mccodd3
2007-11-18, 07:51
I am not a huge computer no it all but I followed your instructions using the Kaspersky scan online. I have this annoying IEXPLORE.exe process that i keep trying to end and it keeps popping back up using 99% of my cpu and very annoying pop ups, slowing my computer way down. I'm sure you guys have seen this a million times I just wanted to post my scan log and ask what further action I should take, thanks guys!
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, November 17, 2007 9:32:58 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/11/2007
Kaspersky Anti-Virus database records: 461025
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 200858
Number of viruses found: 6
Number of infected objects: 51
Number of suspicious objects: 0
Duration of the scan process: 04:21:39
Infected Object Name / Virus Name / Last Action
C:\4bee52ba43fdd18e7c4a16f7\spmsg.dll Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\spuninst.exe Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\branches.inf Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\eula.txt Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\KB883523.CAT Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\spcustom.dll Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\update.exe Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\update.ver Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\updatebr.inf Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\update_SP2QFE.inf Object is locked skipped
C:\Documents and Settings\All Users\Application Data\file joy proc deaf\User Ace.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Retrospect Client\retroclient.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\WFUR522005\Application Data\Aim\haqctmcd\doolrpk\cert8.db Object is locked skipped
C:\Documents and Settings\WFUR522005\Application Data\Aim\haqctmcd\doolrpk\key3.db Object is locked skipped
C:\Documents and Settings\WFUR522005\Application Data\coal mags site\gwbwhfxm.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\Documents and Settings\WFUR522005\Application Data\coal mags site\roapehre.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\Documents and Settings\WFUR522005\Application Data\coal mags site\ShowPeak.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\Documents and Settings\WFUR522005\Application Data\coal mags site\soft ooze city.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\Documents and Settings\WFUR522005\Application Data\coal mags site\susifmti.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Brian" <Brian@lose-it-fast.biz>][Date Mon, 27 Sep 2004 15:49:21 -0800]/html/[From Smith Barney <identifdep_ref75899015999@smithbarney.com>][Date Tue, 28 Sep 2004 04:30:55 +0300]/html Infected: Trojan-Spy.HTML.Smitfraud.c skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Brian" <Brian@lose-it-fast.biz>][Date Mon, 27 Sep 2004 15:49:21 -0800]/html Infected: Trojan-Spy.HTML.Smitfraud.c skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Lucy" <Lucy@lose-it-fast.biz>][Date Wed, 29 Sep 2004 19:13:07 -0800]/text/[From Suntrust Bank <identdep_op42301704993@suntrust.com>][Date Thu, 30 Sep 2004 12:07:40 +0100]/html Infected: Trojan-Spy.HTML.Bankfraud.u skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Lucy" <Lucy@lose-it-fast.biz>][Date Wed, 29 Sep 2004 19:13:07 -0800]/text Infected: Trojan-Spy.HTML.Bankfraud.u skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Irma Schafer" <PNVYCHQJZMK@lineone.net>][Date Fri, 01 Oct 2004 21:51:29 +0400]/UNNAMED/[From "JACQUELINE" <adellenott@superpstore.every1.net>][Date Fri, 01 Oct 2004 23:15:37 -0500]/UNNAMED/[From "Vernon " <rzztpaxbmq@freemail.ru>][Date Sat, 02 Oct 2004 11:13:09 +0400]/html/[From "Antidote found in Crocodiles" <zytarqysmk@agt.net>][Date Sun, 03 Oct 2004 17:12:09 +0600]/UNNAMED/[From Citibank <antifraud.ref.num564773565@citibank.com>][Date Sun, 03 Oct 2004 11:37:52 -0200]/UNNAMED/html Infected: Trojan-Spy.HTML.Citifraud.ai skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Irma Schafer" <PNVYCHQJZMK@lineone.net>][Date Fri, 01 Oct 2004 21:51:29 +0400]/UNNAMED/[From "JACQUELINE" <adellenott@superpstore.every1.net>][Date Fri, 01 Oct 2004 23:15:37 -0500]/UNNAMED/[From "Vernon " <rzztpaxbmq@freemail.ru>][Date Sat, 02 Oct 2004 11:13:09 +0400]/html/[From "Antidote found in Crocodiles" <zytarqysmk@agt.net>][Date Sun, 03 Oct 2004 17:12:09 +0600]/UNNAMED/[From Citibank <antifraud.ref.num564773565@citibank.com>][Date Sun, 03 Oct 2004 11:37:52 -0200]/UNNAMED Infected: Trojan-Spy.HTML.Citifraud.ai skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Irma Schafer" <PNVYCHQJZMK@lineone.net>][Date Fri, 01 Oct 2004 21:51:29 +0400]/UNNAMED/[From "JACQUELINE" <adellenott@superpstore.every1.net>][Date Fri, 01 Oct 2004 23:15:37 -0500]/UNNAMED/[From "Vernon " <rzztpaxbmq@freemail.ru>][Date Sat, 02 Oct 2004 11:13:09 +0400]/html/[From "Antidote found in Crocodiles" <zytarqysmk@agt.net>][Date Sun, 03 Oct 2004 17:12:09 +0600]/UNNAMED Infected: Trojan-Spy.HTML.Citifraud.ai skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Irma Schafer" <PNVYCHQJZMK@lineone.net>][Date Fri, 01 Oct 2004 21:51:29 +0400]/UNNAMED/[From "JACQUELINE" <adellenott@superpstore.every1.net>][Date Fri, 01 Oct 2004 23:15:37 -0500]/UNNAMED/[From "Vernon " <rzztpaxbmq@freemail.ru>][Date Sat, 02 Oct 2004 11:13:09 +0400]/html Infected: Trojan-Spy.HTML.Citifraud.ai skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Irma Schafer" <PNVYCHQJZMK@lineone.net>][Date Fri, 01 Oct 2004 21:51:29 +0400]/UNNAMED/[From "JACQUELINE" <adellenott@superpstore.every1.net>][Date Fri, 01 Oct 2004 23:15:37 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Citifraud.ai skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Irma Schafer" <PNVYCHQJZMK@lineone.net>][Date Fri, 01 Oct 2004 21:51:29 +0400]/UNNAMED Infected: Trojan-Spy.HTML.Citifraud.ai skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash Mail Berkeley mbox: infected - 10 skipped
