Need help in removing multiple malware in windows system32. BD could not take any possible action & I'm unable to delete them manually. Below is the log file.
BitDefender Log File !!!!!
Product : BitDefender Internet Security 2008
Version : BitDefender UIScanner v.11
Log date : 00:36:17 14/10/2008
Log path : C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Profiles\Logs\deep_scan\1223915777_1_02.xml
Scan Paths:Path0000: C:\
Scan Options:Scan for viruses : Yes
Scan for adware : Yes
Scan for spyware : Yes
Scan for applications : Yes
Scan for dialers : Yes
Scan for rootkits : Yes
Target selection options:Scan registry keys : Yes
Scan cookies : Yes
Scan boot sectors : Yes
Scan memory processes : Yes
Scan archives : Yes
Scan runtime packers : Yes
Scan emails : Yes
Scan all files : Yes
Heuristic Scan : Yes
Scanned extensions :
Excluded extensions :
Target ProcessingDefault action for infected objects : Disinfect
Default action for suspicious objects : None
Default action for hidden objects : None
Scan engines summaryNumber of virus signatures : 1869679
Archive plugins : 43
Email plugins : 6
Scan plugins : 12
Archive plugins : 43
System plugins : 5
Unpack plugins : 7
Overall scan summaryScanned items : 250663
Infected items : 20
Suspicious items : 0
Resolved items : 15
Individual viruses found : 14
Scanned directories : 6615
Scanned boot sectors : 3
Scanned archives : 9382
Input-output errors : 25
Scan time : 00:00:53:24
Files per second : 77
Scanned processes summaryScanned : 80
Infected : 0
Scanned registry keys summaryScanned : 1483
Infected : 0
Scanned cookies summaryScanned : 0
Infected : 0
Remaining issues:Object Name Threat Name Final Status
[system]=]HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\ICF\ImagePath=]C:\WINDOWS\SYSTEM32\SVCHOST.EXE:EXT.EXE BehavesLike:Win32.ExplorerHijack No action was possible
[system]=]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\WINCTRL32\DLLName=]C:\WINDOWS\SYSTEM32\WINCTRL32.DLL Trojan.Dropper.Kobcka.Gen.1 No action was possible
[system]=]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\lphc3c7j0ecd9=]C:\WINDOWS\SYSTEM32\LPHC3C7J0ECD9.EXE Trojan.FakeAV.1.Gen No action was possible
[system]=]HKEY_USERS\S-1-5-21-150597262-1105282853-3413232892-1006\CONTROL PANEL\DESKTOP\SCRNSAVE.EXE=]C:\WINDOWS\SYSTEM32\BLPHC3C7J0ECD9.SCR Trojan.FakeAlert.AFW No action was possible
[system]=]HKEY_USERS\S-1-5-21-150597262-1105282853-3413232892-1006\CONTROL PANEL\DESKTOP\Wallpaper=]C:\WINDOWS\SYSTEM32\PHC3C7J0ECD9.BMP Trojan.FakeAlert.AGJ No action was possible
Resolved issues:Object Name Threat Name Final Status
C:\temp\.tt12.tmp.vbs Application.CleanSystemRestore.A Moved to Quarantine
C:\temp\.tt13.tmp.vbs Application.CleanSystemRestore.A Moved to Quarantine
C:\temp\.tt14.tmp.vbs Application.CleanSystemRestore.A Moved to Quarantine
C:\temp\.tt15.tmp.vbs Application.CleanSystemRestore.A Moved to Quarantine
C:\temp\.tt84.tmp.vbs Application.CleanSystemRestore.A Moved to Quarantine
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\w32tms[1].exe BehavesLike:Win32.ExplorerHijack Moved to Quarantine
[system]=]C:\WINDOWS\msauc.exe (memory dump) Trojan.Agent.AJCH Deleted
[system]=]C:\WINDOWS\System32\rs32net.exe (memory dump) Trojan.Agent.AKIA Deleted
C:\WINDOWS\system32\WinCtrl32.dll Trojan.Dropper.Kobcka.Gen.1 Moved to Quarantine
C:\System Volume Information\_restore{74596469-0A02-4C9E-9303-6035F91A9AB2}\RP132\A0045994.exe Trojan.FakeAV.1.Gen Moved to Quarantine
[system]=]C:\WINDOWS\system32\lphc3c7j0ecd9.exe (memory dump) Trojan.FakeAlert.AFW Deleted
C:\System Volume Information\_restore{74596469-0A02-4C9E-9303-6035F91A9AB2}\RP132\A0045995.scr Trojan.FakeAlert.AFW Deleted
C:\WINDOWS\system32\phc3c7j0ecd9.bmp Trojan.FakeAlert.AGJ Deleted
C:\Documents and Settings\Isaac David Ampil II\Shared\wanna ask somebody .mp3 Trojan.Wimad.Gen.1 Disinfected
C:\Documents and Settings\Isaac David Ampil II\Shared\wanna get somebody .mp3 Trojan.Wimad.Gen.1 Disinfected
Objects that were not scanned:Object Name Reason Final Status