Matt Gummer
2008-01-27, 18:14
I would be grateful for advice on how to rid my computer of the virtumonde trojan. Below is the report from Kapersky and HJT report on the next posting as apparently too long.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, January 21, 2008 10:48:04 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/01/2008
Kaspersky Anti-Virus database records: 525479
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 129551
Number of viruses found: 3
Number of infected objects: 11
Number of suspicious objects: 0
Duration of the scan process: 01:27:33
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0747DB7E-4570-4F3C-A6FA-7546F47B3213.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0A242983-F994-4F19-8583-C8E0BC192C46.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS17902502-2F79-4AE8-90E5-529A95104937.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1945D67B-1A03-4AFE-B9FF-794A234F833C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1A40DB48-E5C7-482F-8329-6BD500FC471D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1A8E3A69-8777-4F8B-A982-FA7FEC185D94.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1F86D7DE-ECDB-4453-8E07-D7DF3BB2C570.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS251449E5-F88D-4484-BE4F-07D4B1999D3D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS27A14C66-D1F9-4CF1-8824-4679FE0727C7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS29904C5A-36DD-4E23-9C5D-73D07580D179.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2AD4D0CC-ABD1-4C94-9F47-3738640B75CE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2B9C5DFF-87F4-452A-9B31-6BD66209BD80.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2DBBA0DA-328E-46F5-9391-0B39EE7CC495.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2EF4758F-1DAC-490B-BE41-362057D626C2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2F6B6F11-E61C-4A92-8C5E-3C6806FDB55E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3BD06F4C-F573-4445-A1E8-1BD8303E6F74.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3D54B21C-0FA8-465B-A4F3-CDF63F9BCCCD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS42F88979-F699-43F6-B69F-4E4887579A71.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS47B124F9-2561-4DED-8B17-6B4FA16CA139.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4973F183-9F6F-48C0-A814-FAAF0E25685C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4AFC1F8A-431D-40E4-94E2-53D318FDE97E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4B1FAEAC-1E37-40FD-B7B5-8B74B00F4525.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS517FF028-04ED-447B-8AC9-D511DA2C8581.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS52246559-5FB0-4D2F-B7CB-D00196E41556.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5453A78A-AE87-4D41-AB2E-94CBF671C3A7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS54CF6A15-A221-4BBA-8D6E-A7C4434BA8B7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS58920E2E-0625-42DF-A057-62B87F17681E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5C6047B4-0883-47C6-B5A9-4412FAB1B54A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS61DDBC54-789D-43A8-AB82-A60FD263FD5E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS63653D8D-6C46-4EB9-B923-C2C73B30439B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6435C42F-C3A9-4F99-85FC-E2385354AB68.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6731A233-30C5-4135-82E7-412A25550032.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS68964600-1ADB-41C0-9151-ACCA2652FF9A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS699C4E76-3A66-4FF0-9B21-0DD57EC34FA1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6D6EA93E-6114-4719-A1DF-25785E4EE40F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6EC7C976-AA65-44F5-9B0C-C898042B109E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6F1A1159-8913-48D4-A871-AB4A5B8CFD66.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6FC0C862-391C-4002-9216-0F1DB670B9E3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6FD0F4C8-A204-4309-8A2E-038531B98EB2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS74FCEA08-7685-45E6-AC64-88087A1E7ACC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7B8FF7E4-A574-4024-9ACB-8B689F812BC7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7C92CD7A-72F4-4714-BE60-DE73445641C2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7DC3CA1A-3B18-423B-B9AC-26197A5862AB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS855E3A22-5575-419B-B971-E230CDCC68A8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS85FB52CF-391C-4277-9030-F4DB7D72FC30.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS886F5496-31E6-469D-861A-6AB115B7555F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8F49050C-3781-465E-B5AD-8A391ED2D2DB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS912647C8-FE55-4831-96DA-D6A7DFD9DDD9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS93A6321F-1D05-49B6-BBD1-694BA5A1B8C7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9519C697-5214-4F62-AAEC-A8D68B239982.