mestes
2008-01-16, 06:04
I seem to be infected with Smitfraud-C.CoreService.
I started out using adaware 2007 free to remove this which it could not do. then tried Spybot S&D twice once in safemode but is not detected in safemode, but it is still there when I go back to normal.
Here is my KASPERSKY online scanner log and Hijackthis log to follow.
-------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, January 15, 2008 8:39:24 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/01/2008
Kaspersky Anti-Virus database records: 512527
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
F:\
K:\
Scan Statistics
Total number of scanned objects 231678
Number of viruses found 21
Number of infected objects 56
Number of suspicious objects 0
Duration of the scan process 01:48:09
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\hsperfdata_LOCAL SERVICE\316 Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\51\4278fa73-4fea0fe6/vlocal.class Infected: Trojan-Downloader.Java.Agent.f skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\51\4278fa73-4fea0fe6 ZIP: infected - 1 skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-13333dea/BnnnnBaa.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-13333dea/VaannnaaBaa.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-13333dea/Bnnnnn.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-13333dea ZIP: infected - 3 skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-69ee0dc2-7c7f1563.zip/vlocal.class Infected: Trojan-Downloader.Java.Agent.f skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-69ee0dc2-7c7f1563.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Matthew\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\Desktop\SmitfraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Matthew\Desktop\SmitfraudFix\SmitfraudFix\SmiUpdate.exe Object is locked skipped
C:\Documents and Settings\Matthew\Desktop\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Matthew\Desktop\SmitfraudFix.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Matthew\Desktop\web - graphics\www.johnstondandy.com\apdhtml-dm\!deluxe-tuner\deluxetuner.exe Infected: Trojan-Spy.Win32.Banker.flq skipped
C:\Documents and Settings\Matthew\Desktop\web - graphics\www.johnstondandy.com\apdhtml-dm.zip/!deluxe-tuner/deluxetuner.exe Infected: Trojan-Spy.Win32.Banker.flq skipped
C:\Documents and Settings\Matthew\Desktop\web - graphics\www.johnstondandy.com\apdhtml-dm.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Matthew\Desktop\web - graphics\www.johnstondandy.com\menu editor\!deluxe-tuner\deluxetuner.exe Infected: Trojan-Spy.Win32.Banker.flq skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Outlook\~Outlook.pst.tmp Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Matthew\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2008-01-15.18-12-02.log Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\config\configuration\org.eclipse.osgi\.manager\.tmp56023.instance Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\config\configuration\org.eclipse.update\.lock Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\.vc-core-lock Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\ibdata1 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\ib_logfile0 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\ib_logfile1 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhassetcacheitem.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhassetversioncacheitem.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhlink.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhmessage.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhpqentry.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhpublishlog.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhpublishserver.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhpublishstateitem.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhresult.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhreview.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhreviewtouser.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhrole.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhschemaversion.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhsequence.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhserverglobals.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhsettings.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhsettingssection.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhthumbnail.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhuser.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhuserrole.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhxmpmetadata.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhxmpproperty.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\temp\ib2 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\temp\ib3 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\temp\ib4 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\temp\ib5 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\temp\ib6 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\logs\VersionCue.log Object is locked skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\Program Files\mIRC\mirc.exe.BAK Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\services.exe.vir Infected: not-a-virus:Server-FTP.Win32.Serv-U.25.i skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050737.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050738.scr Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050739.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050746.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050747.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050748.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.at skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050750.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050751.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050752.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050753.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.af skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050754.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050755.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050756.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050757.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050758.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050759.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050760.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.an skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050761.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.aq skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050762.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bh skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050764.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050765.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050767.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050769.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050770.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050771.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ad skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050772.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050773.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050774.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050775.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050776.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050777.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050779.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050781.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0051166.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0051182.exe/mwsSetup.CommonCodebase.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0051182.exe CAB: infected - 1 skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP313\A0070862.dll Infected: not-a-virus:AdWare.Win32.Shopper.q skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP339\A0073532.exe Object is locked skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP340\A0073550.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.25.i skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP340\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\S2E745656.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
C:\WINDOWS\system32\drivers\crusoee.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd7501.sys Object is locked skipped
C:\WINDOWS\system32\drivers\vaxscsi.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
I started out using adaware 2007 free to remove this which it could not do. then tried Spybot S&D twice once in safemode but is not detected in safemode, but it is still there when I go back to normal.
