Kindly be advised we cannot cancel subscriptions or issue refunds on the forum.
You may cancel your Bitdefender subscription from Bitdefender Central or by contacting Customer Support at: https://www.bitdefender.com/consumer/support/help/

Thank you for your understanding.

Got Win 32.bagle

Options

Hi there,


Am new here.


I use The Avira Antivirus and I got, Win 32.Bagle


I scanned the PC with several online antivirus an only Bit defender founded Win 32.Bagle and others trojan. Afetr the disinfection,


I made a second scan with bitdefender and Kasperski: the results are:


Bitdefender :


Scanned File


Status


C:\Users\Marco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1DH28FQ5\b64_1[1].jpg


Infected with: Trojan.Pakes.ZUS


C:\Users\Marco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1DH28FQ5\b64_1[1].jpg


Deleted


C:\Users\Marco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BVV5HM09\b64_1[1].jpg


Infected with: Trojan.Pakes.ZUS


C:\Users\Marco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BVV5HM09\b64_1[1].jpg


Deleted


C:\Users\Marco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNGQMFZM\b64_2[1].jpg


Infected with: Win32.Bagle.SUQ@mm


C:\Users\Marco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNGQMFZM\b64_2[1].jpg


Deleted


C:\Users\Marco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNGQMFZM\b64_2[2].jpg


Infected with: Win32.Bagle.SUQ@mm


C:\Users\Marco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNGQMFZM\b64_2[2].jpg


Deleted


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RELPNWK.zip.bac_a03576=>(Quarantine-4)=>run.exe


Infected with: DeepScan:Generic.Zlob.7.F16D393E


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RELPNWK.zip.bac_a03576=>(Quarantine-4)=>run.exe


Disinfection failed


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RELPNWK.zip.bac_a03576=>(Quarantine-4)=>run.exe


Deleted


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RELPNWK.zip.bac_a03576=>(Quarantine-4)


Updated


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RELPNWK.zip.bac_a03576


Update failed


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$ROL1PVD.zip.bac_a03576=>(Quarantine-4)=>run.exe


Infected with: DeepScan:Generic.Zlob.7.F16D393E


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$ROL1PVD.zip.bac_a03576=>(Quarantine-4)=>run.exe


Disinfection failed


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$ROL1PVD.zip.bac_a03576=>(Quarantine-4)=>run.exe


Deleted


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$ROL1PVD.zip.bac_a03576=>(Quarantine-4)


Updated


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$ROL1PVD.zip.bac_a03576


Update failed


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RVO90TC.zip.bac_a03576=>(Quarantine-4)=>run.exe


Infected with: DeepScan:Generic.Zlob.7.F16D393E


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RVO90TC.zip.bac_a03576=>(Quarantine-4)=>run.exe


Disinfection failed


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RVO90TC.zip.bac_a03576=>(Quarantine-4)=>run.exe


Deleted


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RVO90TC.zip.bac_a03576=>(Quarantine-4)


Updated


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RVO90TC.zip.bac_a03576


Update failed


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\Astro22_professional_edition_7_05_56.zip.bac_a03576=>(Quarantine-4)=>run.exe


Infected with: DeepScan:Generic.Zlob.7.F16D393E


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\Astro22_professional_edition_7_05_56.zip.bac_a03576=>(Quarantine-4)=>run.exe


Disinfection failed


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\Astro22_professional_edition_7_05_56.zip.bac_a03576=>(Quarantine-4)=>run.exe


Deleted


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\Astro22_professional_edition_7_05_56.zip.bac_a03576=>(Quarantine-4)


Updated


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\Astro22_professional_edition_7_05_56.zip.bac_a03576


Update failed


C:\Users\Marco\Condivisi\Programmi\Dizionari\Pragma 4 - ukrainian russian german english latvian translator + kegen.rar=>Pragma 4\pragma4.exe=>(CAB Sfx o)=>\Disk1\clean2003.exe


Infected with: DeepScan:Generic.Malware.P!Pk!.600D78FB


C:\Users\Marco\Condivisi\Programmi\Dizionari\Pragma 4 - ukrainian russian german english latvian translator + kegen.rar=>Pragma 4\pragma4.exe=>(CAB Sfx o)=>\Disk1\clean2003.exe


Disinfection failed


C:\Users\Marco\Condivisi\Programmi\Dizionari\Pragma 4 - ukrainian russian german english latvian translator + kegen.rar=>Pragma 4\pragma4.exe=>(CAB Sfx o)=>\Disk1\clean2003.exe


Deleted


C:\Users\Marco\Condivisi\Programmi\Dizionari\Pragma 4 - ukrainian russian german english latvian translator + kegen.rar=>Pragma 4\pragma4.exe=>(CAB Sfx o)