C:\Documents and Settings\WFUR522005\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbc2e.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbdam Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbdao Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbeam Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbeao Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbm Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbu2d.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbvm.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbvmh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\fii.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\fiih.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\hp Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\hpt2i.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\rpm.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\rpm1m.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\rpm1mh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\rpmh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-black-enchashm.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-black-enchashmh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-black-urlm.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-black-urlmh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-malware-domainm.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-malware-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-white-domainm.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-white-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\History\History.IE5\MSHist012007111720071118\index.dat Object is locked skipped
C:\Documents and Settings\WFUR522005\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\WFUR522005\ntuser.dat.LOG Object is locked skipped
C:\logfiles\pfirewall.log Object is locked skipped
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2007-11-17.16-39-54.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\TEMP\bis10.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\TEMP\bis11.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\TEMP\bis144D.exe Infected: Trojan.Win32.Obfuscated.en skipped
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, November 17, 2007 9:32:58 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/11/2007
Kaspersky Anti-Virus database records: 461025
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 200858
Number of viruses found: 6
Number of infected objects: 51
Number of suspicious objects: 0
Duration of the scan process: 04:21:39
Infected Object Name / Virus Name / Last Action
C:\4bee52ba43fdd18e7c4a16f7\spmsg.dll Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\spuninst.exe Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\branches.inf Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\eula.txt Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\KB883523.CAT Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\spcustom.dll Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\update.exe Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\update.ver Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\updatebr.inf Object is locked skipped
C:\4bee52ba43fdd18e7c4a16f7\update\update_SP2QFE.inf Object is locked skipped
C:\Documents and Settings\All Users\Application Data\file joy proc deaf\User Ace.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Retrospect Client\retroclient.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\WFUR522005\Application Data\Aim\haqctmcd\doolrpk\cert8.db Object is locked skipped
C:\Documents and Settings\WFUR522005\Application Data\Aim\haqctmcd\doolrpk\key3.db Object is locked skipped
C:\Documents and Settings\WFUR522005\Application Data\coal mags site\gwbwhfxm.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\Documents and Settings\WFUR522005\Application Data\coal mags site\roapehre.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\Documents and Settings\WFUR522005\Application Data\coal mags site\ShowPeak.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\Documents and Settings\WFUR522005\Application Data\coal mags site\soft ooze city.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\Documents and Settings\WFUR522005\Application Data\coal mags site\susifmti.