I need your help! [Re-Opened]

Ok nothing bad there...

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    • Extended (if available otherwise Standard)
    • Scan Options:
    • Scan Archives
      Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
    • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
 
it finds infection!

Tuesday, April 17, 2007 4:09:34 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 18/04/2007
Kaspersky Anti-Virus database records: 298681
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
Scan Statistics
Total number of scanned objects 63051
Number of viruses found 3
Number of infected objects 6 / 0
Number of suspicious objects 2
Duration of the scan process 00:41:25

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-03222007-103352.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobVideoAccessActiveXObject.zip/uninst.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobVideoAccessActiveXObject.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\orestis\Application Data\Mozilla\Firefox\Profiles\nogxesmi.default\cert8.db Object is locked skipped
C:\Documents and Settings\orestis\Application Data\Mozilla\Firefox\Profiles\nogxesmi.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\orestis\Application Data\Mozilla\Firefox\Profiles\nogxesmi.default\history.dat Object is locked skipped
C:\Documents and Settings\orestis\Application Data\Mozilla\Firefox\Profiles\nogxesmi.default\key3.db Object is locked skipped
C:\Documents and Settings\orestis\Application Data\Mozilla\Firefox\Profiles\nogxesmi.default\parent.lock Object is locked skipped
C:\Documents and Settings\orestis\Application Data\Mozilla\Firefox\Profiles\nogxesmi.default\search.sqlite Object is locked skipped
C:\Documents and Settings\orestis\Application Data\Mozilla\Firefox\Profiles\nogxesmi.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\orestis\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\orestis\Desktop\noobyhacking\ipstealer.zip/IPStealer.exe Infected: Sniffer.Win32.Assmf4 skipped
C:\Documents and Settings\orestis\Desktop\noobyhacking\ipstealer.zip ZIP: infected - 1 skipped
C:\Documents and Settings\orestis\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\orestis\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\orestis\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\orestis\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\orestis\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{AC33B5BB-3737-479F-BD23-0FFE8274DF7B} Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Application Data\Mozilla\Firefox\Profiles\nogxesmi.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Application Data\Mozilla\Firefox\Profiles\nogxesmi.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Application Data\Mozilla\Firefox\Profiles\nogxesmi.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Application Data\Mozilla\Firefox\Profiles\nogxesmi.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\History\History.IE5\MSHist012007041720070418\index.dat Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\Acr379.tmp Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\Acr383.tmp Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\Acr384.tmp Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\Acr385.tmp Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\Acr386.tmp Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\Acr387.tmp Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\Acr472.tmp Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\Acr473.tmp Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\Acr682.tmp Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\Acr683.tmp Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\Acr68C.tmp Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\Acr70E.tmp Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temp\hsperfdata_orestis\3636 Object is locked skipped
C:\Documents and Settings\orestis\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\orestis\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\orestis\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\orestis\UserData\index.dat Object is locked skipped
C:\Program Files\Mozy\Config\mozyconf.dat Object is locked skipped
C:\Program Files\Mozy\Data\mozy.log Object is locked skipped
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs\access_log Object is locked skipped
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs\error.log Object is locked skipped
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs\error_log Object is locked skipped
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs\ssl_request_log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{0DBAAE05-F984-4CC9-A895-1DEC7658195E}\RP296\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\RTacDbg.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_7fc.dat Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\{00000003-00000000-00000007-00001102-00000008-10211102}.CDF Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{0DBAAE05-F984-4CC9-A895-1DEC7658195E}\RP296\change.log Object is locked skipped
Scan process completed.
 
so what are the 3 viruses that the online scan finds?i also made a scan with spybot but it finds nothing....2 days ago,it had found the 2 threats that i mentioned above and i fixed them.the problems with drive E have stopped since the fixing...i don't know what to say...what are the infections that kaspersky finds??
 
Hello :)

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobVideoAccessActiveXObject.zip/uninst.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobVideoAccessActiveXObject.zip ZIP: suspicious - 1 skipped
That is in Spybot's quarantine - nothing to worry about

C:\Documents and Settings\orestis\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\orestis\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\orestis\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\orestis\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
That is SmitFraudFix tool - nothing to worry about.


C:\Documents and Settings\orestis\Desktop\noobyhacking\ipstealer.zip/IPStealer.exe Infected: Sniffer.Win32.Assmf4 skipped
C:\Documents and Settings\orestis\Desktop\noobyhacking\ipstealer.zip ZIP: infected - 1 skipped
Do you use this tool?
 
no,i don't use it...i had downloaded from a site and i remember that norton blocked it...anyway,quite stupid of me...is it unsafe for my pc?i just deleted the archive...
 
Well it isn't that bad if you downloaded it. Norton detects it as a hacktool...

So everything is ok now ?

:bigthumb:
 
well,the problems don't exist now...but i can't understand why it happened...and how did they vanish?(maybe the fix with spybot killed the threat) anyway really thanks for re-opening the thread...and thanks again for your precious assistance...:bigthumb:
 
hello!
my last question is if it would be better to reinstall the norton internet security pack and remove avg anti-spyware(its trial period expired) and the avg anti-virus...now i don't have a firewall while norton has and i plan just to keep norton and spybot...
 
Hello and sorry for the delay...

Yes you may install Norton Internet Security if you want. You really must use firewall and antivirus. Uninstall AVG antivirus if you install Norton. And the AVG antispy you may keep if you wan't, you can update and scan with the "trial" version.

And you're welcome :bigthumb:
 
Back
Top