Update failed


C:\Windows\System32\drivers\hldrrr.exe


Infected with: Win32.Bagle.SVK@mm


C:\Windows\System32\drivers\hldrrr.exe


Disinfection failed


C:\Windows\System32\drivers\hldrrr.exe


Delete failed


C:\Windows\System32\mdelk.exe


Infected with: Win32.Bagle.SUQ@mm


C:\Windows\System32\mdelk.exe


Disinfection failed


C:\Windows\System32\mdelk.exe


Delete failed


++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++


+


Kasperski:


Scan Settings:


Scan using the following antivirus database: extended


Scan Archives: true


Scan Mail Bases: true


Scan Target - Folders:


C:\


Scan Statistics:


Total number of scanned objects: 112223


Number of viruses found: 4


Number of infected objects: 18


Number of suspicious objects: 0


Duration of the scan process: 08:33:27


Infected Object Name / Virus Name / Last Action


C:\boot\bcd Object is locked skipped


C:\boot\BCD.LOG Object is locked skipped


C:\ProgramData\CyberLink\TinyDB\EPGSignal Object is locked skipped


C:\ProgramData\CyberLink\TinyDB\Schedule Object is locked skipped


C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\271909b66ebd71cd90ef99c6497fc218_620f64cc-efda-4d62-b32f-6226589097a4 Object is locked skipped


C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped


C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped


C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008033120080401\index.dat Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Windows\UsrClass.dat{262eab4f-6104-11dc-9806-001a6b437842}.TM.blf Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Windows\UsrClass.dat{262eab4f-6104-11dc-9806-001a6b437842}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Windows\UsrClass.dat{262eab4f-6104-11dc-9806-001a6b437842}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped


C:\Users\Marco\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped


C:\Users\Marco\AppData\Local\Temp\ehmsas.txt Object is locked skipped


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RELPNWK.zip.bac_a03576/run.exe Infected: Trojan-Downloader.Win32.Zlob.gen skipped


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RELPNWK.zip.bac_a03576 ZIP: infected - 1 skipped


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RELPNWK.zip.bac_a03576 CryptFF.b: infected - 1 skipped


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$ROL1PVD.zip.bac_a03576/run.exe Infected: Trojan-Downloader.Win32.Zlob.gen skipped


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$ROL1PVD.zip.bac_a03576 ZIP: infected - 1 skipped


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$ROL1PVD.zip.bac_a03576 CryptFF.b: infected - 1 skipped


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RVO90TC.zip.bac_a03576/run.exe Infected: Trojan-Downloader.Win32.Zlob.gen skipped


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RVO90TC.zip.bac_a03576 ZIP: infected - 1 skipped


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\$RVO90TC.zip.bac_a03576 CryptFF.b: infected - 1 skipped


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\Astro22_professional_edition_7_05_56.zip.bac_a03576/run.exe Infected: Trojan-Downloader.Win32.Zlob.gen skipped


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\Astro22_professional_edition_7_05_56.zip.bac_a03576 ZIP: infected - 1 skipped


C:\Users\Marco\AppData\Roaming\HouseCall 6.6\Backup\Astro22_professional_edition_7_05_56.zip.bac_a03576 CryptFF.b: infected - 1 skipped


C:\Users\Marco\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat Object is locked skipped


C:\Users\Marco\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped


C:\Users\Marco\Condivisi\Programmi\Programmi Flash\Action ****** Viewer v4.01 Incl Keygen (Flash Decompiler Extractor)\Action ****** Viewer v4.01 Incl Keygen (Flash Decompiler Extractor).zip/Action ****** Viewer v4.01 Incl. Keygen (Flash Decompiler + Extractor).exe/data.rar/p60790c.dat Infected: Trojan.Win32.Inject.akh skipped


C:\Users\Marco\Condivisi\Programmi\Programmi Flash\Action ****** Viewer v4.01 Incl Keygen (Flash Decompiler Extractor)\Action ****** Viewer v4.01 Incl Keygen (Flash Decompiler Extractor).zip/Action ****** Viewer v4.01 Incl. Keygen (Flash Decompiler + Extractor).exe/data.rar Infected: Trojan.Win32.Inject.akh skipped


C:\Users\Marco\Condivisi\Programmi\Programmi Flash\Action ****** Viewer v4.01 Incl Keygen (Flash Decompiler Extractor)\Action ****** Viewer v4.01 Incl Keygen (Flash Decompiler Extractor).zip/Action ****** Viewer v4.01 Incl. Keygen (Flash Decompiler + Extractor).exe Infected: Trojan.Win32.Inject.akh skipped


C:\Users\Marco\Condivisi\Programmi\Programmi Flash\Action ****** Viewer v4.01 Incl Keygen (Flash Decompiler Extractor)\Action ****** Viewer v4.01 Incl Keygen (Flash Decompiler Extractor).zip ZIP: infected - 3 skipped


