Can't Move Or Delete Viruses

Hello,


I got 4 viruses in my computer and I can't delete them, or my Bitdefender Internet security v10 can't do it...


I really don't know much about computers but I need help!, so please try to be very simple and clear with your explanations..


thanks a lot :-)


Here the result of the scan:


//-----------------------------------------------------------------


//


// ProduktBitDefender Internet Security v10


// Produkt10.2


//


// Erstellt am: 22/09/2007 16:48:30


//


//-----------------------------------------------------------------


Statistik


Pfad : C:\


D:\


Ordner : 6640


Dateien : 308843


Geprüfte Speicher-Prozesse: 68


Archive : 56531


Laufzeitkomprimierung :11295


Erkannte Viren : 4


Infizierte Dateien : 12


Infizierte Speicher-Prozesse: 0


Verdächtige Dateien : 0


Warnungen : 0


Desinfizierte Dateien : 0


Gelöschte Dateien : 0


Verschobene Dateien : 0


I/O Fehler : 61


Prüfzeit : 02:09:30


Prüfgeschwindigkeit (Dateien/Sekunde) : 39


Spyware Statistiken


Geprüste Registrierungsschlüssel: 1764


Infizierte Registrierungsschlüssel: 0


Geprüfte Cookies: 136


Infizierte Cookies: 0


Infizierte Spyware-Dateien: 0


Erkannte Spyware-Prozesse: 0


Virusdefinitionen : 896549


Scan Plug-Ins : 16


Archiv Plug-Ins : 41


Archiv Plug-Ins : 7


E-Mail Plug-Ins : 6


System Plug-Ins : 5


Prüf-Optionen


Erkennung


[X] Boot-Sektoren prüfen


[X] Speicher-Prozesse


[X] Archive prüfen


[X] Laufzeitkomprimierung prüfen


[X] E-Mails prüfen


Dateimaske


[ ] Programme


[X] Alle Dateien


[ ] Benutzerdefinierte Erweiterungen:


[ ] Ausgeschlossene Erweiterungen: ;


Aktion


Infizierte Objekte


[ ] Ignorieren


[X] Desinfizieren


[ ] Löschen


[ ] In die Quarantäne verschieben[ ] Benutzer abfragen


Zweite Aktion


[ ] Ignorieren


[ ] Löschen


[X] In die Quarantäne verschieben[ ] Benutzer abfragen


Prüf-Optionen


[X] Warnungen aktiviert


[X] Heuristik aktiviert


[ ] Alle Dateien im Bericht anzeigen


[X] Berichtsdatei: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Bitdefender\Desktop\Profiles\Logs\deep_scan\1190472510.log


Prüfoptionen für Spyware


[X] Auf Riskware prüfen


[ ] Dialer und Anwendungen vom Prüfvorgang ausschließen


[X] Registrierungsschlüssel


[X] Cookies


Zusammenfassung:


C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 131)=>[subject: Ebay geanderter E-Mail-Adresse][Date: Mon, 16 Apr 2007 13:03:53 -0400]=>(MIME part)=>57519.zip=>Dokument.doc.exe Infiziert mit: Trojan.Downloader.Nurech.AI


C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 131)=>[subject: Ebay geanderter E-Mail-Adresse][Date: Mon, 16 Apr 2007 13:03:53 -0400]=>(MIME part)=>57519.zip=>Dokument.doc.exe Desinfizieren fehlgeschlagen


C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 132)=>[subject: Hinweis zu geanderter E-Mail-Adresse E][Date: Mon, 16 Apr 2007 15:35:38 -0300]=>(MIME part)=>43543.zip=>Dokument.doc.exe Infiziert mit: Trojan.Downloader.Nurech.AI


C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 132)=>[subject: Hinweis zu geanderter E-Mail-Adresse E][Date: Mon, 16 Apr 2007 15:35:38 -0300]=>(MIME part)=>43543.zip=>Dokument.doc.exe Desinfizieren fehlgeschlagen


C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Sent=>(message 223)=>[subject: =?iso-8859-1?Q?Enviando_por_correo_ele][Date: Thu, 31 Mar 2005 17:56:37 +0200]=>(MIME part)=>Internet.Download.Manager.v4.03.5.Retai=>crack.exe Infiziert mit: Trojan.Servu.Daemon.C


C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Sent=>(message 223)=>[subject: =?iso-8859-1?Q?Enviando_por_correo_ele][Date: Thu, 31 Mar 2005 17:56:37 +0200]=>(MIME part)=>Internet.Download.Manager.v4.03.5.Retai=>crack.exe Desinfizieren fehlgeschlagen