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9A3189BB-7B2C-4270-A3E9-3843FE04D242.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9A63D7C4-2E87-4C4B-B96A-5A20EE1EA616.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9B5486C4-F8BC-46BE-B5EA-63CD8AC0252E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9E8DA3C5-BB6E-411F-B39D-09F162B4F749.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9EFFD4F8-2F4C-4B74-A4CF-F4BE45A31204.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA1F0FF96-95B8-4CEC-8E0B-2FA78D8E9784.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA63ECA30-471A-4FD1-B7AB-FB87EE05C662.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA8C2AA85-C7C8-4010-A6A0-2828509017E6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA9F6EDE6-B743-4D0B-AECE-FCF984ACA2D8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAE889F65-A641-4413-AF31-1FE6E542A325.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBAA46144-063D-4D8C-AC0C-ECD47447B17C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBD157726-976A-47F0-B137-647682A51076.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBDB297A1-8A5D-4B0E-BF94-C93BD0713359.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBEB0E3A6-A4A4-4D70-B189-B50006A4673C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC152D49B-D005-4D75-9C9D-597E5ACBB06B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC37DFFF4-BF23-4558-A990-215A937FAA99.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCC7EC592-DE85-4126-8F84-797098788D3F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCCCF8BD5-FF75-48A3-A574-BF87BDBE905B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD28C344A-09E2-43ED-9B8B-E911E87CF2C5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD2AC1674-50A2-478E-A819-4C25C1D48D80.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD36026EA-BA66-4269-B427-B2392BD5FBF2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDC988548-98E3-4EF8-88E7-4AB7A9BB6685.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDFC0DA93-E353-445B-907A-FF5B3FB7314D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDFC167DB-B8C2-4F8D-B40E-90FA9D62B64C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE0C56217-646D-4B04-8965-E612DE626B0A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE1ACD4F3-C3CE-4C7A-BC85-4215511ED8EA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE2B58051-BA1B-4799-BF67-13C602A4920D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE3856249-BB88-41BE-8667-746EB24B1317.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE9CB294B-A9B2-4A7B-8976-3AD2E60D310B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEB0216B3-820F-4E50-BF51-AF663A0A84BF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEB88C89B-99C8-4FD1-B50A-D1C933D3D237.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEBD466C6-E684-4BE9-BAFB-0D129E631300.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEC63F845-EF95-473B-953A-703351A59940.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSED32788F-22A7-4EFE-9DD9-8DCF0D6F8527.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF07689B5-1ADC-4892-A60B-DB54F7582118.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF43BE835-647C-422B-A176-01F035DB2F2B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF874B180-B1C9-433F-8079-544DA2F7D919.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFC8941AE-F063-4248-881A-ADF2B8B38BA8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFD071A2F-532B-40EB-846B-FD5C88D0AE8C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Matt Gummer\Application Data\Webroot\Spy Sweeper\Logs\080121072134.ses Object is locked skipped
C:\Documents and Settings\Matt Gummer\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temp\~DF2945.tmp Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temp\~DF9F2F.tmp Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temp\~DFEA66.tmp Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temp\~DFEB80.tmp Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\1YHU0CPA\Adobe_Premiere_Pro_7.0[1].rar/keygen.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.dpa skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\1YHU0CPA\Adobe_Premiere_Pro_7.0[1].rar/crack.exe Infected: Trojan.Win32.Dialer.yz skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\1YHU0CPA\Adobe_Premiere_Pro_7.0[1].rar RAR: infected - 2 skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\IXZZ23ZN\Adobe_Premiere_Pro_7.0[1].rar/keygen.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.dpa skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\IXZZ23ZN\Adobe_Premiere_Pro_7.0[1].rar/crack.exe Infected: Trojan.Win32.Dialer.yz skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\IXZZ23ZN\Adobe_Premiere_Pro_7.0[1].rar RAR: infected - 2 skipped
C:\Documents and Settings\Matt Gummer\ntuser.dat Object is locked skipped
C:\Documents and Settings\Matt Gummer\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\AOL 9.0\download\keygen.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.dpa skipped
C:\Program .
