Help - Search - Members - Calendar
Full Version: Infected :( ... Bitdefender log
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
MaXPower
here i cant delete those viruses with my bitdefender virusscan here you got the log :

//-----------------------------------------------------------------
//
// Product: BitDefender 8 Professional Plus
// Version: (no ver)
//
// Created on: 18/09/2004 00:34:17
//
//-----------------------------------------------------------------


Statistics

Scan path : C:\
D:\
E:\
F:\
Folders : 3565
Files : 269594
Archives : 1750
Packed files : 28612
Identified viruses : 7
Infected files : 16
Warnings : 0
Suspect files : 0
Disinfected files : 0
Deleted files : 0
Copied files : 0
Moved files : 10
Renamed files : 0
I/O errors : 25
Scan time : 00:44:59
Scan speed (files/sec) : 99

Virus definitions : 91068
Scan plugins : 11
Archive plugins : 37
Unpack plugins : 4
Mail plugins : 6
System plugins : 1

Scan options

Detection
[X] Scan boot sectors
[X] Scan archives
[X] Scan packed files
[X] Scan email

File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;

Action

Infected objects
[ ] Ignore
[X] Disinfect
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[ ] Prompt user

Second action
[ ] Ignore
[ ] Delete
[ ] Copy to quarantine
[X] Move to quarantine
[ ] Rename
[ ] Prompt user

Scan options
[X] Enable warnings
[X] Enable heuristics
[ ] Show all files in log
[X] Report file: vscan.log
[ ] Append to existing report

Summary:

