Kasper log...
KASPERSKY ONLINE SCANNER REPORT
Sunday, November 25, 2007 04:09:30
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/11/2007
Kaspersky Anti-Virus database records: 465281
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
Scan Statistics
Total number of scanned objects 46184
Number of viruses found 22
Number of infected objects 85
Number of suspicious objects 4
Duration of the scan process 00:54:09
Infected Object Name Virus Name Last Action
C:\134B.tmp/stream/data0002 Infected: not-a-virus

ownloader.Win32.Agent.q skipped
C:\134B.tmp/stream/data0003 Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\134B.tmp/stream Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\134B.tmp NSIS: infected - 3 skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pohtcoju.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\QMGR0.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\QMGR1.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant.zip/v1.8.2/wbuninst.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip/Yazzle1552OinUninstaller.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04CC0000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05C80000.VBN/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05C80000.VBN/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05C80000.VBN/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05C80000.VBN ZIP: infected - 3 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05C80000.VBN CryptZ: infected - 3 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06540000.VBN Infected: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00000.VBN/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00000.VBN/Counter.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00000.VBN/Beyond.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00000.VBN/Worker.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00000.VBN/web.exe Infected: Trojan-Downloader.Win32.Delf.ags skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00000.VBN ZIP: infected - 5 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00000.VBN CryptZ: infected - 5 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F040000.VBN/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F040000.VBN/Counter.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F040000.VBN/Beyond.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F040000.VBN/Worker.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F040000.VBN/web.exe Infected: Trojan-Downloader.Win32.Delf.ags skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F040000.VBN ZIP: infected - 5 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F040000.VBN CryptZ: infected - 5 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0000.VBN/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0000.VBN/Counter.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0000.VBN/Beyond.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0000.VBN/Worker.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0000.VBN/web.exe Infected: Trojan-Downloader.Win32.Delf.ags skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0000.VBN ZIP: infected - 5 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0000.VBN CryptZ: infected - 5 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0002.VBN/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0002.VBN/Counter.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0002.VBN/Beyond.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0002.VBN/Worker.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0002.VBN/web.exe Infected: Trojan-Downloader.Win32.Delf.ags skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0002.VBN ZIP: infected - 5 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\122C0002.VBN CryptZ: infected - 5 skipped
C:\Documents and Settings\Default User\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Default User\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\dummy\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\dummy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\dummy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\dummy\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\dummy\Local Settings\History\History.IE5\MSHist012007112520071126\index.dat Object is locked skipped
C:\Documents and Settings\dummy\Local Settings\Temp\baqfjyyr.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\dummy\Local Settings\Temp\cbmuausj.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\dummy\Local Settings\Temp\cctqltmy.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\dummy\Local Settings\Temp\cfxdweos.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\cjfngber.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\djcomerf.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\dyvxrutn.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\dummy\Local Settings\Temp\eqhnbjhp.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\dummy\Local Settings\Temp\fowfrguy.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\hfqrhmcl.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\kjywxlum.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\mncuctss.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\mwcxsfow.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\nfefmueq.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\npqjspen.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\ntscijte.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\dummy\Local Settings\Temp\obrbpchi.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\ruaowwwm.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\dummy\Local Settings\Temp\swyjbryl.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\vboxtkrt.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\vlgyxuxk.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\dummy\Local Settings\Temp\vochloqy.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\WinAntiSpyware2007Setup.exe/file03 Infected: Trojan-Downloader.Win32.Agent.dhj skipped
C:\Documents and Settings\dummy\Local Settings\Temp\WinAntiSpyware2007Setup.exe/file05/file2 Infected: not-a-virus

ownloader.Win32.WinFixer.t skipped
C:\Documents and Settings\dummy\Local Settings\Temp\WinAntiSpyware2007Setup.exe/file05 Infected: not-a-virus

ownloader.Win32.WinFixer.t skipped
C:\Documents and Settings\dummy\Local Settings\Temp\WinAntiSpyware2007Setup.exe/file26 Infected: not-a-virus

ownloader.Win32.WinFixer.t skipped
C:\Documents and Settings\dummy\Local Settings\Temp\WinAntiSpyware2007Setup.exe/file39 Infected: not-a-virus

ownloader.Win32.WinFixer.x skipped
C:\Documents and Settings\dummy\Local Settings\Temp\WinAntiSpyware2007Setup.exe Inno: infected - 5 skipped
C:\Documents and Settings\dummy\Local Settings\Temp\wvjpofki.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\xnekxlqj.exe Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\dummy\Local Settings\Temp\~DF2069.tmp Object is locked skipped
C:\Documents and Settings\dummy\Local Settings\Temp\~DF2072.tmp Object is locked skipped
C:\Documents and Settings\dummy\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dummy\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\dummy\ntuser.dat.LOG Object is locked skipped
C:\Downloads\OregonTrail-dm[1].exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0541NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0964NAV~.TMP Object is locked skipped
C:\System Volume Information\catalog.wci\00000002.ps1 Object is locked skipped
C:\System Volume Information\catalog.wci\00000002.ps2 Object is locked skipped
C:\System Volume Information\catalog.wci\00010005.ci Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped
C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped
C:\temp\EzRhooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
C:\temp\EzRLib.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
C:\unzipped\hijackthis\backups\backup-20060320-124127-724.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\jkkll.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ww skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Downloaded Program Files\popcaploader.dll Infected: not-a-virus

ownloader.Win32.PopCap.b skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SYSTEM.ALT Object is locked skipped
C:\WINNT\SYSTEM32\EzRhooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
C:\WINNT\SYSTEM32\EzRLib.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
C:\WINNT\SYSTEM32\kygbbdio.dll Infected: Trojan.Win32.BHO.rd skipped
C:\WINNT\SYSTEM32\laforlng.dll Infected: Trojan.Win32.BHO.rd skipped
C:\WINNT\SYSTEM32\lurksdti.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\WINNT\SYSTEM32\Perflib_Perfdata_404.dat Object is locked skipped
C:\WINNT\SYSTEM32\Perflib_Perfdata_750.dat Object is locked skipped
C:\WINNT\SYSTEM32\Perflib_Perfdata_784.dat Object is locked skipped
C:\WINNT\SYSTEM32\teugvpqc.dll Infected: Trojan.Win32.BHO.rg skipped
C:\WINNT\SYSTEM32\tpdvdrkd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\WINNT\SYSTEM32\WBEM\Repository\CIM.REP Object is locked skipped
C:\WINNT\SYSTEM32\wcxgtenp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\WINNT\SYSTEM32\xirbbpow.dll Infected: Trojan.Win32.BHO.rd skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
Scan process completed.