Hi,
Hope you guys can help me with this one. I ran an AVG scan and it came up with 2 infections it couldn't remove. Here's the log:
"Scan ""Scheduled scan"" was finished."
"Infections";"2";"0";"2"
"Folders selected for scanning:";"Scan whole computer"
"Scan started:";"23 November 2009, Monday, 05:00:01"
"Scan finished:";"23 November 2009, Monday, 05:34:50 (34 minute(s) 48 second(s))"
"Total object scanned:";"511050"
"User who launched the scan:";"SYSTEM"
"Infections"
"File";"Infection";"Result"
"C:\$Recycle.Bin\S-1-5-21-4097568201-891318238-3029008619-1000\$RQ56APU\Fast and Furious 4.exe:\$JF\wmplayer.exe";"Trojan horse Dropper.Generic.AQAO";"Infected"
"C:\$Recycle.Bin\S-1-5-21-4097568201-891318238-3029008619-1000\$RQ56APU\Fast and Furious 4.exe";"Trojan horse Dropper.Generic.AQAO";"Infected"
When I try to remove the infections manually (or put them in the vault), I receive this error:

Clicking "Ignore" brings up this error:

Clicking "Go to file"" brings up the same error and takes me to the recycle bin (C:\$Recycle.Bin), which is empty.
So what's with this file? and what's with "wmplayer.exe" that also shows up as an infection?
When I saw that "$JF\wmplayer.exe" bit, I thought maybe it was my friend who plugged in his disk-on-key a few days ago while I was away (hence the letter "F" showing up. Also I have no driver named "F"). His disk-on-key had many files on it and maybe he ran this "Fast and Furious 4.exe" file. Could this be a "ghost" file or something?
MBAM log:
Malwarebytes' Anti-Malware 1.41
Database version: 3217
Windows 6.0.6001 Service Pack 1
23/11/2009 15:51:56
mbam-log-2009-11-23 (15-51-56).txt
Scan type: Quick Scan
Objects scanned: 92213
Time elapsed: 5 minute(s), 27 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
RootRepeal log:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2009/11/23 15:54
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================
Drivers
-------------------
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x904B0000 Size: 45056 File Visible: No Signed: -
Status: -
Name: dump_msahci.sys
Image Path: C:\Windows\System32\Drivers\dump_msahci.sys
Address: 0x904BB000 Size: 40960 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0xAF96A000 Size: 49152 File Visible: No Signed: -
Status: -
Name: splz.sys
Image Path: C:\Windows\System32\Drivers\splz.sys
Address: 0x8068B000 Size: 1048576 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name:
Image Path:
Address: 0x8F9C3000 Size: 53248 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name:
Image Path:
Address: 0x8F6CD000 Size: 249856 File Visible: No Signed: -
Status: Hidden from the Windows API!
Processes
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1688 Status: Locked to the Windows API!
SSDT
-------------------
#: 012 Function Name: NtAdjustPrivilegesToken
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d5f32
#: 021 Function Name: NtAlpcConnectPort
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d7182
#: 022 Function Name: NtAlpcCreatePort
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d6118
#: 054 Function Name: NtConnectPort
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d5292
#: 060 Function Name: NtCreateFile
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d5ad6
#: 071 Function Name: NtCreatePort
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d5174
#: 075 Function Name: NtCreateSection
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d592c
#: 077 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d6e3c
#: 078 Function Name: NtCreateThread
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d4d3a
#: 129 Function Name: NtDuplicateObject
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d4a9c
#: 165 Function Name: NtLoadDriver
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d6abe
#: 174 Function Name: NtMakeTemporaryObject
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d5516
#: 186 Function Name: NtOpenFile
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d5d1a
#: 194 Function Name: NtOpenProcess
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d47cc
#: 197 Function Name: NtOpenSection
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d57a6
#: 201 Function Name: NtOpenThread
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d4944
#: 276 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d65d8
#: 286 Function Name: NtSecureConnectPort
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d685a
#: 317 Function Name: NtSetSystemInformation
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d6c6c
#: 326 Function Name: NtShutdownSystem
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d54b0
#: 332 Function Name: NtSystemDebugControl
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d569a
#: 334 Function Name: NtTerminateProcess
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d503e
#: 335 Function Name: NtTerminateThread
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d4f0c
#: 382 Function Name: NtCreateThreadEx
Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8f5d6224
==EOF==next post...