I would be very grateful if someone could help me.
I am new to the Forum and am afraid that I do not have a great deal of experience.
I have a Sony Vaio PCG-Z1RSP laptop PC. For the last 11 months I have used McAffee Personal Firewall and McAffee Anti-virus and Internet Protection. I also use Ad-Aware. All products are kept scrupulously up-to-date. Previously I have used Norton Anti-virus.
I have recently noticed that my computer has been acting strangely. The first indication was that the tray icon for McAffee firewall appeared to be activated and then deactivated on other occasions.
I also recently had my old hard drive replacement with a new one. Reflect was used for the replacement process and it appeared to work well.
Soon after, a tray icon appeared, from McAffee, indicating that I was not protected. McAffee resisted all attempts to fix the problem through the McAffee front end.
I started to see some new files appearing when I made a routine clean with EasyCleaner. The new files were:
Each day new files based on this template appeared.
I ran McAffee but found no infection.
I ran the on-line Symantec virus scan and it indicated that: C:\windows|system32\afflb.dll was infected with Bloodhound.Overpacked.
When I deactivated the System Restore the files: SystemVolume Information\_rstore{xxxxxxxxxxxxxxxxx}.old, disappeared.
I went into Safe Mode and found that McAffee would not run. I now appreciate that AcAffee does not run in Safe Mode.
I then downloaded AVG7.5 and ran in Safe Mode with System Restore active and deactivated. No infection was found.
However, as soon as System Restore was activated the SystemVolume Information\_rstore{xxxxxxxxxxxxxxxxx}.old files returned.
I ran Ad-Aware in normal and Safe Mode with System Restore active and deactivated. No infections were found.
I installed ZoneAlarm and ran the anti-virus and anti-spyware, but without any result.
I downloaded Spybot Search and Destroy and CCleaner. I ran both in Safe Mode with System Restore active and deactivated. I deleted everything found by both programs.
I have also appended the most recent HJT file below. This was captured after running the above scanns.
I also ran the Kaspersky on-line virus scan and have appended the results below HJT.
After all of the scans the: SystemVolume Information\_rstore{xxxxxxxxxxxxxxxxx}.old files are still appearing and I am very concerned.
I sincerely apologise, in advance, if this is a topic that has been addressed before.
Can you please help.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:25:29, on 06/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Tuesday, November 06, 2007 4:43:53 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/11/2007
Kaspersky Anti-Virus database records: 452113
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
E:\
G:\
Scan Statistics
Total number of scanned objects 88995
Number of viruses found 0
Number of infected objects 0
Number of suspicious objects 0
Duration of the scan process 02:03:02
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{9F954B29-5010-4DE3-B8D1-B3E55B2A53AF}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\MSKWMDB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\RBLDB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\settingsdb.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR7.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-11062007-015816.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Phil\Application Data\MailFrontier\ASD.log Object is locked skipped
C:\Documents and Settings\Phil\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Phil\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\Phil\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Phil\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Phil\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Phil\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Phil\Local Settings\Temp\~DF7C91.tmp Object is locked skipped
C:\Documents and Settings\Phil\Local Settings\Temp\~DFB7EF.tmp Object is locked skipped
C:\Documents and Settings\Phil\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Phil\ntuser.dat Object is locked skipped
C:\Documents and Settings\Phil\NTUSER.DAT.LOG Object is locked skipped
C:\System Volume Information\38C.tmp Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{3CAC2750-5E56-4BC4-8F7A-D6A13E7F81B4}\RP1\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\Internet Logs\YOUR-BIVIOSD2X9.ldb Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{5D854D02-8E49-4EE0-BA89-65FD7AEBFABB}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\mcmsc_8KLdaPxbJepdRcV Object is locked skipped
C:\WINDOWS\Temp\mcmsc_JVdFMIHfFdaeRYo Object is locked skipped
C:\WINDOWS\Temp\mcmsc_l5bpbyyhFhuSFq6 Object is locked skipped
C:\WINDOWS\Temp\mcmsc_nTKYoELlujCkbf4 Object is locked skipped
C:\WINDOWS\Temp\sqlite_ByfQRyvbnWB70VS Object is locked skipped
C:\WINDOWS\Temp\sqlite_lAfMGo7tyvqREbu Object is locked skipped
C:\WINDOWS\Temp\sqlite_SIvihbtAnuC4jmo Object is locked skipped
C:\WINDOWS\Temp\sqlite_v5s2XmhCcgJdakv Object is locked skipped
C:\WINDOWS\Temp\ZLT03aa7.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT03aab.TMP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
As an addendum to the above posting, I have appended a PerfectDisk Drive Analysis that shows excess fragments. The fragments relate to SystemVolumeInformation.
I hope that this may be helpful and hope to hear from you.
You can get rid of all the system restore files by simply turning the system restore option off and then back on. This dumps all the previous files.But since you are having a problem i would be careful in doing so since the option to go back will not be there in case you want to go back before the dump.