Then I tried ren C:\WINDOWS\explorer.exe C:\WINDOWS\explorer.old
This didn't work - it said invalid parameter. But I then I looked under the help for 'ren' and found this:
Renames a file or files.
RENAME [drive:][path]filename1 filename2.
REN [drive:][path]filename1 filename2.
Note that you cannot specify a new drive or path for your destination file.
So what I did instead was CD into the windows directory, and ran ren explorer.exe explorer.old, CD back into C:\, then I ran the copy command to replace it. I did the same thing for the other files (Except I did it from C:\WINDOWS\system32\) and it seemed to work. I _think_ this had the same effect as what you asked me to do, but I'm not sure.
I rebooted the computer and scanned:
Avira AntiVir Personal
Report file date: Friday, July 10, 2009 15:45
Scanning for 1448372 virus strains and unwanted programs.
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : 1ECA66A679AB494
Version information:
BUILD.DAT : 9.0.0.403 17961 Bytes 6/3/2009 17:05:00
AVSCAN.EXE : 9.0.3.6 466689 Bytes 5/11/2009 14:14:47
AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 15:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 16:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 15:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 17:30:36
ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 6/24/2009 01:29:46
ANTIVIR2.VDF : 7.1.4.173 306688 Bytes 7/2/2009 01:29:49
ANTIVIR3.VDF : 7.1.4.182 52224 Bytes 7/5/2009 01:29:50
Engineversion : 8.2.0.204
AEVDF.DLL : 8.1.1.1 106868 Bytes 4/30/2009 16:52:04
AESCRIPT.DLL : 8.1.2.13 426362 Bytes 7/6/2009 01:30:05
AESCN.DLL : 8.1.2.3 127347 Bytes 5/14/2009 16:02:01
AERDL.DLL : 8.1.2.2 438642 Bytes 7/6/2009 01:30:04
AEPACK.DLL : 8.1.3.18 401783 Bytes 5/27/2009 21:07:20
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 7/6/2009 01:30:01
AEHEUR.DLL : 8.1.0.137 1823095 Bytes 7/6/2009 01:30:00
AEHELP.DLL : 8.1.3.6 205174 Bytes 7/6/2009 01:29:52
AEGEN.DLL : 8.1.1.48 348532 Bytes 7/6/2009 01:29:51
AEEMU.DLL : 8.1.0.9 393588 Bytes 10/9/2008 19:32:40
AECORE.DLL : 8.1.6.12 180599 Bytes 5/27/2009 21:07:20
AEBB.DLL : 8.1.0.3 53618 Bytes 10/9/2008 19:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 13:47:59
AVPREF.DLL : 9.0.0.1 43777 Bytes 12/5/2008 15:32:15
AVREP.DLL : 8.0.0.3 155905 Bytes 1/20/2009 19:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 15:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 3/24/2009 20:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 15:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 20:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 13:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 15:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 5/15/2009 20:39:58
RCTEXT.DLL : 9.0.37.0 86785 Bytes 4/17/2009 15:19:48
Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Start of the scan: Friday, July 10, 2009 15:45
Starting search for hidden objects.
'53848' objects were checked, '0' hidden objects were found.
The scan of running processes will be started
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'veohwebplayer.exe' - '1' Module(s) have been scanned
Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'RegSrvc.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'LEXPPS.EXE' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'LEXBCES.EXE' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'S24EvMon.exe' - '1' Module(s) have been scanned
Scan process 'EvtEng.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
35 processes with 35 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
The registry was scanned ( '60' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\ASP357.tmp\aspapp\ocpinst.exe
[0] Archive type: NSIS
--> [UnknownDir]
[WARNING] No further files can be extracted from this archive. The archive will be closed
[WARNING] No further files can be extracted from this archive. The archive will be closed
C:\Program Files\MSN Messenger\msimg32.dll
[DETECTION] Contains recognition pattern of the ADSPY/FunWeb adware or spyware
C:\Qoobox\Quarantine\C\Documents and Settings\Jennifer\dcduasm.exe.vir
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Jennifer\Jennifer.exe.vir
[DETECTION] Is the TR/Rabbit.JU Trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACmnuemwpejjuxeir.dll.vir
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACmwjjnfrwhbmxfmx.dll.vir
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACpypiqqowksgvxdk.dll.vir
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACrpmiqtdyxgsfkwh.dll.vir
[DETECTION] Is the TR/TDss.aebu Trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\uactmp.db.vir
[DETECTION] Contains HEUR/HTML.Malware suspicious code
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACwrkjxmjafxneirv.dll.vir
[DETECTION] Is the TR/TDss.adzz Trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\wiawow32.sys.vir
[DETECTION] Is the TR/ATRAPS.Gen Trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACawviwewbsbxjccv.sys.vir
[DETECTION] Contains recognition pattern of the RKIT/TDss.Y.23 root kit
C:\Qoobox\Quarantine\C\WINDOWS\system32\wbem\grpconv.exe.vir
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP745\A0101425.exe
[0] Archive type: NSIS
--> [PluginsDir]/utility.dll
[DETECTION] Is the TR/StartPage.21845.K Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP745\A0101430.exe
[0] Archive type: NSIS
--> [PluginsDir]/utility.dll
[DETECTION] Is the TR/StartPage.21845.K Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP745\A0101432.exe