C:\Users\Marco\ntuser.dat Object is locked skipped


C:\Users\Marco\ntuser.dat.LOG1 Object is locked skipped


C:\Users\Marco\ntuser.dat.LOG2 Object is locked skipped


C:\Users\Marco\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped


C:\Users\Marco\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped


C:\Users\Marco\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped


C:\Windows\bthservsdp.dat Object is locked skipped


C:\Windows\Debug\PASSWD.LOG Object is locked skipped


C:\Windows\Debug\sam.log Object is locked skipped


C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped


C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped


C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped


C:\Windows\ServiceProfiles\LocalService\ntuser.dat Object is locked skipped


C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped


C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped


C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped


C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped


C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped


C:\Windows\ServiceProfiles\NetworkService\ntuser.dat Object is locked skipped


C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped


C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped


C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped


C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped


C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped


C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped


C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped


C:\Windows\System32\catroot2\edb.log Object is locked skipped


C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped


C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped


C:\Windows\System32\config\components Object is locked skipped


C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped


C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped


C:\Windows\System32\config\default Object is locked skipped


C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped


C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped


C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped


C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped


C:\Windows\System32\config\RegBack\SAM Object is locked skipped


C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped


C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped


C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped


C:\Windows\System32\config\sam Object is locked skipped


C:\Windows\System32\config\SAM.LOG1 Object is locked skipped


C:\Windows\System32\config\SAM.LOG2 Object is locked skipped


C:\Windows\System32\config\security Object is locked skipped


C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped


C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped


C:\Windows\System32\config\software Object is locked skipped


C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped


C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped


C:\Windows\System32\config\system Object is locked skipped


C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped


C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped


C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked skipped


C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked skipped


C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked skipped


C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked skipped


C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped


C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped


C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped


C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped


C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped


C:\Windows\System32\drivers\hldrrr.exe Infected: Trojan-Downloader.Win32.Bagle.mk skipped


C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped


C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped


C:\Windows\System32\mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped


C:\Windows\System32\Msdtc\KtmRmTm.blf Object is locked skipped


C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked skipped


C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked skipped


C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped


C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped


C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped


C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped


C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped


C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped


C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.002 Object is locked skipped


C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped


C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped


C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped


C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16386_none_69f99fa4b7380194\ntkrnlpa.exe Object is locked skipped


C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16514_none_6a435250b701059d\ntkrnlpa.exe Object is locked skipped


C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16551_none_6a1511c2b724295c\ntkrnlpa.exe Object is locked skipped


C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16575_none_6a037312b730c69a\ntkrnlpa.exe Object is locked skipped


C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16584_none_69f7a2dcb739c934\ntkrnlpa.exe Object is locked skipped


C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20629_none_6ac720a1d022400b\ntkrnlpa.exe Object is locked skipped


C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20670_none_6a880e6bd052e7b1\ntkrnlpa.exe Object is locked skipped


C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20697_none_6a797099d05cd0f4\ntkrnlpa.exe Object is locked skipped


C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20707_none_6adac1cbd013d2a2\ntkrnlpa.exe Object is locked skipped


Scan process completed.


********************************************************************************


*************************


I triied to launch hijackthis, but dosen't works.


I'd like to buz Bit defender Antivirus, because it was the best program, but I am afraid that with the PC infected, it will not works,


What i have to do ? Should I fromat the PC?


Thanks for your attention.

Comments

  • piece
    Options

    search for a BDAspy link on the forum


    use that to make a log and send that log to us

  • Obhund
    Options
    search for a BDAspy link on the forum


    use that to make a log and send that log to us


    I don't know what is the BDAspy, i used the buotton 'search' ,but i didn't find an link.

  • Obhund
    Options

    ok I founded the bdspy and i perfomed the log.


    When i try to open the log file i read this message:


    The XML page cannot be displayed


    Cannot view XML input using XSL style sheet. Please correct the error and then click the Refresh button, or try again later.


    --------------------------------------------------------------------------------


    The system cannot locate the resource specified. Error processing resource 'file:///C:/Users/Marco/Desktop/HijackList.xsl'.

  • Obhund
    Options

    this is the report of the last bitdefender scan:


    BitDefender Online Scanner - Real Time Virus Report


    Generated at: Tue, Apr 01, 2008 - 23:30:08


    Scan Info


    Scanned Files


    355982


    Infected Files 7


    Virus Detected


    Win32.Bagle.SUQ@mm 3


    Trojan.Pakes.ZUS 2


    Win32.Bagle.SVK@mm 1


    Win32.Bagle.STX@mm 1