documents and Settings\ernst gooris\Bureaublad\Security\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
D:\Documents and Settings\ernst gooris\Bureaublad\Security\SmitfraudFix.exe RarSFX: infected - 2 skipped
D:\Documents and Settings\ernst gooris\Bureaublad\Security\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
D:\Documents and Settings\ernst gooris\Cookies\index.dat Object is locked skipped
D:\Documents and Settings\ernst gooris\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-1de9bb6a-1cd3a952.zip.bac_a02936/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-1de9bb6a-1cd3a952.zip.bac_a02936/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-1de9bb6a-1cd3a952.zip.bac_a02936/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-1de9bb6a-1cd3a952.zip.bac_a02936 ZIP: infected - 3 skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-1de9bb6a-1cd3a952.zip.bac_a02936 CryptFF.b: infected - 3 skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-59e10998-46188dbc.zip.bac_a02936/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-59e10998-46188dbc.zip.bac_a02936/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-59e10998-46188dbc.zip.bac_a02936/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-59e10998-46188dbc.zip.bac_a02936 ZIP: infected - 3 skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-59e10998-46188dbc.zip.bac_a02936 CryptFF.b: infected - 3 skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-652b4e66-1c98baf3.zip.bac_a02936/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-652b4e66-1c98baf3.zip.bac_a02936/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-652b4e66-1c98baf3.zip.bac_a02936/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-652b4e66-1c98baf3.zip.bac_a02936 ZIP: infected - 3 skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\count.jar-652b4e66-1c98baf3.zip.bac_a02936 CryptFF.b: infected - 3 skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\classload.jar-2fa9f21f-4ced6d9b.zip.bac_a02936/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\classload.jar-2fa9f21f-4ced6d9b.zip.bac_a02936/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\classload.jar-2fa9f21f-4ced6d9b.zip.bac_a02936/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\classload.jar-2fa9f21f-4ced6d9b.zip.bac_a02936/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\classload.jar-2fa9f21f-4ced6d9b.zip.bac_a02936 ZIP: infected - 4 skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\classload.jar-2fa9f21f-4ced6d9b.zip.bac_a02936 CryptFF.b: infected - 4 skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\jd1.exe.bac_a02936 Infected: Trojan.Win32.OpenPort.c skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\exefile[1].exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0080033.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0080096.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0080168.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0080234.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0080302.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0080375.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0080414.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0080429.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\MFEX-1.DAT.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0080474.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0080500.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0080566.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0080646.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0081646.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0081665.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0081706.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\.housecall\Quarantine\A0081717.exe.bac_a02936 Infected: Trojan-Downloader.Win32.Small.cis skipped
D:\Documents and Settings\ernst gooris\UserData\index.dat Object is locked skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP502\A0149239.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP502\A0149257.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP503\A0149304.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP504\A0149350.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP505\A0149386.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP508\A0150386.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP510\A0150475.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP511\A0151476.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP514\A0152479.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP514\A0152544.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP514\A0152579.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP514\A0152591.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP515\A0152646.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP515\A0152676.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP515\A0152694.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0152779.exe/data0007 Infected: Trojan-Downloader.Win32.Agent.bjc skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0152779.exe NSIS: infected - 1 skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0152977.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP516\A0153004.exe Infected: Trojan.Win32.DNSChanger.fb skipped
D:\System Volume Information\_restore{1F84C355-C0AB-45ED-B26D-8D8C00FD9195}\RP517\change.log Object is locked skipped
D:\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
Scan process completed.
----
Seems like a lot of problems..
Thanks again for the help!