Kaspersky log file
KASPERSKY ONLINE SCANNER REPORT
Friday, September 14, 2007 11:16:23 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 14/09/2007
Kaspersky Anti-Virus database records: 418356
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 95167
Number of viruses found: 12
Number of infected objects: 29
Number of suspicious objects: 3
Duration of the scan process: 01:51:14
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\dbc2e.ht1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\dbdam Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\dbdao Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\dbeam Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\dbeao Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\dbm Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\dbu2d.ht1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\dbvm.cf1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\dbvmh.ht1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\fii.cf1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\fiih.ht1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\hp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\hpt2i.ht1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\rpm.cf1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\rpm1m.cf1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\rpm1mh.ht1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\rpmh.ht1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\safeweb\goog-black-enchashm.cf1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\safeweb\goog-black-enchashmh.ht1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\safeweb\goog-black-urlm.cf1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\safeweb\goog-black-urlmh.ht1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\safeweb\goog-malware-domainm.cf1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\safeweb\goog-malware-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\safeweb\goog-white-domainm.cf1 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Desktop\d633c2ec930b\safeweb\goog-white-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.100.Crwl Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.100.gthr Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wid Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010007.wid Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.wid Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.wid Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.ci Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.wid Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.wsb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010016.wid Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.wid Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Crwl412.gthr Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy26.gthr Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf1.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf2.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Perflib_Perfdata_f90.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\All Users\Application Data\SingleClick Systems\HomeNet Manager\Logs\hnm_svc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Wave Systems Corp\AuthManager\AuthPkg.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Wave Systems Corp\AuthManager\biolsp.txt Object is locked skipped
C:\Documents and Settings\Charles Freeman\Application Data\errsafer.exe Infected: not-a-virus

ownloader.Win32.WinFixer.o skipped
C:\Documents and Settings\Charles Freeman\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped
C:\Documents and Settings\Charles Freeman\Application Data\Microsoft\Templates\NormalEmail.dotm Object is locked skipped
C:\Documents and Settings\Charles Freeman\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-4b9c0e39-1d166fc5.zip/OP.class Infected: Trojan-Downloader.Java.OpenStream.ab skipped
C:\Documents and Settings\Charles Freeman\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-4b9c0e39-1d166fc5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Charles Freeman\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Application Data\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Application Data\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Application Data\Microsoft\Outlook\2006 archive.pst Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Application Data\Microsoft\Outlook\archive.pst/Archive Folders/Inbox/24 May 2003 06:20 from
support@microsoft.com:Re: My application/movie28.pif Infected: Email-Worm.Win32.Sobig.b skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Application Data\Microsoft\Outlook\archive.pst/Archive Folders/Inbox/22 May 2003 16:55 from
support@microsoft.com:Screensaver/screen_doc.pif Infected: Email-Worm.Win32.Sobig.b skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Application Data\Microsoft\Outlook\archive.pst Mail MS Mail: infected - 2 skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Application Data\Microsoft\Outlook\~archive1.pst.tmp Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Application Data\Microsoft\Outlook\~Outlook1.pst.tmp Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\History\History.IE5\MSHist012007091420070915\index.dat Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Temp\~DF45D5.tmp Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Temp\~DF47CF.tmp Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Temp\~DF4AA4.tmp Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Temp\~DF4C76.tmp Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Temp\~DF5488.tmp Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Temp\~DF8E26.tmp Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Charles Freeman\Local Settings\Temporary Internet Files\Content.Word\~WRS{92D46046-B8B7-480A-A6FC-448E969DE14D}.tmp Object is locked skipped
C:\Documents and Settings\Charles Freeman\My Documents\downloads\geekstogo\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Charles Freeman\My Documents\downloads\geekstogo\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Charles Freeman\My Documents\downloads\geekstogo\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Charles Freeman\My Documents\downloads\geekstogo\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Charles Freeman\My Documents\downloads\winmx\grokstersetup.exe/WISE0029.BIN Infected: not-a-virus:AdWare.Win32.Altnet.c skipped
C:\Documents and Settings\Charles Freeman\My Documents\downloads\winmx\grokstersetup.exe/WISE0033.BIN/WISE0005.BIN Infected: not-a-virus:AdWare.Win32.Altnet.c skipped
C:\Documents and Settings\Charles Freeman\My Documents\downloads\winmx\grokstersetup.exe/WISE0033.BIN Infected: not-a-virus:AdWare.Win32.Altnet.c skipped
C:\Documents and Settings\Charles Freeman\My Documents\downloads\winmx\grokstersetup.exe WiseSFX: infected - 3 skipped
C:\Documents and Settings\Charles Freeman\My Documents\EP5UH\Outlook\archive.pst/Archive Folders/Inbox/25 Jan 2002 19:05 from
EndOfItem@ebay.com:eBay End of Item - Unf.eml Infected: Trojan-Spy.HTML.Bayfraud.ib skipped
C:\Documents and Settings\Charles Freeman\My Documents\EP5UH\Outlook\archive.pst/Archive Folders/Inbox/02 Feb 2003 02:02 from chalkart:How are you.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\Charles Freeman\My Documents\EP5UH\Outlook\archive.pst/Archive Folders/Inbox/20 Feb 2003 21:55 from dwh2:Here to find out more!.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\Charles Freeman\My Documents\EP5UH\Outlook\archive.pst/Archive Folders/Inbox/05 Apr 2003 04:15 from janetvance9:How are you.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\Charles Freeman\My Documents\EP5UH\Outlook\archive.pst Mail MS Mail: infected - 1, suspicious - 3 skipped
C:\Documents and Settings\Charles Freeman\ntuser.dat Object is locked skipped
C:\Documents and Settings\Charles Freeman\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Charles Freeman\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Memeo\AutoBackup\MemeoService.exe.log-2007-9-14.log Object is locked skipped
C:\SDFix\backups\backups.zip/backups/antivirus.exe Infected: not-a-virus

ownloader.Win32.WinFixer.o skipped
C:\SDFix\backups\backups.zip/backups/drvcleaner.exe Infected: not-a-virus

ownloader.Win32.WinFixer.m skipped
C:\SDFix\backups\backups.zip ZIP: infected - 2 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP270\A0076290.exe Infected: not-a-virus:AdWare.Win32.Agent.cu skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP272\A0076464.exe Infected: Trojan-Downloader.Win32.Zlob.bzt skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP272\A0076465.exe Infected: Trojan-Downloader.Win32.Zlob.bzt skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP272\A0076466.dll Infected: Trojan-Downloader.Win32.Zlob.bzt skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP303\A0081445.dll Infected: Trojan-Downloader.Win32.Agent.bfj skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP312\A0081945.exe Infected: not-a-virus

ownloader.Win32.WinFixer.m skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP312\A0081946.exe Infected: not-a-virus

ownloader.Win32.WinFixer.o skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP312\A0081954.exe Infected: not-a-virus

ownloader.Win32.WinFixer.o skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP312\A0081955.exe Infected: not-a-virus

ownloader.Win32.WinFixer.m skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP312\A0081986.exe Infected: not-a-virus

ownloader.Win32.WinFixer.x skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP312\change.log Object is locked skipped
... rest of log to follow in next post.