Can't Move Or Delete Viruses
Hello,
I got 4 viruses in my computer and I can't delete them, or my Bitdefender Internet security v10 can't do it...
I really don't know much about computers but I need help!, so please try to be very simple and clear with your explanations..
thanks a lot :-)
Here the result of the scan:
//-----------------------------------------------------------------
//
// ProduktBitDefender Internet Security v10
// Produkt10.2
//
// Erstellt am: 22/09/2007 16:48:30
//
//-----------------------------------------------------------------
Statistik
Pfad : C:\
\
Ordner : 6640
Dateien : 308843
Geprüfte Speicher-Prozesse: 68
Archive : 56531
Laufzeitkomprimierung :11295
Erkannte Viren : 4
Infizierte Dateien : 12
Infizierte Speicher-Prozesse: 0
Verdächtige Dateien : 0
Warnungen : 0
Desinfizierte Dateien : 0
Gelöschte Dateien : 0
Verschobene Dateien : 0
I/O Fehler : 61
Prüfzeit : 02:09:30
Prüfgeschwindigkeit (Dateien/Sekunde) : 39
Spyware Statistiken
Geprüste Registrierungsschlüssel: 1764
Infizierte Registrierungsschlüssel: 0
Geprüfte Cookies: 136
Infizierte Cookies: 0
Infizierte Spyware-Dateien: 0
Erkannte Spyware-Prozesse: 0
Virusdefinitionen : 896549
Scan Plug-Ins : 16
Archiv Plug-Ins : 41
Archiv Plug-Ins : 7
E-Mail Plug-Ins : 6
System Plug-Ins : 5
Prüf-Optionen
Erkennung
[X] Boot-Sektoren prüfen
[X] Speicher-Prozesse
[X] Archive prüfen
[X] Laufzeitkomprimierung prüfen
[X] E-Mails prüfen
Dateimaske
[ ] Programme
[X] Alle Dateien
[ ] Benutzerdefinierte Erweiterungen:
[ ] Ausgeschlossene Erweiterungen: ;
Aktion
Infizierte Objekte
[ ] Ignorieren
[X] Desinfizieren
[ ] Löschen
[ ] In die Quarantäne verschieben[ ] Benutzer abfragen
Zweite Aktion
[ ] Ignorieren
[ ] Löschen
[X] In die Quarantäne verschieben[ ] Benutzer abfragen
Prüf-Optionen
[X] Warnungen aktiviert
[X] Heuristik aktiviert
[ ] Alle Dateien im Bericht anzeigen
[X] Berichtsdatei: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Bitdefender\Desktop\Profiles\Logs\deep_scan\1190472510.log
Prüfoptionen für Spyware
[X] Auf Riskware prüfen
[ ] Dialer und Anwendungen vom Prüfvorgang ausschließen
[X] Registrierungsschlüssel
[X] Cookies
Zusammenfassung:
C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 131)=>[subject: Ebay geanderter E-Mail-Adresse][Date: Mon, 16 Apr 2007 13:03:53 -0400]=>(MIME part)=>57519.zip=>Dokument.doc.exe Infiziert mit: Trojan.Downloader.Nurech.AI
C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 131)=>[subject: Ebay geanderter E-Mail-Adresse][Date: Mon, 16 Apr 2007 13:03:53 -0400]=>(MIME part)=>57519.zip=>Dokument.doc.exe Desinfizieren fehlgeschlagen
C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 132)=>[subject: Hinweis zu geanderter E-Mail-Adresse E][Date: Mon, 16 Apr 2007 15:35:38 -0300]=>(MIME part)=>43543.zip=>Dokument.doc.exe Infiziert mit: Trojan.Downloader.Nurech.AI
C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 132)=>[subject: Hinweis zu geanderter E-Mail-Adresse E][Date: Mon, 16 Apr 2007 15:35:38 -0300]=>(MIME part)=>43543.zip=>Dokument.doc.exe Desinfizieren fehlgeschlagen
C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Sent=>(message 223)=>[subject: =?iso-8859-1?Q?Enviando_por_correo_ele][Date: Thu, 31 Mar 2005 17:56:37 +0200]=>(MIME part)=>Internet.Download.Manager.v4.03.5.Retai=>crack.exe Infiziert mit: Trojan.Servu.Daemon.C
C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Sent=>(message 223)=>[subject: =?iso-8859-1?Q?Enviando_por_correo_ele][Date: Thu, 31 Mar 2005 17:56:37 +0200]=>(MIME part)=>Internet.Download.Manager.v4.03.5.Retai=>crack.exe Desinfizieren fehlgeschlagen
C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Sent=>(message 223)=>[subject: =?iso-8859-1?Q?Enviando_por_correo_ele][Date: Thu, 31 Mar 2005 17:56:37 +0200]=>(MIME part)=>Internet.Download.Manager.v4.03.5.Retai=>crack.exe Verschieben fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 747)=>[subject: Die wichtige Mitteilung][Date: Sat, 25 Mar 2006 18:51:28 +0100]=>(MIME part)=>dahl.gif Infiziert mit: Trojan.Spy.HTML.Bankfraud.M
