Limozine
2007-11-12, 03:27
Hi,
I'm so far unable to completely remove zlob.dnschanger and burstnet from my computer. Spybot keeps detecting the zlob but hasn't been able to remove it. Here's what I've done so far:
1) Run Spybot scan and clean numerous times.
2) Run Kaspersky online scan.
3) Run Fixwareout.exe.
4) Run roguefix.
5) Scanned with HJT.
Here's the Kaspersky results log:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, November 10, 2007 2:07:12 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 10/11/2007
Kaspersky Anti-Virus database records: 456002
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
W:\
Scan Statistics:
Total number of scanned objects: 308464
Number of viruses found: 11
Number of infected objects: 46
Number of suspicious objects: 0
Duration of the scan process: 04:27:21
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\03c1391ea6909ff1012833235d592c7b_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1ef77a34a0c8ee04907ecf721ccfb310_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\217d5af2f6ab10fa7f43d7dedd12240b_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\31360a6a90d89e742e381442a9849887_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\33c4589edb55a92a3377830e934614c3_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3721b63bed2920721a79925d33eb787c_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3af42a2edda8e56dae92efa231e64708_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47f43e7e919f5a7c0e11c7ca23c530c1_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55bd4324ca9da027723532b2563bf7de_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\72ffe01f6836f82a8ef02b207dadd0dc_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\768ff03707fa65e9bc15b06224f09c8e_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\786b2446aa8e6e50770f4238cf025494_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\99da4a2deafb913ed3f6daf7367cb7c4_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aa49bbc79516dee4db891d057688a29f_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b11ea927d3bb952250a3d6f49bda709c_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bfa7724e407eb4ecc5cc5ec6985aa85a_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c7187936b834aaa04dd1cfebb20c28e8_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc759392e6ee85cb6a5ebd0514868751_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e28b11462de1c87f982f0bd6841796d3_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e60c4c861e02c5f53ccecb42fc49f888_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e893450c9f4e55de295b817e4fb20aba_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed7df0ecd58e9ad3fef1e7c9bd4073f6_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff597bd9eb46a21c2425f9d1121af867_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Michael\Application Data\SpamBayes\Proxy\hammie.db Object is locked skipped
C:\Documents and Settings\Michael\Application Data\SpamBayes\Proxy\spambayes.messageinfo.db Object is locked skipped
C:\Documents and Settings\Michael\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped
C:\Documents and Settings\Michael\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Bank of America" <noreply@bankofamerica.com>][Date Fri, 28 Sep 2007 12:33:12 -0300]/html Infected: Trojan-Spy.HTML.Bankfraud.tk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "ASFLEX." <nasser@yahoo.com>][Date Wed, 25 Jul 2007 01:10:32 +0200]/UNNAMED/DC/DC 09.JPG.scr Infected: Trojan-Downloader.Win32.Small.eyf skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "ASFLEX." <nasser@yahoo.com>][Date Wed, 25 Jul 2007 01:10:32 +0200]/UNNAMED/DC Infected: Trojan-Downloader.Win32.Small.eyf skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "ASFLEX." <nasser@yahoo.com>][Date Wed, 25 Jul 2007 01:10:32 +0200]/UNNAMED Infected: Trojan-Downloader.Win32.Small.eyf skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Velma Michael" <lucja.daniell@neuimmo.com>][Date Wed, 8 Aug 2007 10:21:21 -0100]/UNNAMED/game.zip/Game.exe Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Velma Michael" <lucja.daniell@neuimmo.com>][Date Wed, 8 Aug 2007 10:21:21 -0100]/UNNAMED/game.zip Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Velma Michael" <lucja.daniell@neuimmo.com>][Date Wed, 8 Aug 2007 10:21:21 -0100]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Sophia Bowles" <marlena.dautrich@up.net>][Date Mon, 13 Aug 2007 05:29:23 -0100]/UNNAMED/LGame.zip/LGame/lgame.exe Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Sophia