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, January 21, 2008 10:48:04 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/01/2008
Kaspersky Anti-Virus database records: 525479
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 129551
Number of viruses found: 3
Number of infected objects: 11
Number of suspicious objects: 0
Duration of the scan process: 01:27:33
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0747DB7E-4570-4F3C-A6FA-7546F47B3213.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0A242983-F994-4F19-8583-C8E0BC192C46.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS17902502-2F79-4AE8-90E5-529A95104937.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1945D67B-1A03-4AFE-B9FF-794A234F833C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1A40DB48-E5C7-482F-8329-6BD500FC471D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1A8E3A69-8777-4F8B-A982-FA7FEC185D94.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1F86D7DE-ECDB-4453-8E07-D7DF3BB2C570.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS251449E5-F88D-4484-BE4F-07D4B1999D3D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS27A14C66-D1F9-4CF1-8824-4679FE0727C7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS29904C5A-36DD-4E23-9C5D-73D07580D179.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2AD4D0CC-ABD1-4C94-9F47-3738640B75CE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2B9C5DFF-87F4-452A-9B31-6BD66209BD80.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2DBBA0DA-328E-46F5-9391-0B39EE7CC495.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2EF4758F-1DAC-490B-BE41-362057D626C2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2F6B6F11-E61C-4A92-8C5E-3C6806FDB55E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3BD06F4C-F573-4445-A1E8-1BD8303E6F74.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3D54B21C-0FA8-465B-A4F3-CDF63F9BCCCD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS42F88979-F699-43F6-B69F-4E4887579A71.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS47B124F9-2561-4DED-8B17-6B4FA16CA139.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4973F183-9F6F-48C0-A814-FAAF0E25685C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4AFC1F8A-431D-40E4-94E2-53D318FDE97E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4B1FAEAC-1E37-40FD-B7B5-8B74B00F4525.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS517FF028-04ED-447B-8AC9-D511DA2C8581.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS52246559-5FB0-4D2F-B7CB-D00196E41556.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5453A78A-AE87-4D41-AB2E-94CBF671C3A7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS54CF6A15-A221-4BBA-8D6E-A7C4434BA8B7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS58920E2E-0625-42DF-A057-62B87F17681E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5C6047B4-0883-47C6-B5A9-4412FAB1B54A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS61DDBC54-789D-43A8-AB82-A60FD263FD5E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS63653D8D-6C46-4EB9-B923-C2C73B30439B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6435C42F-C3A9-4F99-85FC-E2385354AB68.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6731A233-30C5-4135-82E7-412A25550032.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS68964600-1ADB-41C0-9151-ACCA2652FF9A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS699C4E76-3A66-4FF0-9B21-0DD57EC34FA1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6D6EA93E-6114-4719-A1DF-25785E4EE40F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6EC7C976-AA65-44F5-9B0C-C898042B109E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6F1A1159-8913-48D4-A871-AB4A5B8CFD66.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6FC0C862-391C-4002-9216-0F1DB670B9E3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6FD0F4C8-A204-4309-8A2E-038531B98EB2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS74FCEA08-7685-45E6-AC64-88087A1E7ACC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7B8FF7E4-A574-4024-9ACB-8B689F812BC7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7C92CD7A-72F4-4714-BE60-DE73445641C2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7DC3CA1A-3B18-423B-B9AC-26197A5862AB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS855E3A22-5575-419B-B971-E230CDCC68A8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS85FB52CF-391C-4277-9030-F4DB7D72FC30.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS886F5496-31E6-469D-861A-6AB115B7555F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8F49050C-3781-465E-B5AD-8A391ED2D2DB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS912647C8-FE55-4831-96DA-D6A7DFD9DDD9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS93A6321F-1D05-49B6-BBD1-694BA5A1B8C7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9519C697-5214-4F62-AAEC-A8D68B239982.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9A3189BB-7B2C-4270-A3E9-3843FE04D242.