C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-48e68be7.zip=>InsecureClassLoader.class Infected Java.Trojan.Exploit.Bytverify
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-48e68be7.zip=>InsecureClassLoader.class Disinfection failed
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-48e68be7.zip=>Installer.class Infected Java.Trojan.OpenConnection.F
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-48e68be7.zip=>Installer.class Disinfection failed
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-48e68be7.zip Moved
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-4996d387.zip=>GetAccess.class Infected Java.Trojan.Exploit.Bytverify
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-4996d387.zip=>GetAccess.class Disinfection failed
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-4996d387.zip=>Dummy.class Infected Java.Trojan.Exploit.Bytverify
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-4996d387.zip=>Dummy.class Disinfection failed
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-4996d387.zip Moved
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-3a93430c.zip=>InsecureClassLoader.class Infected Java.Trojan.Exploit.Bytverify
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-3a93430c.zip=>InsecureClassLoader.class Disinfection failed
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-3a93430c.zip=>Installer.class Infected Java.Trojan.OpenConnection.F
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-3a93430c.zip=>Installer.class Disinfection failed
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\classload.jar-11faa9ed-3a93430c.zip Moved
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\Counters.jar-6402defc-1303b7d8.zip=>Counter.class Infected Java.Trojan.Exploit.Bytverify
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\Counters.jar-6402defc-1303b7d8.zip=>Counter.class Disinfection failed
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\Counters.jar-6402defc-1303b7d8.zip=>Gummy.class Infected Java.Trojan.Exploit.Bytverify
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\Counters.jar-6402defc-1303b7d8.zip=>Gummy.class Disinfection failed
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\Counters.jar-6402defc-1303b7d8.zip Moved
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\ar3.jar-1199dff7-65bf5b1f.zip=>Gummy.class Infected Java.Trojan.Exploit.Bytverify
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\ar3.jar-1199dff7-65bf5b1f.zip=>Gummy.class Disinfection failed
C:\Documents and Settings\Patryk\.jpi_cache\jar\1.0\ar3.jar-1199dff7-65bf5b1f.zip Moved
C:\Program Files\Winad Client\ClientCom.dll=>(Upx) Infected Trojan.Downloader.Winupdt.A
C:\Program Files\Winad Client\ClientCom.dll=>(Upx) Disinfection failed
C:\Program Files\Winad Client\ClientCom.dll Moved
C:\System Volume Information\_restore{FF96CAE1-FC85-4616-8495-3DC89E699104}\RP84\A0021129.exe=>(Upx) Infected Trojan.Downloader.Winupdt.A
C:\System Volume Information\_restore{FF96CAE1-FC85-4616-8495-3DC89E699104}\RP84\A0021129.exe=>(Upx) Disinfection failed
C:\System Volume Information\_restore{FF96CAE1-FC85-4616-8495-3DC89E699104}\RP84\A0021129.exe Moved
C:\System Volume Information\_restore{FF96CAE1-FC85-4616-8495-3DC89E699104}\RP84\A0021130.exe Infected Adware.Serchentrix.A
C:\System Volume Information\_restore{FF96CAE1-FC85-4616-8495-3DC89E699104}\RP84\A0021130.exe Disinfection failed
C:\System Volume Information\_restore{FF96CAE1-FC85-4616-8495-3DC89E699104}\RP84\A0021130.exe Moved
C:\System Volume Information\_restore{FF96CAE1-FC85-4616-8495-3DC89E699104}\RP84\A0021131.exe=>(Embedded EXE o) Infected Trojan.Clicker.Delf.R
C:\System Volume Information\_restore{FF96CAE1-FC85-4616-8495-3DC89E699104}\RP84\A0021131.exe=>(Embedded EXE o) Disinfection failed
C:\System Volume Information\_restore{FF96CAE1-FC85-4616-8495-3DC89E699104}\RP84\A0021131.exe=>(Embedded EXE o) Move failed
C:\System Volume Information\_restore{FF96CAE1-FC85-4616-8495-3DC89E699104}\RP89\A0024654.dll=>(Upx) Infected Trojan.Downloader.Winupdt.A
C:\System Volume Information\_restore{FF96CAE1-FC85-4616-8495-3DC89E699104}\RP89\A0024654.dll=>(Upx) Disinfection failed
C:\System Volume Information\_restore{FF96CAE1-FC85-4616-8495-3DC89E699104}\RP89\A0024654.dll Moved
C:\unin.exe=>(RAR Sfx o)=>fast.exe=>(Morphine 1.2)=>(Upx) Infected Virtool.HiddenRun.B
C:\unin.exe=>(RAR Sfx o)=>fast.exe=>(Morphine 1.2)=>(Upx) Disinfection failed
C:\temp\FLEOK\msbb.exe Infected Adware.180Solutions.5.11
C:\temp\FLEOK\msbb.exe Disinfection failed
C:\temp\FLEOK\msbb.exe Moved

Scanned files

It happens much i cant delete some files with virusscanners how's that come ?
Hunter
You must do three things..

First to clean out your sun java cache you must do this..

Virus found in the Java™ Runtime Environment, Standard Edition (JRE) cache directory


SOLUTION

If you find one of these malicious applets on your computer, please use an anti-virus program to delete the applet, or you can clean the cache directory manually.

Here are the instructions on how to manually remove these malicious applets from the JRE cache directory:

From the Start button, click Settings > Control Panel
In the Control Panel, open the "Java Plug-in Control Panel"
Select the Cache Tab
Click the Clear button inside the Cache Tab, which will clear your JRE cache directory
http://www.java.com/en/download/help/cache_virus.jsp

**************************

Second to clean out your System Restore folder (System Volume Information)

You must do this..Problem is..the system restore also has a copy of all those virus and trojans that have infected your system. They are in a compressed mode...your ANTIVIRUS knows they are there but can not help you get rid of them, so you must do it manually.


NAME: Disabling System Restore on Windows XP
ALIAS: Disabling Windows XP AutoRestore feature


http://www.europe.f-secure.com/v-descs/sfc_dis1.shtml


***************************


Third you should follow these instructions and then post your hijackthis log in this thread and we will help you with the rest of the problems.

Guidelines for Posting in This Forum, READ THIS FIRST PLEASE

http://forum.gladiator-antivirus.com/index...showtopic=10517
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.