Bowles" <marlena.dautrich@up.net>][Date Mon, 13 Aug 2007 05:29:23 -0100]/UNNAMED/LGame.zip Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Sophia Bowles" <marlena.dautrich@up.net>][Date Mon, 13 Aug 2007 05:29:23 -0100]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Willis Seay" <teofilo.davidson@jesper.dk>][Date Mon, 20 Aug 2007 15:35:07 -0100]/UNNAMED/game.zip/game.exe Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Willis Seay" <teofilo.davidson@jesper.dk>][Date Mon, 20 Aug 2007 15:35:07 -0100]/UNNAMED/game.zip Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Willis Seay" <teofilo.davidson@jesper.dk>][Date Mon, 20 Aug 2007 15:35:07 -0100]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx Mail MS Outlook 5: infected - 13 skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Temp\SpamBayesServer1.log Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Temp\~DFA579.tmp Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Temp\~DFAB50.tmp Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Michael\My Documents\Anytime\morning.ATW Object is locked skipped
C:\Documents and Settings\Michael\My Documents\Bible Reading\mike.exe/vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
C:\Documents and Settings\Michael\My Documents\Bible Reading\mike.exe 7-Zip: infected - 1 skipped
C:\Documents and Settings\Michael\My Documents\Bible Reading\mike.exe UPX: infected - 1 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\privacy_patrol_free.exe/file8 Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\privacy_patrol_free.exe Inno: infected - 1 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\RevelationV2.zip/SetupRevelationV2.exe/WISE0012.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\RevelationV2.zip/SetupRevelationV2.exe/WISE0013.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\RevelationV2.zip/SetupRevelationV2.exe Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\RevelationV2.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\SetupRevelationV2.exe/WISE0012.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\SetupRevelationV2.exe/WISE0013.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\SetupRevelationV2.exe WiseSFX: infected - 2 skipped
C:\Documents and Settings\Michael\My Documents\HelpDesk\help.exe/vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
C:\Documents and Settings\Michael\My Documents\HelpDesk\help.exe 7-Zip: infected - 1 skipped
C:\Documents and Settings\Michael\My Documents\HelpDesk\help.exe UPX: infected - 1 skipped
C:\Documents and Settings\Michael\My Documents\USB Backup\Password Recovery\mailpv.exe Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Documents and Settings\Michael\My Documents\USB Backup\Password Recovery\SetupRevelationV2.exe/WISE0012.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\USB Backup\Password Recovery\SetupRevelationV2.exe/WISE0013.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\USB Backup\Password Recovery\SetupRevelationV2.exe WiseSFX: infected - 2 skipped
C:\Documents and Settings\Michael\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Michael\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\SnadBoy's Revelation v2\Revelation.exe Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Program Files\SnadBoy's Revelation v2\RevelationHelper.dll Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Program Files\UltraVNC\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\Program Files\UltraVNC\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 skipped
C:\Program Files\UltraVNC\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{4DF7BEB3-E3D2-473C-B32D-682F2CA7D884}\RP404\A0046074.exe/data0001 Infected: Trojan.Win32.DNSChanger.qb skipped
C:\System Volume Information\_restore{4DF7BEB3-E3D2-473C-B32D-682F2CA7D884}\RP404\A0046074.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{4DF7BEB3-E3D2-473C-B32D-682F2CA7D884}\RP404\change.log Object is locked skipped
C:\Web Sites\Aartek\mike.exe/vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
C:\Web Sites\Aartek\mike.exe 7-Zip: infected - 1 skipped
C:\Web Sites\Aartek\mike.exe UPX: infected - 1 skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{9E6798FF-C8D9-417F-BEE9-0411D207736F}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
W:\Aartek\mike.exe/vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
W:\Aartek\mike.exe 7-Zip: infected - 1 skipped
W:\Aartek\mike.exe UPX: infected - 1 skipped
Scan process completed.