Here is my KASPERSKY online scanner log and Hijackthis log to follow.
-------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, January 15, 2008 8:39:24 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/01/2008
Kaspersky Anti-Virus database records: 512527
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
F:\
K:\
Scan Statistics
Total number of scanned objects 231678
Number of viruses found 21
Number of infected objects 56
Number of suspicious objects 0
Duration of the scan process 01:48:09
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\hsperfdata_LOCAL SERVICE\316 Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\51\4278fa73-4fea0fe6/vlocal.class Infected: Trojan-Downloader.Java.Agent.f skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\51\4278fa73-4fea0fe6 ZIP: infected - 1 skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-13333dea/BnnnnBaa.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-13333dea/VaannnaaBaa.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-13333dea/Bnnnnn.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-13333dea ZIP: infected - 3 skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-69ee0dc2-7c7f1563.zip/vlocal.class Infected: Trojan-Downloader.Java.Agent.f skipped
C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-69ee0dc2-7c7f1563.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Matthew\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\Desktop\SmitfraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Matthew\Desktop\SmitfraudFix\SmitfraudFix\SmiUpdate.exe Object is locked skipped
C:\Documents and Settings\Matthew\Desktop\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Matthew\Desktop\SmitfraudFix.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Matthew\Desktop\web - graphics\www.johnstondandy.com\apdhtml-dm\!deluxe-tuner\deluxetuner.exe Infected: Trojan-Spy.Win32.Banker.flq skipped
C:\Documents and Settings\Matthew\Desktop\web - graphics\www.johnstondandy.com\apdhtml-dm.zip/!deluxe-tuner/deluxetuner.exe Infected: Trojan-Spy.Win32.Banker.flq skipped
C:\Documents and Settings\Matthew\Desktop\web - graphics\www.johnstondandy.com\apdhtml-dm.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Matthew\Desktop\web - graphics\www.johnstondandy.com\menu editor\!deluxe-tuner\deluxetuner.exe Infected: Trojan-Spy.Win32.Banker.flq skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Outlook\~Outlook.pst.tmp Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Matthew\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matthew\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Matthew\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2008-01-15.18-12-02.log Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\config\configuration\org.eclipse.osgi\.manager\.tmp56023.instance Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\config\configuration\org.eclipse.update\.lock Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\.vc-core-lock Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\ibdata1 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\ib_logfile0 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\ib_logfile1 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhassetcacheitem.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhassetversioncacheitem.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhlink.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhmessage.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhpqentry.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhpublishlog.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhpublishserver.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhpublishstateitem.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhresult.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhreview.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhreviewtouser.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhrole.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhschemaversion.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhsequence.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhserverglobals.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhsettings.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhsettingssection.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhthumbnail.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhuser.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhuserrole.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhxmpmetadata.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\database\data\versioncue\bhxmpproperty.ibd Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\temp\ib2 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\temp\ib3 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\temp\ib4 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\temp\ib5 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\data\temp\ib6 Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\logs\VersionCue.log Object is locked skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\Program Files\mIRC\mirc.exe.BAK Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\services.exe.vir Infected: not-a-virus:Server-FTP.Win32.Serv-U.25.i skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050737.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050738.scr Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050739.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050746.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050747.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050748.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.at skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050750.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050751.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050752.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050753.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.af skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050754.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050755.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050756.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050757.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050758.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050759.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050760.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.an skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050761.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.aq skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050762.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bh skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050764.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050765.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050767.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050769.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050770.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050771.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ad skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050772.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050773.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050774.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050775.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050776.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050777.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050779.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0050781.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0051166.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0051182.exe/mwsSetup.CommonCodebase.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP240\A0051182.exe CAB: infected - 1 skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP313\A0070862.dll Infected: not-a-virus:AdWare.Win32.Shopper.q skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP339\A0073532.exe Object is locked skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP340\A0073550.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.25.i skipped
C:\System Volume Information\_restore{24B27BB0-A4B9-4121-857A-F4DB40845266}\RP340\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\S2E745656.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
C:\WINDOWS\system32\drivers\crusoee.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd7501.sys Object is locked skipped
C:\WINDOWS\system32\drivers\vaxscsi.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.