[0] Archive type: NSIS
--> [PluginsDir]/utility.dll
[DETECTION] Is the TR/StartPage.HMI Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148901.sys
[DETECTION] Contains recognition pattern of the RKIT/TDss.Y.23 root kit
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148902.dll
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148903.dll
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148904.dll
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148905.dll
[DETECTION] Is the TR/TDss.adzz Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148906.dll
[DETECTION] Is the TR/TDss.aebu Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148936.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148937.exe
[DETECTION] Is the TR/Rabbit.JU Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148946.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148947.sys
[DETECTION] Is the TR/ATRAPS.Gen Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0149089.dll
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0149090.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP791\A0149178.exe
[DETECTION] Is the TR/Agent.1436664 Trojan
C:\WINDOWS\explorer.old
[DETECTION] Is the TR/Patched.AA.522 Trojan
C:\WINDOWS\system32\lsass.old
[DETECTION] Is the TR/Patched.Gen Trojan
C:\WINDOWS\system32\services.old
[DETECTION] Is the TR/Patched.Gen Trojan
C:\WINDOWS\system32\winlogon.old
[DETECTION] Is the TR/Patched.AA.546 Trojan
Beginning disinfection:
C:\Program Files\MSN Messenger\msimg32.dll
[DETECTION] Contains recognition pattern of the ADSPY/FunWeb adware or spyware
[WARNING] The file was ignored!
C:\Qoobox\Quarantine\C\Documents and Settings\Jennifer\dcduasm.exe.vir
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[WARNING] The file was ignored!
C:\Qoobox\Quarantine\C\Documents and Settings\Jennifer\Jennifer.exe.vir
[DETECTION] Is the TR/Rabbit.JU Trojan
[WARNING] The file was ignored!
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACmnuemwpejjuxeir.dll.vir
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
[WARNING] The file was ignored!
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACmwjjnfrwhbmxfmx.dll.vir
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
[WARNING] The file was ignored!
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACpypiqqowksgvxdk.dll.vir
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
[WARNING] The file was ignored!
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACrpmiqtdyxgsfkwh.dll.vir
[DETECTION] Is the TR/TDss.aebu Trojan
[WARNING] The file was ignored!
C:\Qoobox\Quarantine\C\WINDOWS\system32\uactmp.db.vir
[DETECTION] Contains HEUR/HTML.Malware suspicious code
[NOTE] The detection was classified as suspicious.
[WARNING] The file was ignored!
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACwrkjxmjafxneirv.dll.vir
[DETECTION] Is the TR/TDss.adzz Trojan
[WARNING] The file was ignored!
C:\Qoobox\Quarantine\C\WINDOWS\system32\wiawow32.sys.vir
[DETECTION] Is the TR/ATRAPS.Gen Trojan
[WARNING] The file was ignored!
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACawviwewbsbxjccv.sys.vir
[DETECTION] Contains recognition pattern of the RKIT/TDss.Y.23 root kit
[WARNING] The file was ignored!
C:\Qoobox\Quarantine\C\WINDOWS\system32\wbem\grpconv.exe.vir
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP745\A0101425.exe
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP745\A0101430.exe
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP745\A0101432.exe
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148901.sys
[DETECTION] Contains recognition pattern of the RKIT/TDss.Y.23 root kit
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148902.dll
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148903.dll
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148904.dll
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148905.dll
[DETECTION] Is the TR/TDss.adzz Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148906.dll
[DETECTION] Is the TR/TDss.aebu Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148936.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148937.exe
[DETECTION] Is the TR/Rabbit.JU Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148946.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0148947.sys
[DETECTION] Is the TR/ATRAPS.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0149089.dll
[DETECTION] Is the TR/Trash.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP789\A0149090.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP791\A0149178.exe
[DETECTION] Is the TR/Agent.1436664 Trojan
[WARNING] The file was ignored!
C:\WINDOWS\explorer.old
[DETECTION] Is the TR/Patched.AA.522 Trojan
[WARNING] The file was ignored!
C:\WINDOWS\system32\lsass.old
[DETECTION] Is the TR/Patched.Gen Trojan
[WARNING] The file was ignored!
C:\WINDOWS\system32\services.old
[DETECTION] Is the TR/Patched.Gen Trojan
[WARNING] The file was ignored!
C:\WINDOWS\system32\winlogon.old
[DETECTION] Is the TR/Patched.AA.546 Trojan
[WARNING] The file was ignored!
End of the scan: Friday, July 10, 2009 16:34
Used time: 48:21 Minute(s)
The scan has been done completely.
6702 Scanned directories
375742 Files were scanned
31 Viruses and/or unwanted programs were found
1 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
0 Files were moved to quarantine
0 Files were renamed
2 Files cannot be scanned
375708 Files not concerned
9303 Archives were scanned
36 Warnings
3 Notes
53848 Objects were scanned with rootkit scan
0 Hidden objects were found