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 747)=>[subject: Die wichtige Mitteilung][Date: Sat, 25 Mar 2006 18:51:28 +0100]=>(MIME part)=>dahl.gif Desinfizieren fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 747)=>[subject: Die wichtige Mitteilung][Date: Sat, 25 Mar 2006 18:51:28 +0100]=>(MIME part)=>dahl.gif Verschieben fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 752)=>[subject: VOLKSBANKEN RAIFFEISENBANKEN INTERNET-][Date: Mon, 27 Mar 2006 00:19:20 +0200]=>(MIME part)=>archer.gif Infiziert mit: Trojan.Spy.HTML.Bankfraud.M
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 752)=>[subject: VOLKSBANKEN RAIFFEISENBANKEN INTERNET-][Date: Mon, 27 Mar 2006 00:19:20 +0200]=>(MIME part)=>archer.gif Desinfizieren fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 752)=>[subject: VOLKSBANKEN RAIFFEISENBANKEN INTERNET-][Date: Mon, 27 Mar 2006 00:19:20 +0200]=>(MIME part)=>archer.gif Verschieben fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 911)=>[subject: Volksbanken Raiffeisenbanken AG Intern][Date: Tue, 18 Apr 2006 08:18:46 +0200]=>(MIME part)=>celerity.gif Infiziert mit: Trojan.Spy.HTML.Bankfraud.M
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 911)=>[subject: Volksbanken Raiffeisenbanken AG Intern][Date: Tue, 18 Apr 2006 08:18:46 +0200]=>(MIME part)=>celerity.gif Desinfizieren fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 911)=>[subject: Volksbanken Raiffeisenbanken AG Intern][Date: Tue, 18 Apr 2006 08:18:46 +0200]=>(MIME part)=>celerity.gif Verschieben fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 2844)=>[subject: 1&1 Rechnung 590328548 vom 23.01.2007][Date: Tue, 23 Jan 2007 20:41:01 -0300]=>(MIME part)=>Rechnung.pdf.exe Infiziert mit: Trojan.Clagger.L
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 2844)=>[subject: 1&1 Rechnung 590328548 vom 23.01.2007][Date: Tue, 23 Jan 2007 20:41:01 -0300]=>(MIME part)=>Rechnung.pdf.exe Desinfizieren fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 2844)=>[subject: 1&1 Rechnung 590328548 vom 23.01.2007][Date: Tue, 23 Jan 2007 20:41:01 -0300]=>(MIME part)=>Rechnung.pdf.exe Verschieben fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 3414)=>[subject: Hinweis zu geanderter E-Mail-Adresse E][Date: Mon, 16 Apr 2007 15:35:38 -0300]=>(MIME part)=>43543.zip=>Dokument.doc.exe Infiziert mit: Trojan.Downloader.Nurech.AI
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 3414)=>[subject: Hinweis zu geanderter E-Mail-Adresse E][Date: Mon, 16 Apr 2007 15:35:38 -0300]=>(MIME part)=>43543.zip=>Dokument.doc.exe Desinfizieren fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 3415)=>[subject: Ebay geanderter E-Mail-Adresse][Date: Mon, 16 Apr 2007 13:03:53 -0400]=>(MIME part)=>57519.zip=>Dokument.doc.exe Infiziert mit: Trojan.Downloader.Nurech.AI
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 3415)=>[subject: Ebay geanderter E-Mail-Adresse][Date: Mon, 16 Apr 2007 13:03:53 -0400]=>(MIME part)=>57519.zip=>Dokument.doc.exe Desinfizieren fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 131)=>[subject: Ebay geanderter E-Mail-Adresse][Date: Mon, 16 Apr 2007 13:03:53 -0400]=>(MIME part)=>57519.zip=>Dokument.doc.exe Infiziert mit: Trojan.Downloader.Nurech.AI
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 131)=>[subject: Ebay geanderter E-Mail-Adresse][Date: Mon, 16 Apr 2007 13:03:53 -0400]=>(MIME part)=>57519.zip=>Dokument.doc.exe Desinfizieren fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 132)=>[subject: Hinweis zu geanderter E-Mail-Adresse E][Date: Mon, 16 Apr 2007 15:35:38 -0300]=>(MIME part)=>43543.zip=>Dokument.doc.exe Infiziert mit: Trojan.Downloader.Nurech.AI
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 132)=>[subject: Hinweis zu geanderter E-Mail-Adresse E][Date: Mon, 16 Apr 2007 15:35:38 -0300]=>(MIME part)=>43543.zip=>Dokument.doc.exe Desinfizieren fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Sent=>(message 223)=>[subject: =?iso-8859-1?Q?Enviando_por_correo_ele][Date: Thu, 31 Mar 2005 17:56:37 +0200]=>(MIME part)=>Internet.Download.Manager.v4.03.5.Retai=>crack.exe Infiziert mit: Trojan.Servu.Daemon.C
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Sent=>(message 223)=>[subject: =?iso-8859-1?Q?Enviando_por_correo_ele][Date: Thu, 31 Mar 2005 17:56:37 +0200]=>(MIME part)=>Internet.Download.Manager.v4.03.5.Retai=>crack.exe Desinfizieren fehlgeschlagen