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Brian" <Brian@lose-it-fast.biz>][Date Mon, 27 Sep 2004 15:49:21 -0800]/html/[From Smith Barney <identifdep_ref75899015999@smithbarney.com>][Date Tue, 28 Sep 2004 04:30:55 +0300]/html Infected: Trojan-Spy.HTML.Smitfraud.c skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Brian" <Brian@lose-it-fast.biz>][Date Mon, 27 Sep 2004 15:49:21 -0800]/html Infected: Trojan-Spy.HTML.Smitfraud.c skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Lucy" <Lucy@lose-it-fast.biz>][Date Wed, 29 Sep 2004 19:13:07 -0800]/text/[From Suntrust Bank <identdep_op42301704993@suntrust.com>][Date Thu, 30 Sep 2004 12:07:40 +0100]/html Infected: Trojan-Spy.HTML.Bankfraud.u skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Lucy" <Lucy@lose-it-fast.biz>][Date Wed, 29 Sep 2004 19:13:07 -0800]/text Infected: Trojan-Spy.HTML.Bankfraud.u skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Irma Schafer" <PNVYCHQJZMK@lineone.net>][Date Fri, 01 Oct 2004 21:51:29 +0400]/UNNAMED/[From "JACQUELINE" <adellenott@superpstore.every1.net>][Date Fri, 01 Oct 2004 23:15:37 -0500]/UNNAMED/[From "Vernon " <rzztpaxbmq@freemail.ru>][Date Sat, 02 Oct 2004 11:13:09 +0400]/html/[From "Antidote found in Crocodiles" <zytarqysmk@agt.net>][Date Sun, 03 Oct 2004 17:12:09 +0600]/UNNAMED/[From Citibank <antifraud.ref.num564773565@citibank.com>][Date Sun, 03 Oct 2004 11:37:52 -0200]/UNNAMED/html Infected: Trojan-Spy.HTML.Citifraud.ai skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Irma Schafer" <PNVYCHQJZMK@lineone.net>][Date Fri, 01 Oct 2004 21:51:29 +0400]/UNNAMED/[From "JACQUELINE" <adellenott@superpstore.every1.net>][Date Fri, 01 Oct 2004 23:15:37 -0500]/UNNAMED/[From "Vernon " <rzztpaxbmq@freemail.ru>][Date Sat, 02 Oct 2004 11:13:09 +0400]/html/[From "Antidote found in Crocodiles" <zytarqysmk@agt.net>][Date Sun, 03 Oct 2004 17:12:09 +0600]/UNNAMED/[From Citibank <antifraud.ref.num564773565@citibank.com>][Date Sun, 03 Oct 2004 11:37:52 -0200]/UNNAMED Infected: Trojan-Spy.HTML.Citifraud.ai skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Irma Schafer" <PNVYCHQJZMK@lineone.net>][Date Fri, 01 Oct 2004 21:51:29 +0400]/UNNAMED/[From "JACQUELINE" <adellenott@superpstore.every1.net>][Date Fri, 01 Oct 2004 23:15:37 -0500]/UNNAMED/[From "Vernon " <rzztpaxbmq@freemail.ru>][Date Sat, 02 Oct 2004 11:13:09 +0400]/html/[From "Antidote found in Crocodiles" <zytarqysmk@agt.net>][Date Sun, 03 Oct 2004 17:12:09 +0600]/UNNAMED Infected: Trojan-Spy.HTML.Citifraud.ai skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Irma Schafer" <PNVYCHQJZMK@lineone.net>][Date Fri, 01 Oct 2004 21:51:29 +0400]/UNNAMED/[From "JACQUELINE" <adellenott@superpstore.every1.net>][Date Fri, 01 Oct 2004 23:15:37 -0500]/UNNAMED/[From "Vernon " <rzztpaxbmq@freemail.ru>][Date Sat, 02 Oct 2004 11:13:09 +0400]/html Infected: Trojan-Spy.HTML.Citifraud.ai skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Irma Schafer" <PNVYCHQJZMK@lineone.net>][Date Fri, 01 Oct 2004 21:51:29 +0400]/UNNAMED/[From "JACQUELINE" <adellenott@superpstore.every1.net>][Date Fri, 01 Oct 2004 23:15:37 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Citifraud.ai skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash/[From "Irma Schafer" <PNVYCHQJZMK@lineone.net>][Date Fri, 01 Oct 2004 21:51:29 +0400]/UNNAMED Infected: Trojan-Spy.HTML.Citifraud.ai skipped
C:\Documents and Settings\WFUR522005\Application Data\Thunderbird\Profiles\s3hlzqk3.default\Mail\mail.comcast.net\Trash Mail Berkeley mbox: infected - 10 skipped
C:\Documents and Settings\WFUR522005\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbc2e.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbdam Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbdao Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbeam Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbeao Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbm Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbu2d.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbvm.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\dbvmh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\fii.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\fiih.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\hp Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\hpt2i.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\rpm.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\rpm1m.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\rpm1mh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\rpmh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-black-enchashm.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-black-enchashmh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-black-urlm.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-black-urlmh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-malware-domainm.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-malware-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-white-domainm.cf1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Google\Google Desktop\85b9de05b485\safeweb\goog-white-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\WFUR522005\Local Settings\History\History.IE5\MSHist012007111720071118\index.dat Object is locked skipped
C:\Documents and Settings\WFUR522005\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\WFUR522005\ntuser.dat.LOG Object is locked skipped
C:\logfiles\pfirewall.log Object is locked skipped
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2007-11-17.16-39-54.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\TEMP\bis10.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\TEMP\bis11.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\TEMP\bis144D.exe Infected: Trojan.Win32.Obfuscated.en skipped