I'm so far unable to completely remove zlob.dnschanger and burstnet from my computer. Spybot keeps detecting the zlob but hasn't been able to remove it. Here's what I've done so far:
1) Run Spybot scan and clean numerous times.
2) Run Kaspersky online scan.
3) Run Fixwareout.exe.
4) Run roguefix.
5) Scanned with HJT.
Here's the Kaspersky results log:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, November 10, 2007 2:07:12 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 10/11/2007
Kaspersky Anti-Virus database records: 456002
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
W:\
Scan Statistics:
Total number of scanned objects: 308464
Number of viruses found: 11
Number of infected objects: 46
Number of suspicious objects: 0
Duration of the scan process: 04:27:21
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\03c1391ea6909ff1012833235d592c7b_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1ef77a34a0c8ee04907ecf721ccfb310_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\217d5af2f6ab10fa7f43d7dedd12240b_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\31360a6a90d89e742e381442a9849887_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\33c4589edb55a92a3377830e934614c3_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3721b63bed2920721a79925d33eb787c_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3af42a2edda8e56dae92efa231e64708_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47f43e7e919f5a7c0e11c7ca23c530c1_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55bd4324ca9da027723532b2563bf7de_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\72ffe01f6836f82a8ef02b207dadd0dc_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\768ff03707fa65e9bc15b06224f09c8e_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\786b2446aa8e6e50770f4238cf025494_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\99da4a2deafb913ed3f6daf7367cb7c4_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aa49bbc79516dee4db891d057688a29f_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b11ea927d3bb952250a3d6f49bda709c_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bfa7724e407eb4ecc5cc5ec6985aa85a_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c7187936b834aaa04dd1cfebb20c28e8_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc759392e6ee85cb6a5ebd0514868751_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e28b11462de1c87f982f0bd6841796d3_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e60c4c861e02c5f53ccecb42fc49f888_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e893450c9f4e55de295b817e4fb20aba_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed7df0ecd58e9ad3fef1e7c9bd4073f6_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff597bd9eb46a21c2425f9d1121af867_c1aff602-128f-44e8-97b1-b783ba54b724 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Michael\Application Data\SpamBayes\Proxy\hammie.db Object is locked skipped
C:\Documents and Settings\Michael\Application Data\SpamBayes\Proxy\spambayes.messageinfo.db Object is locked skipped
C:\Documents and Settings\Michael\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped
C:\Documents and Settings\Michael\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Bank of America" <noreply@bankofamerica.com>][Date Fri, 28 Sep 2007 12:33:12 -0300]/html Infected: Trojan-Spy.HTML.Bankfraud.tk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "ASFLEX." <nasser@yahoo.com>][Date Wed, 25 Jul 2007 01:10:32 +0200]/UNNAMED/DC/DC 09.JPG.scr Infected: Trojan-Downloader.Win32.Small.eyf skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "ASFLEX." <nasser@yahoo.com>][Date Wed, 25 Jul 2007 01:10:32 +0200]/UNNAMED/DC Infected: Trojan-Downloader.Win32.Small.eyf skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "ASFLEX." <nasser@yahoo.com>][Date Wed, 25 Jul 2007 01:10:32 +0200]/UNNAMED Infected: Trojan-Downloader.Win32.Small.eyf skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Velma Michael" <lucja.daniell@neuimmo.com>][Date Wed, 8 Aug 2007 10:21:21 -0100]/UNNAMED/game.zip/Game.exe Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Velma Michael" <lucja.daniell@neuimmo.com>][Date Wed, 8 Aug 2007 10:21:21 -0100]/UNNAMED/game.zip Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Velma Michael" <lucja.daniell@neuimmo.com>][Date Wed, 8 Aug 2007 10:21:21 -0100]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Sophia Bowles" <marlena.dautrich@up.net>][Date Mon, 13 Aug 2007 05:29:23 -0100]/UNNAMED/LGame.zip/LGame/lgame.exe Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Sophia Bowles" <marlena.dautrich@up.net>][Date Mon, 