|
Re: How to remove Email-Worm.Win32.Rays
Hi Ried,
Sorry for the late reply due to the blackout yesterday while scanning.
I have to continue a new scan this morning.
This is the report from the scan:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, October 12, 2007 10:58:54 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 12/10/2007
Kaspersky Anti-Virus database records: 431168
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 178489
Number of viruses found: 6
Number of infected objects: 150
Number of suspicious objects: 0
Duration of the scan process: 02:05:53
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Admin\Admin.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Admin\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Admin\Staff Matters\Leave Roster\2007\2007.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Admin\Staff Matters\Leave Roster\2007\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Admin\Staff Matters\Leave Roster\2007\Leave Taken 2007.xls Object is locked skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Admin\Staff Matters\Leave Roster\2007\New Microsoft Excel Worksheet.xls Object is locked skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Admin\Staff Matters\Leave Roster\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Admin\Staff Matters\Leave Roster\Leave Roster.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Auction\Auction.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Auction\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Auction\may\Auction Letters\Auction Letters.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Auction\may\Auction Letters\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Auction\may\Auction3\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Auction\may\Auction3A\Auction3A.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Auction\may\Auction3A\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Auction\may\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Auction\may\may.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Database\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Database\Database.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Database\WTWY Data\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Database\WTWY Data\JOB REGISTER 2005.xls Object is locked skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Database\WTWY Data\Thian\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Database\WTWY Data\Thian\Thian.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Database\WTWY Data\WTWY Data.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Database\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Database\Database.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Database\Memo.doc Object is locked skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Database\~WRL0002.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\EstateAgency.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\00Tender Progress\Sale by tender Progress final.xls Object is locked skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0256\0256.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0256\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0264\0264(2)\0264(2).exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0264\0264(2)\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0264\0264.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0264\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0287\0287.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0287\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0292\0292(6)\0292(6).exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0292\0292(6)\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0292\0292.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0292\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0327\0327(3)\0327(3).exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0327\0327(3)\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0327\0327.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0327\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0345\0345.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0345\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0354\0354(3)\0354(3).exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0354\0354(3)\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0354\0354(4)\0354(4).exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0354\0354(4)\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0354\0354.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0354\03544\03544.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0354\03544\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0354\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0397\0397.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0397\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0398\0398.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0398\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0399\0399.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0399\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0400\0400.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0400\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0401\0401.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0401\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0402\0402.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\0402\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\New Folder\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\New Folder\New Folder.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\New Folder (2)\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\New Folder (2)\New Folder (2).exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\EstateAgency\Sale by Tender\Sale by Tender.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Library\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Library\free soft\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Library\free soft\dc400\comment.htt Infected: Trojan.VBS.Starter.a skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Library\free soft\dc400\dc400.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Library\free soft\free soft.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\Library\Library.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Desktop\SA50\sa50.exe Infected: Email-Worm.Win32.Rays skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012007101120071012\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\~DFD2B6.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Comodo\Comodo AntiVirus\TroubleShootLog\cavasm.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Comodo\Comodo AntiVirus\TroubleShootLog\monln.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\WTWY\Local Settings\Temp\Temporary Directory 1 for make up call (uncensored).zip\setup.exe/data0006/stream/data0004 Infected: not-a-virus:AdWare.Win32.BHO.ha skipped
