JJ360
2006-10-06, 05:57
spybot and f-secure scans.
Are my passwords etc at risk??
spybot:
-- Report generated: 2006-10-05 19:06 ---
Pipas.A: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins
Advertising.com: Tracking cookie (Firefox: default) (Cookie, fixed)
Advertising.com: Tracking cookie (Firefox: default) (Cookie, fixed)
Advertising.com: Tracking cookie (Firefox: default) (Cookie, fixed)
Advertising.com: Tracking cookie (Firefox: default) (Cookie, fixed)
Avenue A, Inc.: Tracking cookie (Firefox: default) (Cookie, fixed)
DoubleClick: Tracking cookie (Firefox: default) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: default) (Cookie, fixed)
WebTrends live: Tracking cookie (Firefox: default) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-09-27 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2006-02-20 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-09-22 Includes\Cookies.sbi (*)
2006-09-22 Includes\Dialer.sbi (*)
2006-09-22 Includes\Hijackers.sbi (*)
2006-09-22 Includes\Keyloggers.sbi (*)
2006-09-22 Includes\Malware.sbi (*)
2006-09-22 Includes\PUPS.sbi (*)
2006-09-22 Includes\Revision.sbi (*)
2006-09-22 Includes\Security.sbi (*)
2006-09-22 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-09-22 Includes\Trojans.sbi (*)
....................................................................................................
F-secure
Scanning Report
05 October 2006 21:03:15 - 21:43:44
Computer name: CARDIO1
Scanning type: Perform full computer check
Target: C:\ + system + rootkits
Result: 1 malware found
W32/Virus.Z (virus)
* C:\Documents and Settings\johns\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-523da84a-609e8c52.zip\SuperMSClassLoader.class
Statistics
Scanned:
* Files: 91821
* Not scanned: 23
Result:
* Viruses: 1
* Spyware: 0
* Suspicious items: 0
* Riskware: 0
Actions:
* Disinfected: 0
* Renamed: 0
* Deleted: 0
* Quarantined: 0
* Failed: 0
Boot Sectors:
* Scanned: 1
* Infected: 0
* Suspicious items: 0
* Disinfected: 0
Files not scanned:
* Cannot open file C:\HIBERFIL.SYS
* Cannot open file C:\PAGEFILE.SYS
* Cannot open file C:\WINDOWS\SYSTEM32\CSJBS.EXE
* Cannot open file C:\WINDOWS\SYSTEM32\DMXBL.EXE
* Cannot open file C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* Cannot open file C:\SYSTEM VOLUME INFORMATION\MOUNTPOINTMANAGERREMOTEDATABASE
* Cannot open file C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCRST.DLL
* Cannot read from file C:\Documents and Settings\johns\Local Settings\Temporary Internet Files\Content.IE5\416NK963\yahoo[3]\yahoo[3] [F-Secure Libra]
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts.zip\Shared/Cache/CursorManiaBtn.html is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterdisabled.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch.zip\bar/1.bin/MWSOESTB.DLL is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA1.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA2.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA3.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA4.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA5.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA6.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA7.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA8.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsSecurityCenterAntiVirusDisableNotify.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsSecurityCenterFirewallDisableNotify.zip\sbRecovery.reg is encrypted
* Cannot open file C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\6AAD78E6F2F4C803414A70C17E498A35_07C28FC8-DD05-4FAA-BD03-3B4482EF3CAB
Options
Definitions version:
* Viruses: 2006-10-05_03
* Spyware: 2006-10-05_03
Scanning Engines:
* F-Secure AVP: 6.00.171, 2006-10-05
* F-Secure Libra: 2.04.01, 2006-10-05
* F-Secure Orion: 1.02.37, 2006-10-03
* F-Secure Draco: 1.00.35, 2006-10-03
* F-Secure BlackLight: 1.00.47
Scanning options:
* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML AVB BAT CEO CMD LSP MAP MHT MIF PHP POT WMF NWS TAR TGZ ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX
* Scan inside archives
Actions:
* Viruses: Ask after scan
* Spyware: Ask after scan
Are my passwords etc at risk??