13 Aug 2007 05:29:23 -0100]/UNNAMED/LGame.zip Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Sophia Bowles" <marlena.dautrich@up.net>][Date Mon, 13 Aug 2007 05:29:23 -0100]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.brk skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Willis Seay" <teofilo.davidson@jesper.dk>][Date Mon, 20 Aug 2007 15:35:07 -0100]/UNNAMED/game.zip/game.exe Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Willis Seay" <teofilo.davidson@jesper.dk>][Date Mon, 20 Aug 2007 15:35:07 -0100]/UNNAMED/game.zip Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Willis Seay" <teofilo.davidson@jesper.dk>][Date Mon, 20 Aug 2007 15:35:07 -0100]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Identities\{DF56823E-91B0-413F-9D8A-85CEB3BE9F2E}\Microsoft\Outlook Express\Deleted Items.dbx Mail MS Outlook 5: infected - 13 skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Temp\SpamBayesServer1.log Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Temp\~DFA579.tmp Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Temp\~DFAB50.tmp Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Michael\My Documents\Anytime\morning.ATW Object is locked skipped
C:\Documents and Settings\Michael\My Documents\Bible Reading\mike.exe/vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
C:\Documents and Settings\Michael\My Documents\Bible Reading\mike.exe 7-Zip: infected - 1 skipped
C:\Documents and Settings\Michael\My Documents\Bible Reading\mike.exe UPX: infected - 1 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\privacy_patrol_free.exe/file8 Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\privacy_patrol_free.exe Inno: infected - 1 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\RevelationV2.zip/SetupRevelationV2.exe/WISE0012.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\RevelationV2.zip/SetupRevelationV2.exe/WISE0013.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\RevelationV2.zip/SetupRevelationV2.exe Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\RevelationV2.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\SetupRevelationV2.exe/WISE0012.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\SetupRevelationV2.exe/WISE0013.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\Downloaded Programs\SetupRevelationV2.exe WiseSFX: infected - 2 skipped
C:\Documents and Settings\Michael\My Documents\HelpDesk\help.exe/vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
C:\Documents and Settings\Michael\My Documents\HelpDesk\help.exe 7-Zip: infected - 1 skipped
C:\Documents and Settings\Michael\My Documents\HelpDesk\help.exe UPX: infected - 1 skipped
C:\Documents and Settings\Michael\My Documents\USB Backup\Password Recovery\mailpv.exe Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Documents and Settings\Michael\My Documents\USB Backup\Password Recovery\SetupRevelationV2.exe/WISE0012.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\USB Backup\Password Recovery\SetupRevelationV2.exe/WISE0013.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Michael\My Documents\USB Backup\Password Recovery\SetupRevelationV2.exe WiseSFX: infected - 2 skipped
C:\Documents and Settings\Michael\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Michael\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\SnadBoy's Revelation v2\Revelation.exe Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Program Files\SnadBoy's Revelation v2\RevelationHelper.dll Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Program Files\UltraVNC\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\Program Files\UltraVNC\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 skipped
C:\Program Files\UltraVNC\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{4DF7BEB3-E3D2-473C-B32D-682F2CA7D884}\RP404\A0046074.exe/data0001 Infected: Trojan.Win32.DNSChanger.qb skipped
C:\System Volume Information\_restore{4DF7BEB3-E3D2-473C-B32D-682F2CA7D884}\RP404\A0046074.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{4DF7BEB3-E3D2-473C-B32D-682F2CA7D884}\RP404\change.log Object is locked skipped
C:\Web Sites\Aartek\mike.exe/vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
C:\Web Sites\Aartek\mike.exe 7-Zip: infected - 1 skipped
C:\Web Sites\Aartek\mike.exe UPX: infected - 1 skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{9E6798FF-C8D9-417F-BEE9-0411D207736F}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
W:\Aartek\mike.exe/vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
W:\Aartek\mike.exe 7-Zip: infected - 1 skipped
W:\Aartek\mike.exe UPX: infected - 1 skipped
Scan process completed.