Hello Dave,
I ran all the scans (Adwcleaner, antimalware, junk removal, security check)
There are no virus detected. The files encrypted by CTB-Locker have a file extension "ormmqme" right next to the regular extension. For example, it looks like this picture.jpg.ormmqme". All the files that have such extension are useless, that ia, it can not be open by the program used to create it.
Below are the logs from the scan:
ADWCLEANER LOG:
# AdwCleaner v4.202 - Logfile created 29/04/2015 at 16:17:27
# Updated 23/04/2015 by Xplode
# Database : 2015-04-27.1 [Server]
# Operating system : Microsoft Windows XP Service Pack 3 (x86)
# Username : Vu - HI-8DBADD13280B
# Running from : C:\Documents and Settings\Vu\Desktop\CLEANUP\adwcleaner_4.202.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Files / Folders ] *****
File Deleted : C:\Documents and Settings\Vu\Application Data\Mozilla\Firefox\Profiles\cr9uk1km.default\searchplugins\bingp.xml
File Deleted : C:\Program Files\Mozilla Firefox\defaults\pref\channel-prefs.JS.ormmqme
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Search
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
Key Deleted : HKCU\Software\Local AppWizard-Generated Applications
***** [ Web browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Mozilla Firefox v9.0.1 (en-US)
-\\ Google Chrome v42.0.2311.90
[C:\Documents and Settings\Vu\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] :
hxxp://search.aol.com/aol/search?q={searchTerms}[C:\Documents and Settings\Vu\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] :
hxxp://www.ask.com/web?q={searchTerms}[C:\Documents and Settings\Vu\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Extension] : fcfenmboojpjinhpgggodefccipikbpd
*************************
AdwCleaner[R0].txt - [4175 bytes] - [29/04/2015 16:02:12]
AdwCleaner[R1].txt - [3334 bytes] - [29/04/2015 16:15:01]
AdwCleaner[S0].txt - [4333 bytes] - [29/04/2015 16:02:54]
AdwCleaner[S1].txt - [3301 bytes] - [29/04/2015 16:17:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3360 bytes] ##########
JUNK REMOVAL LOG
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.6 (04.28.2015:1)
OS: Microsoft Windows XP x86
Ran by Vu on Wed 04/29/2015 at 16:22:46.12
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\\{710EB7A1-45ED-11D0-924A-0020AFC7AC4D}
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] C:\WINDOWS\wininit.ini
~~~ Folders
~~~ FireFox
Emptied folder: C:\Documents and Settings\Vu\Application Data\mozilla\firefox\profiles\cr9uk1km.default\minidumps [1 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 04/29/2015 at 16:26:18.45
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
SECURITY CHECK LOG:
Results of screen317's Security Check version 1.00
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````Windows Firewall Enabled!
Please wait while WMIC is being installed.display Name Symantec AntiVirus
Corporate Edition
Antivirus out of date! `````````Anti-malware/Other Utilities Check:`````````CCleaner
Adobe Flash Player 17.0.0.169
Adobe Reader XI
Mozilla Firefox (9.0.1)
Google Chrome (41.0.2272.118)
Google Chrome (42.0.2311.90)
````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
Malwarebytes Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````Total Fragmentation on Drive C:: 26%
Defragment your hard drive soon! (Do NOT defrag if SSD!)````````````````````End of Log``````````````````````