system
1
hi, i’m new to this forum.
i’ve got viruses sitting in my temp folder, here are all of them, after i’ve dont bootscan, they still come back, even if i have my system restore off, and i was suffering for about 4 weeks, before asking you guys for help… if no one can help me, i’m gonna formate my PC yet again… =(((
02/27/2005 15:27
Scan of C:
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\412FKLWR\classload[1].jar\GetAccess.class is infected by JS:ClassLoader-7 - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\412FKLWR\classload[1].jar\InsecureClassLoader.class is infected by JS:Exploit-Bytverify-11 - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\412FKLWR\classload[1].jar\Dummy.class is infected by VBS:Malware [Gen] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\412FKLWR\classload[1].jar\Installer.class is infected by Win32:Trojano-477 [Trj] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\412FKLWR\down[1].exe is infected by Win32:Indown [Adw] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\412FKLWR\protector[1].exe is infected by Win32:StartPage-077 [Trj] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\412FKLWR\Worker[1].class is infected by VBS:Malware [Gen] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\412FKLWR\prompt[2].htm is infected by JS:Istbar [Trj] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\412FKLWR\CAO39E8Y.exe is infected by Win32:StartPage-077 [Trj] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\8RSTLD5X\protector[1].exe is infected by Win32:StartPage-077 [Trj] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\S5FPWGW8\Counter[1].class is infected by VBS:Malware [Gen] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\S5FPWGW8\exploit[1].htm is infected by VBS:Malware [Script] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\S5FPWGW8\VerifierBug[1].class is infected by VBS:Malware [Gen] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\WRQ965EL\Xeyond[1].class is infected by VBS:Malware [Gen] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\WRQ965EL\Gummy[1].class is infected by JS:Gummy [Trj] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\WRQ965EL\down[1].exe is infected by Win32:Indown [Adw] - Deleted
File C:\Documents and Settings\Blood\Local Settings\Temporary Internet Files\Content.IE5\WRQ965EL\CA2GYIYZ.ocx is infected by Win32:Trojano-874 [Trj] - Deleted
Number of searched folders: 4424
Number of tested files: 137738
Number of infected files: 17
Thank you, Paul.
system
2
Hi and welcome
are you aware you can(and should) just empty your temp folders regularly. it appears from your post that the files depicted have been deleted anyway .
can i suggest going herehttp://www.lurkhere.com/~nicefiles/index.html and downloading HJT then generate a log for us to review 
system
3
ok, i will by tomorrow…
yes,… they are deleted… but as soon as it logs back from bootscan, they are all restored… i’ve checked it… they ALWAYS come back…