Username "Tabion" - 12/20/2007 1:52:15 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"Logitech Utility"="Logi_MwX.Exe"
"SoundMan"="SOUNDMAN.EXE"
"MULTIMEDIA KEYBOARD"="C:\\Program Files\\Netropa\\Multimedia Keyboard\\MMKeybd.exe"
"lxdcamon"="\"C:\\Program Files\\Lexmark 1300 Series\\lxdcamon.exe\""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\windows\\system32\\ctfmon.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
[font=\"Arial\"][color=\"red\"]BitDefender Online Scanner[/color][/font]
[font=\"Arial\"]Scan report generated at: Thu, Dec 20, 2007 - 02:52:20[/font]
[font=\"Arial\"] [/font]
[font=\"Arial\"]Scan path: A:\;C:\;D:\;F:\;G:\;[/font]
[font=\"Arial\"] [/font]
[font=\"Arial\"]Statistics[/font]
[font=\"Arial\"]Time[/font]
[font=\"Arial\"]00:51:14[/font]
[font=\"Arial\"]Files[/font]
[font=\"Arial\"]192896[/font]
[font=\"Arial\"]Folders[/font]
[font=\"Arial\"]5259[/font]
[font=\"Arial\"]Boot Sectors[/font]
[font=\"Arial\"]4[/font]
[font=\"Arial\"]Archives[/font]
[font=\"Arial\"]1799[/font]
[font=\"Arial\"]Packed Files[/font]
[font=\"Arial\"]9570[/font]
[font=\"Arial\"]Results[/font]
[font=\"Arial\"]Identified Viruses [/font]
[font=\"Arial\"]1[/font]
[font=\"Arial\"]Infected Files [/font]
[font=\"Arial\"]2[/font]
[font=\"Arial\"]Suspect Files [/font]
[font=\"Arial\"]0[/font]
[font=\"Arial\"]Warnings[/font]
[font=\"Arial\"]0[/font]
[font=\"Arial\"]Disinfected[/font]
[font=\"Arial\"]0[/font]
[font=\"Arial\"]Deleted Files[/font]
[font=\"Arial\"]2[/font]
[font=\"Arial\"]Engines Info[/font]
[font=\"Arial\"]Virus Definitions[/font]
[font=\"Arial\"]882639[/font]
[font=\"Arial\"]Engine build[/font]
[font=\"Arial\"]AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)[/font]
[font=\"Arial\"]Scan plugins[/font]
[font=\"Arial\"]14[/font]
[font=\"Arial\"]Archive plugins[/font]
[font=\"Arial\"]38[/font]
[font=\"Arial\"]Unpack plugins[/font]
[font=\"Arial\"]7[/font]
[font=\"Arial\"]E-mail plugins[/font]
[font=\"Arial\"]6[/font]
[font=\"Arial\"]System plugins[/font]
[font=\"Arial\"]1[/font]
[font=\"Arial\"]Scan Settings[/font]
[font=\"Arial\"]First Action[/font]
[font=\"Arial\"]Disinfect[/font]
[font=\"Arial\"]Second Action[/font]
[font=\"Arial\"]Delete[/font]
[font=\"Arial\"]Heuristics[/font]
[font=\"Arial\"]Yes[/font]
[font=\"Arial\"]Enable Warnings[/font]
[font=\"Arial\"]Yes[/font]
[font=\"Arial\"]Scanned Extensions[/font]
[font=\"Arial\"]*;[/font]
[font=\"Arial\"]Exclude Extensions[/font]
[font=\"Arial\"] [/font]
[font=\"Arial\"]Scan Emails[/font]
[font=\"Arial\"]Yes[/font]
[font=\"Arial\"]Scan Archives[/font]
[font=\"Arial\"]Yes[/font]
[font=\"Arial\"]Scan Packed[/font]
[font=\"Arial\"]Yes[/font]
[font=\"Arial\"]Scan Files[/font]
[font=\"Arial\"]Yes[/font]
[font=\"Arial\"]Scan Boot[/font]
[font=\"Arial\"]Yes[/font]
[font=\"Arial\"]Scanned File[/font]
[font=\"Arial\"] Status[/font]
[font=\"Arial\"]C:\qoobox\Quarantine\C\WINDOWS\system32\kdfol.exe.vir[/font]
[font=\"Arial\"]Infected with: Trojan.DNSCHanger.QN[/font]
[font=\"Arial\"]C:\qoobox\Quarantine\C\WINDOWS\system32\kdfol.exe.vir[/font]
[font=\"Arial\"]Disinfection failed[/font]
[font=\"Arial\"]C:\qoobox\Quarantine\C\WINDOWS\system32\kdfol.exe.vir[/font]
[font=\"Arial\"]Deleted[/font]
[font=\"Arial\"]C:\System Volume Information\_restore{10955F49-53EE-4A1A-9980-F6DF3FA35510}\RP2\A0000012.exe[/font]
[font=\"Arial\"]Infected with: Trojan.DNSCHanger.QN[/font]
[font=\"Arial\"]C:\System Volume Information\_restore{10955F49-53EE-4A1A-9980-F6DF3FA35510}\RP2\A0000012.exe[/font]
[font=\"Arial\"]Disinfection failed[/font]
[font=\"Arial\"]C:\System Volume Information\_restore{10955F49-53EE-4A1A-9980-F6DF3FA35510}\RP2\A0000012.exe[/font]
[font=\"Arial\"]Deleted[/font]
[font=\"Arial\"] [/font]
[font=\"Arial\"] [/font]
Well, there very well be my problem!
Any suggestions on proper removal?