spybot:
-- Report generated: 2006-10-05 19:06 ---
Pipas.A: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins
Advertising.com: Tracking cookie (Firefox: default) (Cookie, fixed)
Advertising.com: Tracking cookie (Firefox: default) (Cookie, fixed)
Advertising.com: Tracking cookie (Firefox: default) (Cookie, fixed)
Advertising.com: Tracking cookie (Firefox: default) (Cookie, fixed)
Avenue A, Inc.: Tracking cookie (Firefox: default) (Cookie, fixed)
DoubleClick: Tracking cookie (Firefox: default) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: default) (Cookie, fixed)
WebTrends live: Tracking cookie (Firefox: default) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-09-27 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2006-02-20 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-09-22 Includes\Cookies.sbi (*)
2006-09-22 Includes\Dialer.sbi (*)
2006-09-22 Includes\Hijackers.sbi (*)
2006-09-22 Includes\Keyloggers.sbi (*)
2006-09-22 Includes\Malware.sbi (*)
2006-09-22 Includes\PUPS.sbi (*)
2006-09-22 Includes\Revision.sbi (*)
2006-09-22 Includes\Security.sbi (*)
2006-09-22 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-09-22 Includes\Trojans.sbi (*)
....................................................................................................
F-secure
Scanning Report
05 October 2006 21:03:15 - 21:43:44
Computer name: CARDIO1
Scanning type: Perform full computer check
Target: C:\ + system + rootkits
Result: 1 malware found
W32/Virus.Z (virus)
* C:\Documents and Settings\johns\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-523da84a-609e8c52.zip\SuperMSClassLoader.class
Statistics
Scanned:
* Files: 91821
* Not scanned: 23
Result:
* Viruses: 1
* Spyware: 0
* Suspicious items: 0
* Riskware: 0
Actions:
* Disinfected: 0
* Renamed: 0
* Deleted: 0
* Quarantined: 0
* Failed: 0
Boot Sectors:
* Scanned: 1
* Infected: 0
* Suspicious items: 0
* Disinfected: 0
Files not scanned:
* Cannot open file C:\HIBERFIL.SYS
* Cannot open file C:\PAGEFILE.SYS
* Cannot open file C:\WINDOWS\SYSTEM32\CSJBS.EXE
* Cannot open file C:\WINDOWS\SYSTEM32\DMXBL.EXE
* Cannot open file C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* Cannot open file C:\SYSTEM VOLUME INFORMATION\MOUNTPOINTMANAGERREMOTEDATABASE
* Cannot open file C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCRST.DLL
* Cannot read from file C:\Documents and Settings\johns\Local Settings\Temporary Internet Files\Content.IE5\416NK963\yahoo[3]\yahoo[3] [F-Secure Libra]
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts.zip\Shared/Cache/CursorManiaBtn.html is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterdisabled.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch.zip\bar/1.bin/MWSOESTB.DLL is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA1.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA2.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA3.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA4.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA5.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA6.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA7.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PipasA8.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsSecurityCenterAntiVirusDisableNotify.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsSecurityCenterFirewallDisableNotify.zip\sbRecovery.reg is encrypted
* Cannot open file C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\6AAD78E6F2F4C803414A70C17E498A35_07C28FC8-DD05-4FAA-BD03-3B4482EF3CAB
Options
Definitions version:
* Viruses: 2006-10-05_03
* Spyware: 2006-10-05_03
Scanning Engines:
* F-Secure AVP: 6.00.171, 2006-10-05
* F-Secure Libra: 2.04.01, 2006-10-05
* F-Secure Orion: 1.02.37, 2006-10-03
* F-Secure Draco: 1.00.35, 2006-10-03
* F-Secure BlackLight: 1.00.47
Scanning options:
* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML AVB BAT CEO CMD LSP MAP MHT MIF PHP POT WMF NWS TAR TGZ ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX
* Scan inside archives
Actions:
* Viruses: Ask after scan
* Spyware: Ask after scan