Brief overview: It appears that a virus infected the computer and now will not allow .exe programs to run. We noticed a popup of "Winviruspro" always coming up. We purchased Norton Antivirus and ran it. It found several virus and we deleted them. When we did .exe programs quit running. Per the Email from chaufferu2 we completed the 5 steps with these results. Also added additional comment at the very end of this message.
Step 1 Could not perform. Got the following error message.
This file does not have a program associated with it for performing this action. Create an association in the folder options control panel.
Step 2 attached panda log:
ANALYSIS: 2008-06-13 10:54:21
PROTECTIONS: 1
MALWARE: 35
SUSPECTS: 12
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
Norton AntiVirus 15.0.0.58 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00518224 Application/SecureCleaner HackTools No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0054028.dll
00521098 Application/SecureCleaner HackTools No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0054029.dll
00716072 Adware/IST Adware No 0 No No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059097.exe[SBTVSetup.exe][SBTVHelper.dll]
00716072 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP581\A0052280.dll
00901730 Generic Malware Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059100.dll
00902199 Generic Malware Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059098.dll
00902206 Generic Malware Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059108.dll
00902341 Generic Malware Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059106.dll
00984992 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP581\A0052276.dll
00985682 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059113.dll
01020628 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059112.dll
01020699 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059099.dll
01042717 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059110.dll
01047005 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059115.dll
01047013 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059114.dll
01047019 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059116.dll
01047020 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059105.dll
01300662 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059117.dll
01692614 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059104.dll
02206125 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059103.exe
02861848 Application/SecureCleaner HackTools No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0054027.dll
02883259 Application/LiveAntiSpy HackTools No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0054025.exe
02892061 Adware/Zango Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP581\A0052273.exe
02917677 Adware/IST Adware No 0 Yes No C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059107.exe
02990522 Generic Malware Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0054024.exe
02990522 Generic Malware Virus/Trojan No 0 Yes Yes C:\Documents and Settings\Mel\Local Settings\Temp\Install.exe
02990522 Generic Malware Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0050237.exe
02994886 Trj/Autorun.WQ Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0050236.exe
02994886 Trj/Autorun.WQ Virus/Trojan No 1 Yes Yes C:\Documents and Settings\Mel\Local Settings\Temp\3324.tmp
02994886 Trj/Autorun.WQ Virus/Trojan No 1 Yes Yes C:\Documents and Settings\Mel\Local Settings\Temp\72E6.tmp
02994886 Trj/Autorun.WQ Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0050220.exe
02995119 Trj/Agent.IVZ Virus/Trojan No 0 Yes Yes C:\WINDOWS\Temp\NTA032.exe
02995119 Trj/Agent.IVZ Virus/Trojan No 0 Yes Yes C:\WINDOWS\Temp\NTDC9632.exe
02995207 Trj/Downloader.TUB Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP581\A0052275.exe
02995207 Trj/Downloader.TUB Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP581\A0052274.exe
02995207 Trj/Downloader.TUB Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0058993.exe
02995207 Trj/Downloader.TUB Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP583\A0052887.exe
02995207 Trj/Downloader.TUB Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0051253.exe
03007679 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\WINDOWS\SYSTEM32\DRIVERS\clbdriver.sys
03007679 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0050234.sys
03007682 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP581\A0052279.dll
03009150 Trj/Downloader.TVK Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP590\A0061604.exe
03009150 Trj/Downloader.TVK Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP590\A0061606.exe
03009150 Trj/Downloader.TVK Virus/Trojan No 0 Yes Yes C:\RECYCLER\S-1-5-21-2998895352-2177372474-286818211-1007\Dc12.exe
03009150 Trj/Downloader.TVK Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP590\A0061611.exe
03009150 Trj/Downloader.TVK Virus/Trojan No 0 Yes Yes C:\Documents and Settings\Mel\Local Settings\Temp\11DA.tmp
03020331 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0051252.exe
03021297 Generic Trojan Virus/Trojan No 0 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP590\A0061457.exe
03021298 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP589\A0059228.exe
03021298 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0052919.exe
03021298 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0053973.exe
03021298 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0053972.exe
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0053939.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0053929.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0053928.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0052929.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0052928.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0053964.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP585\A0054057.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP585\A0054058.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP586\A0055772.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP586\A0055773.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP587\A0056446.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP587\A0056447.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP587\A0056458.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP587\A0056459.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP587\A0056462.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0058980.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0058981.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0053953.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0058998.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059007.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059012.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059026.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP588\A0059027.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0052915.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP583\A0052888.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP581\A0052281.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0052263.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0052259.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0051260.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0051259.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0053951.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0051246.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0051245.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0050231.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0050228.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0050217.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0050216.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0050203.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0050202.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0049203.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0052916.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0053941.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0049202.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP590\A0061605.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0049193.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP580\A0049192.dll
03064404 Trj/Downloader.MDW Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP584\A0053965.dll
03065392 Trj/SubSys.C Virus/Trojan No 1 Yes Yes C:\Documents and Settings\Mel\Local Settings\Temp\1EB7.tmp
03065392 Trj/SubSys.C Virus/Trojan No 1 Yes Yes C:\Documents and Settings\Mel\Local Settings\Temp\5FC.tmp
;===================================================================================================================================================================================
SUSPECTS
Sent Location o
;===================================================================================================================================================================================
No C:\WINDOWS\SYSTEM32\CLBCATQ.DLL o
No C:\WINDOWS\SYSTEM32\CRYPT16.EXE o
No C:\Program Files\Common Files\Real\Plugins\clbascauth.dll o
No C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex.dll o
No C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatq.dll o
No C:\WINDOWS\$NtServicePackUninstall$\clbcatex.dll o
No C:\WINDOWS\$NtServicePackUninstall$\clbcatq.dll o
No C:\WINDOWS\$NtUninstallKB902400$\clbcatex.dll o
No C:\WINDOWS\$NtUninstallKB902400$\clbcatq.dll o
No C:\WINDOWS\ServicePackFiles\i386\clbcatex.dll o
No C:\WINDOWS\ServicePackFiles\i386\clbcatq.dll o
No C:\WINDOWS\SYSTEM32\clbcatex.dll o
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description o
;===================================================================================================================================================================================
;===================================================================================================================================================================================
Step 3:Could not install error message:
Windows cannot open file:
File: spywareblastersetup42[2]
To open this filewindows needs to know what program created it.
Tried to install Zonedout error message:
This file does not have a program associated with it for performing this action. Create an association in the folder options control panel.
Other important observations.
On the desk top I keep getting the following. First this message:
WLAN_CFG
Access violation at address 7C911e58 in module 'ntdll.ll' Read of address 00000000
When I click OK I get the following error:
WUSB54GL.exe - Application Error
The exception unkown softwart exception (0xc0000026) occured in the application at location 0x7c94eac0
Click ok to Terminate the Program
Click on Cancel to debug the program
I have clicked on cancel to debug, but there is no effect.
Thanks so much for your time. This is my mothers computer and being retired her main form of entertainment. Again Thanks So Much
Tom Griesbach