C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\Sent=>(message 223)=>[subject: =?iso-8859-1?Q?Enviando_por_correo_ele][Date: Thu, 31 Mar 2005 17:56:37 +0200]=>(MIME part)=>Internet.Download.Manager.v4.03.5.Retai=>crack.exe Verschieben fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 747)=>[subject: Die wichtige Mitteilung][Date: Sat, 25 Mar 2006 18:51:28 +0100]=>(MIME part)=>dahl.gif Infiziert mit: Trojan.Spy.HTML.Bankfraud.M


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 747)=>[subject: Die wichtige Mitteilung][Date: Sat, 25 Mar 2006 18:51:28 +0100]=>(MIME part)=>dahl.gif Desinfizieren fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 747)=>[subject: Die wichtige Mitteilung][Date: Sat, 25 Mar 2006 18:51:28 +0100]=>(MIME part)=>dahl.gif Verschieben fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 752)=>[subject: VOLKSBANKEN RAIFFEISENBANKEN INTERNET-][Date: Mon, 27 Mar 2006 00:19:20 +0200]=>(MIME part)=>archer.gif Infiziert mit: Trojan.Spy.HTML.Bankfraud.M


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 752)=>[subject: VOLKSBANKEN RAIFFEISENBANKEN INTERNET-][Date: Mon, 27 Mar 2006 00:19:20 +0200]=>(MIME part)=>archer.gif Desinfizieren fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 752)=>[subject: VOLKSBANKEN RAIFFEISENBANKEN INTERNET-][Date: Mon, 27 Mar 2006 00:19:20 +0200]=>(MIME part)=>archer.gif Verschieben fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 911)=>[subject: Volksbanken Raiffeisenbanken AG Intern][Date: Tue, 18 Apr 2006 08:18:46 +0200]=>(MIME part)=>celerity.gif Infiziert mit: Trojan.Spy.HTML.Bankfraud.M


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 911)=>[subject: Volksbanken Raiffeisenbanken AG Intern][Date: Tue, 18 Apr 2006 08:18:46 +0200]=>(MIME part)=>celerity.gif Desinfizieren fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 911)=>[subject: Volksbanken Raiffeisenbanken AG Intern][Date: Tue, 18 Apr 2006 08:18:46 +0200]=>(MIME part)=>celerity.gif Verschieben fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 2844)=>[subject: 1&1 Rechnung 590328548 vom 23.01.2007][Date: Tue, 23 Jan 2007 20:41:01 -0300]=>(MIME part)=>Rechnung.pdf.exe Infiziert mit: Trojan.Clagger.L


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 2844)=>[subject: 1&1 Rechnung 590328548 vom 23.01.2007][Date: Tue, 23 Jan 2007 20:41:01 -0300]=>(MIME part)=>Rechnung.pdf.exe Desinfizieren fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 2844)=>[subject: 1&1 Rechnung 590328548 vom 23.01.2007][Date: Tue, 23 Jan 2007 20:41:01 -0300]=>(MIME part)=>Rechnung.pdf.exe Verschieben fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 3414)=>[subject: Hinweis zu geanderter E-Mail-Adresse E][Date: Mon, 16 Apr 2007 15:35:38 -0300]=>(MIME part)=>43543.zip=>Dokument.doc.exe Infiziert mit: Trojan.Downloader.Nurech.AI


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 3414)=>[subject: Hinweis zu geanderter E-Mail-Adresse E][Date: Mon, 16 Apr 2007 15:35:38 -0300]=>(MIME part)=>43543.zip=>Dokument.doc.exe Desinfizieren fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 3415)=>[subject: Ebay geanderter E-Mail-Adresse][Date: Mon, 16 Apr 2007 13:03:53 -0400]=>(MIME part)=>57519.zip=>Dokument.doc.exe Infiziert mit: Trojan.Downloader.Nurech.AI


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox=>(message 3415)=>[subject: Ebay geanderter E-Mail-Adresse][Date: Mon, 16 Apr 2007 13:03:53 -0400]=>(MIME part)=>57519.zip=>Dokument.doc.exe Desinfizieren fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 131)=>[subject: Ebay geanderter E-Mail-Adresse][Date: Mon, 16 Apr 2007 13:03:53 -0400]=>(MIME part)=>57519.zip=>Dokument.doc.exe Infiziert mit: Trojan.Downloader.Nurech.AI


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 131)=>[subject: Ebay geanderter E-Mail-Adresse][Date: Mon, 16 Apr 2007 13:03:53 -0400]=>(MIME part)=>57519.zip=>Dokument.doc.exe Desinfizieren fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 132)=>[subject: Hinweis zu geanderter E-Mail-Adresse E][Date: Mon, 16 Apr 2007 15:35:38 -0300]=>(MIME part)=>43543.zip=>Dokument.doc.exe Infiziert mit: Trojan.Downloader.Nurech.AI


