Bitdefender keeps warning me that I have a trojan named trojan SwfDL.A and disinfection failed. I have scanned with ewido and ActiveScan but they do not detect it.
I have tried to delete the six infected files, but I cannot find them using the windows browser. I am also unable to delete them by going to the control panel, under internet options, and deleting the temporary files. I am posting a bitdefender report to show you where the files are supposed to be, along with a Hijack This file.
please advise.
Following is Bitdefender scan report
//-----------------------------------------------------------------
//
// Product: BitDefender 9 Professional Plus
// Version: 9.5
//
// Created on: 23/06/2006 14:23:10
//
//-----------------------------------------------------------------
Statistics
Scan path : C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files
Folders : 13
Files : 208
Archives : 10
Packed files : 1
Identified viruses : 1
Infected files : 6
Warnings : 0
Suspect files : 0
Disinfected files : 0
Deleted files : 6
Copied files : 0
Moved files : 0
Renamed files : 0
I/O errors : 0
Scan time : 00:00:52
Scan speed (files/sec) : 4
Spyware Statistics
Memory processes scanned : 21
Memory processes infected : 0
Registry keys scanned : 902
Registry keys infected : 0
Cookies scanned : 0
Cookies infected : 0
Spyware files infected : 0
Spyware threats detected : 0
Virus definitions : 415299
Scan plugins : 15
Archive plugins : 42
Unpack plugins : 5
Mail plugins : 6
System plugins : 5
Scan options
Detection
[X] Scan boot sectors
[X] Scan archives
[X] Scan packed files
[X] Scan email
File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;
Action
Infected objects
[ ] Ignore
[X] Disinfect
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[ ] Prompt user
Second action
[ ] Ignore
[X] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[ ] Prompt user
Scan options
[X] Enable warnings
[X] Enable heuristics
[ ] Show all files in log
[X] Report file: C:\Program Files\Softwin\BitDefender9\Logs\vscan_1151090590.l og
Spyware scan options
[X] Memory Processes
[X] Registry keys
[X] Cookies
Summary:
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\6RU9C3WT\sp2-cydoor-728[1].swf=>[SWF command] Infected: Trojan.SwfDL.A
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\6RU9C3WT\sp2-cydoor-728[1].swf=>[SWF command] Disinfection failed
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\6RU9C3WT\sp2-cydoor-728[1].swf=>[SWF command] Deleted
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\6RU9C3WT\sp2-cydoor-728[1].swf Update failed
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8T634D6Z\sp2-cydoor-728[1].swf=>[SWF command] Infected: Trojan.SwfDL.A
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8T634D6Z\sp2-cydoor-728[1].swf=>[SWF command] Disinfection failed
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8T634D6Z\sp2-cydoor-728[1].swf=>[SWF command] Deleted
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8T634D6Z\sp2-cydoor-728[1].swf Update failed
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\9SKNXDG5\sp2-cydoor-728[1].swf=>[SWF command] Infected: Trojan.SwfDL.A
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\9SKNXDG5\sp2-cydoor-728[1].swf=>[SWF command] Disinfection failed
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\9SKNXDG5\sp2-cydoor-728[1].swf=>[SWF command] Deleted
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\9SKNXDG5\sp2-cydoor-728[1].swf Update failed
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\M99Y32LS\sp2-cydoor-728[1].swf=>[SWF command] Infected: Trojan.SwfDL.A
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\M99Y32LS\sp2-cydoor-728[1].swf=>[SWF command] Disinfection failed
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\M99Y32LS\sp2-cydoor-728[1].swf=>[SWF command] Deleted
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\M99Y32LS\sp2-cydoor-728[1].swf Update failed
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\W9YZ09EF\sp2-cydoor-728[1].swf=>[SWF command] Infected: Trojan.SwfDL.A
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\W9YZ09EF\sp2-cydoor-728[1].swf=>[SWF command] Disinfection failed
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\W9YZ09EF\sp2-cydoor-728[1].swf=>[SWF command] Deleted
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\W9YZ09EF\sp2-cydoor-728[1].swf Update failed
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\WTUJQBW3\sp2-cydoor-728[1].swf=>[SWF command] Infected: Trojan.SwfDL.A
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\WTUJQBW3\sp2-cydoor-728[1].swf=>[SWF command] Disinfection failed
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\WTUJQBW3\sp2-cydoor-728[1].swf=>[SWF command] Deleted
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\WTUJQBW3\sp2-cydoor-728[1].swf Update failed
Here is my Hijack This log:
Logfile of HijackThis v1.99.1
Scan saved at 2:37:51 PM, on 6/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Softwin\BitDefender9\bdoesrv.exe
C:\progra~1\softwin\bitdef~1\bdnagent.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\lotus\organize\easyclip.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Citrix\ICA Client\pn.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Citrix\ICA Client\Wfcrun32.exe
C:\PROGRA~1\Citrix\ICACLI~1\WFICA32.EXE
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender9\vsserv.exe
c:\program files\softwin\bitdefender9\bdmcon.exe
C:\Program Files\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.scroogle.org/scrapen8.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [BDMCon] c:\progra~1\softwin\bitdef~1\bdmcon.exe
O4 - HKLM\..\Run: [BDOESRV] "C:\Program Files\Softwin\BitDefender9\bdoesrv.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "c:\program files\softwin\bitdefender9\bdnagent.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RegDoctor] C:\Program Files\RegDoctor\RegDoctor.exe -Quick
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Lotus Organizer EasyClip.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Subscribe to... - \feedscript.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1133082041592
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1135393219166
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender9\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)