C:\Documents and Settings\WTWY\Local Settings\Temp\Temporary Directory 1 for make up call (uncensored).zip\setup.exe/data0006/stream Infected: not-a-virus:AdWare.Win32.BHO.ha skipped
C:\Documents and Settings\WTWY\Local Settings\Temp\Temporary Directory 1 for make up call (uncensored).zip\setup.exe/data0006 Infected: not-a-virus:AdWare.Win32.BHO.ha skipped
C:\Documents and Settings\WTWY\Local Settings\Temp\Temporary Directory 1 for make up call (uncensored).zip\setup.exe NSIS: infected - 3 skipped
C:\Documents and Settings\WTWY\Local Settings\Temporary Internet Files\Content.IE5\T7EQWWB7\whCC-TRAFE7[1].exe/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\WTWY\Local Settings\Temporary Internet Files\Content.IE5\T7EQWWB7\whCC-TRAFE7[1].exe/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\WTWY\Local Settings\Temporary Internet Files\Content.IE5\T7EQWWB7\whCC-TRAFE7[1].exe/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\WTWY\Local Settings\Temporary Internet Files\Content.IE5\T7EQWWB7\whCC-TRAFE7[1].exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\WTWY\Local Settings\Temporary Internet Files\Content.IE5\T7EQWWB7\whCC-TRAFE7[1].exe RarSFX: infected - 4 skipped
C:\Documents and Settings\WTWY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\WTWY\ntuser.dat.LOG Object is locked skipped
C:\Inetpub\wwwroot\db\desktop.ini Object is locked skipped
C:\Inetpub\wwwroot\db\_vti_pvt\botinfs.cnf Object is locked skipped
C:\Inetpub\wwwroot\db\_vti_pvt\bots.cnf Object is locked skipped
C:\Inetpub\wwwroot\db\_vti_pvt\deptodoc.btr Object is locked skipped
C:\Inetpub\wwwroot\db\_vti_pvt\doctodep.btr Object is locked skipped
C:\Inetpub\wwwroot\db\_vti_pvt\fpdbw.ico Object is locked skipped
C:\Inetpub\wwwroot\db\_vti_pvt\linkinfo.btr Object is locked skipped
C:\Inetpub\wwwroot\db\_vti_pvt\service.cnf Object is locked skipped
C:\Inetpub\wwwroot\db\_vti_pvt\service.lck Object is locked skipped
C:\Inetpub\wwwroot\db\_vti_pvt\services.cnf Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\ibdata1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\ib_logfile0 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\ib_logfile1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\SA60.err Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068350.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068351.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068362.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068369.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068389.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068390.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068391.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068392.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068393.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068394.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068398.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068400.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\A0068401.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP333\snapshot\MFEX-5.DAT Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP334\A0068404.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP334\A0068409.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP334\A0068431.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP334\A0068432.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP334\A0068451.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP334\A0068453.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP334\A0068454.exe Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP334\A0068457.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP335\A0068459.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP335\A0068472.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP335\A0068489.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP335\A0068498.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP335\A0068502.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP335\A0068504.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP335\A0068505.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP335\A0068528.dll Infected: not-a-virus:AdWare.Win32.BHO.ha skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP337\A0068620.dll Infected: not-a-virus:AdWare.Win32.Agent.ma skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP337\A0068626.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP337\A0068629.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP337\A0068630.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP338\A0070636.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP338\A0070869.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP338\A0070870.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP339\A0070915.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP339\A0070916.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP339\A0070917.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP339\A0070943.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP339\A0070944.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP339\A0070945.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP339\A0070950.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP339\A0071952.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP339\A0071957.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP339\A0071958.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP339\A0071959.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP339\A0071960.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP340\A0071961.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP340\A0071962.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP340\A0071963.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP342\A0072118.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP342\A0072122.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP342\A0072124.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP342\A0072125.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP342\A0072126.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP342\A0072127.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP345\A0073283.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP345\A0073284.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP345\A0073285.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP345\A0073286.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP345\A0074299.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP346\A0074334.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP346\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{E6140F25-E48A-4F15-B58C-5DEBD0F446C9}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\Logfiles\W3SVC1\ex071012.log Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ib10 Object is locked skipped
C:\WINDOWS\Temp\ib11 Object is locked skipped
C:\WINDOWS\Temp\ib7 Object is locked skipped
C:\WINDOWS\Temp\ib8 Object is locked skipped
C:\WINDOWS\Temp\ib9 Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
|