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Inbox.sbd\Bandeja de entrada.sbd\mi amor=>(message 132)=>[subject: Hinweis zu geanderter E-Mail-Adresse E][Date: Mon, 16 Apr 2007 15:35:38 -0300]=>(MIME part)=>43543.zip=>Dokument.doc.exe Desinfizieren fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Sent=>(message 223)=>[subject: =?iso-8859-1?Q?Enviando_por_correo_ele][Date: Thu, 31 Mar 2005 17:56:37 +0200]=>(MIME part)=>Internet.Download.Manager.v4.03.5.Retai=>crack.exe Infiziert mit: Trojan.Servu.Daemon.C


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Sent=>(message 223)=>[subject: =?iso-8859-1?Q?Enviando_por_correo_ele][Date: Thu, 31 Mar 2005 17:56:37 +0200]=>(MIME part)=>Internet.Download.Manager.v4.03.5.Retai=>crack.exe Desinfizieren fehlgeschlagen


C:\RECYCLER\S-1-5-21-3394647633-4259527022-3314538741-1007\Dc22.default\Mail\Local Folders\Sent=>(message 223)=>[subject: =?iso-8859-1?Q?Enviando_por_correo_ele][Date: Thu, 31 Mar 2005 17:56:37 +0200]=>(MIME part)=>Internet.Download.Manager.v4.03.5.Retai=>crack.exe Verschieben fehlgeschlagen


greetings,


olivia

Comments

  • Hello Olivia


    Delete these mails also in the junk and trash folder when you are in Thunderbird. That should solve your problem. Be sure that you disable realtime protection. After you done that compress your email file. If you can't find them in Thunderbird. Do this go to start,my computer,double click on the icon of your hard disc where windows is installed on,go to documents and settings,your user account,after that go to menu tools,folder options,view/display check the options show hidden files and folders confirm by pressing on apply and ok and uncheck hide known file extensions and hide system protected operating system file confirm also by pressing on apply. Now you should see the folder called Application Data ( I suppose that it's the same as Anwendungsdaten) and navigate further to C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\


    Rightclick on inbox and send choose open with choose wordpad and delete the found messages.


    If BitDefender blocks you to delete the mails do this rightclick on the BitDefender icon with you will find near the system clock go to antivirus,press on realtime protection (enabled). For the new versions click on settings and go to antivirus,shield and uncheck realtime protection (enabled)


    Retry to delete it. For your other problem right click on your recycle bin and choose empty. If that doesn't work go to start,my computer,double click on the icon of your hard disc now you will see a folder called recycler open it and delete Dc22.default. Now re-enable realtime protection by doing the same but press on antivirus,enable realtime protection.


    Best regards


    Niels

  • Hello Nils,


    thanks for your answer.


    the main problem was that the mails with the viruses didn't exist anymore, so I couldn't delete them!.


    Now I download the last version of bitdefender http://download.bitdefender.com/windows/de...ty_2008_32b.exe


    and I think the viruses are now destroy..., I hope so...


    I will see during the next days!


    Thank you very, very much for your help,


    greetings,


    Olivia


    Hello Olivia


    Delete these mails also in the junk and trash folder when you are in Thunderbird. That should solve your problem. Be sure that you disable realtime protection. After you done that compress your email file. If you can't find them in Thunderbird. Do this go to start,my computer,double click on the icon of your hard disc where windows is installed on,go to documents and settings,your user account,after that go to menu tools,folder options,view/display check the options show hidden files and folders confirm by pressing on apply and ok and uncheck hide known file extensions and hide system protected operating system file confirm also by pressing on apply. Now you should see the folder called Application Data ( I suppose that it's the same as Anwendungsdaten) and navigate further to C:\Dokumente und Einstellungen\Olivia Court Mesa\Anwendungsdaten\Thunderbird\Profiles\lc3hot8x.default\Mail\Local Folders\


    Rightclick on inbox and send choose open with choose wordpad and delete the found messages.


    If BitDefender blocks you to delete the mails do this rightclick on the BitDefender icon with you will find near the system clock go to antivirus,press on realtime protection (enabled). For the new versions click on settings and go to antivirus,shield and uncheck realtime protection (enabled)


    Retry to delete it. For your other problem right click on your recycle bin and choose empty. If that doesn't work go to start,my computer,double click on the icon of your hard disc now you will see a folder called recycler open it and delete Dc22.default. Now re-enable realtime protection by doing the same but press on antivirus,enable realtime protection.


    Best regards


    Niels

  • Hello Olivia


    These mails are still stored on the location I mentioned. The problem is that I don't know how it's called in a German windows version. But yes it could be that you didn't find them in your inbox.


    Glad that I could assist you.


    Best regards


    Niels