C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Sent=>(message 223)=>[subject: =?iso-8859-1?Q?Enviando_por_correo_ele][Date: Thu, 31 Mar 2005 17:56:37 +0200]=>(MIME part)=>Internet.Download.Manager.v4.03.5.Retai=>crack.exe Verschieben fehlgeschlagen
greetings,
olivia
Comments
-
Hello Olivia
Delete these mails also in the junk and trash folder when you are in Thunderbird. That should solve your problem. Be sure that you disable realtime protection. After you done that compress your email file. If you can't find them in Thunderbird. Do this go to start,my computer,double click on the icon of your hard disc where windows is installed on,go to documents and settings,your user account,after that go to menu tools,folder options,view/display check the options show hidden files and folders confirm by pressing on apply and ok and uncheck hide known file extensions and hide system protected operating system file confirm also by pressing on apply. Now you should see the folder called Application Data ( I suppose that it's the same as Anwendungsdaten) and navigate further to C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\
Rightclick on inbox and send choose open with choose wordpad and delete the found messages.
If BitDefender blocks you to delete the mails do this rightclick on the BitDefender icon with you will find near the system clock go to antivirus,press on realtime protection (enabled). For the new versions click on settings and go to antivirus,shield and uncheck realtime protection (enabled)
Retry to delete it. For your other problem right click on your recycle bin and choose empty. If that doesn't work go to start,my computer,double click on the icon of your hard disc now you will see a folder called recycler open it and delete Dc22.default. Now re-enable realtime protection by doing the same but press on antivirus,enable realtime protection.
Best regards
Niels0 -
Hello Nils,
thanks for your answer.
the main problem was that the mails with the viruses didn't exist anymore, so I couldn't delete them!.
Now I download the last version of bitdefender http://download.bitdefender.com/windows/de...ty_2008_32b.exe
and I think the viruses are now destroy..., I hope so...
I will see during the next days!
Thank you very, very much for your help,
greetings,
OliviaHello Olivia
Delete these mails also in the junk and trash folder when you are in Thunderbird. That should solve your problem. Be sure that you disable realtime protection. After you done that compress your email file. If you can't find them in Thunderbird. Do this go to start,my computer,double click on the icon of your hard disc where windows is installed on,go to documents and settings,your user account,after that go to menu tools,folder options,view/display check the options show hidden files and folders confirm by pressing on apply and ok and uncheck hide known file extensions and hide system protected operating system file confirm also by pressing on apply. Now you should see the folder called Application Data ( I suppose that it's the same as Anwendungsdaten) and navigate further to C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\
Rightclick on inbox and send choose open with choose wordpad and delete the found messages.
If BitDefender blocks you to delete the mails do this rightclick on the BitDefender icon with you will find near the system clock go to antivirus,press on realtime protection (enabled). For the new versions click on settings and go to antivirus,shield and uncheck realtime protection (enabled)
Retry to delete it. For your other problem right click on your recycle bin and choose empty. If that doesn't work go to start,my computer,double click on the icon of your hard disc now you will see a folder called recycler open it and delete Dc22.default. Now re-enable realtime protection by doing the same but press on antivirus,enable realtime protection.
Best regards
Niels0 -
Hello Olivia
These mails are still stored on the location I mentioned. The problem is that I don't know how it's called in a German windows version. But yes it could be that you didn't find them in your inbox.
Glad that I could assist you.
Best regards
Niels0