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9A63D7C4-2E87-4C4B-B96A-5A20EE1EA616.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9B5486C4-F8BC-46BE-B5EA-63CD8AC0252E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9E8DA3C5-BB6E-411F-B39D-09F162B4F749.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9EFFD4F8-2F4C-4B74-A4CF-F4BE45A31204.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA1F0FF96-95B8-4CEC-8E0B-2FA78D8E9784.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA63ECA30-471A-4FD1-B7AB-FB87EE05C662.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA8C2AA85-C7C8-4010-A6A0-2828509017E6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA9F6EDE6-B743-4D0B-AECE-FCF984ACA2D8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAE889F65-A641-4413-AF31-1FE6E542A325.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBAA46144-063D-4D8C-AC0C-ECD47447B17C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBD157726-976A-47F0-B137-647682A51076.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBDB297A1-8A5D-4B0E-BF94-C93BD0713359.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBEB0E3A6-A4A4-4D70-B189-B50006A4673C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC152D49B-D005-4D75-9C9D-597E5ACBB06B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC37DFFF4-BF23-4558-A990-215A937FAA99.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCC7EC592-DE85-4126-8F84-797098788D3F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCCCF8BD5-FF75-48A3-A574-BF87BDBE905B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD28C344A-09E2-43ED-9B8B-E911E87CF2C5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD2AC1674-50A2-478E-A819-4C25C1D48D80.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD36026EA-BA66-4269-B427-B2392BD5FBF2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDC988548-98E3-4EF8-88E7-4AB7A9BB6685.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDFC0DA93-E353-445B-907A-FF5B3FB7314D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDFC167DB-B8C2-4F8D-B40E-90FA9D62B64C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE0C56217-646D-4B04-8965-E612DE626B0A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE1ACD4F3-C3CE-4C7A-BC85-4215511ED8EA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE2B58051-BA1B-4799-BF67-13C602A4920D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE3856249-BB88-41BE-8667-746EB24B1317.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE9CB294B-A9B2-4A7B-8976-3AD2E60D310B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEB0216B3-820F-4E50-BF51-AF663A0A84BF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEB88C89B-99C8-4FD1-B50A-D1C933D3D237.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEBD466C6-E684-4BE9-BAFB-0D129E631300.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEC63F845-EF95-473B-953A-703351A59940.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSED32788F-22A7-4EFE-9DD9-8DCF0D6F8527.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF07689B5-1ADC-4892-A60B-DB54F7582118.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF43BE835-647C-422B-A176-01F035DB2F2B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF874B180-B1C9-433F-8079-544DA2F7D919.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFC8941AE-F063-4248-881A-ADF2B8B38BA8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFD071A2F-532B-40EB-846B-FD5C88D0AE8C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Matt Gummer\Application Data\Webroot\Spy Sweeper\Logs\080121072134.ses Object is locked skipped
C:\Documents and Settings\Matt Gummer\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temp\~DF2945.tmp Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temp\~DF9F2F.tmp Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temp\~DFEA66.tmp Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temp\~DFEB80.tmp Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\1YHU0CPA\Adobe_Premiere_Pro_7.0[1].rar/keygen.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.dpa skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\1YHU0CPA\Adobe_Premiere_Pro_7.0[1].rar/crack.exe Infected: Trojan.Win32.Dialer.yz skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\1YHU0CPA\Adobe_Premiere_Pro_7.0[1].rar RAR: infected - 2 skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\IXZZ23ZN\Adobe_Premiere_Pro_7.0[1].rar/keygen.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.dpa skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\IXZZ23ZN\Adobe_Premiere_Pro_7.0[1].rar/crack.exe Infected: Trojan.Win32.Dialer.yz skipped
C:\Documents and Settings\Matt Gummer\Local Settings\Temporary Internet Files\Content.IE5\IXZZ23ZN\Adobe_Premiere_Pro_7.0[1].rar RAR: infected - 2 skipped
C:\Documents and Settings\Matt Gummer\ntuser.dat Object is locked skipped
C:\Documents and Settings\Matt Gummer\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\AOL 9.0\download\keygen.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.dpa skipped
C:\Program .