Malware Infestation: Possible WM97/Luda-A Virus

emosamurai

New member
I just launched my computer and noticed that on my desktop and within "My Computer" there were these .vbs files named "Girls.vbs" and "Money.vbs" and everywhere I look, I've got legitimately named files, but they are all vbs files. Here is the Kapersky log and my HJT log. I followed all of the instructions on the BEFORE you POST thread, ran Spybot, in regular mode and safe mode, and the only thing it's found is tracking cookies. Please help if you can!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:23:08 PM, on 1/10/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\mozilla firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O4 - HKLM\..\RunServices: [Win322L4oader] C:\Windows\system32\nodd.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Tartule] C:\Users\Daniel\Favorites\Tartule.lnk
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Policies\Explorer\Run: [NTSecurity] NTSecurity.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Startup: System.vbs
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlbk_device - - C:\Windows\system32\dlbkcoms.exe
O23 - Service: Dell Printer Status Watcher (DLPWD) - Dell Inc. - C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
O23 - Service: Dell Printer Status Database (DLSDB) - Dell Inc. - C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe

--
End of file - 4547 bytes


By the way, my Kapersky log is too big to fit onto 1 post. Should I post it utilizing 2 posts?

Whatever else you need, please let me know. Again, please help!
 
I'm afraid I have unpleasant news for you. You have a Very Dangerous infection on this machine.
The infection is delivered by Troj/RaHack-A

PLEASE NOTE:- we are not sure how much of this applies to Vista, but you should be aware of the possibility

It allows outsiders COMPLETE access to every keystroke, account, and password you use while on this machine, and complete access to any other data present...
IF this computer has been used for any kind of important data, my best recommendation is to Disconnect from Internet, Re-Format the entire drive and re-install your Operating system and Applications.

We can likely clean the infected files off the computer, and if you wish we will attempt to do so, but we cannot be sure that the infection didn't do something to your system to reduce the system security. In that instance, even after removal of the infection, you could be subject to another attack or takeover as soon as you re-connect to the Internet.

The Decision Whether to ReFormat or Not should be based on:
  • The use of the computer - this is the primary factor in the decision whether to re-format and re-install, or just disinfect.
  • The variety of malware - this influences the decision on whether to re-format and re-install, or just disinfect. IN THIS CASE we have a Backdoor Trojan, the worst kind.
If the Computer has been used for any important data, you are strongly advised to do the following, immediately:
  • Disconnect the infected computer from the internet and from any networked computers until the computer can be cleaned.
  • Back up all important data on the machine. Do not back up any Applications (programs). Those should be re-installed from the original source CDs or websites.
  • If you have ever used this computer for shopping, banking, or any transactions relating to your financial well being:
    Call all of your banks, credit card companies, and financial institutions, informing them that you may be a victim of identity theft, and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change ALL your online passwords -- for ISP login, email, banks, financial accounts, PayPal, eBay, online companies, and any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new password and transaction information.
  • Take any other steps you think appropriate for an attempted identity theft.
While you are deciding whether to ReFormat and Re-Install, a useful link is here: http://www.dslreports.com/faq/10063
Please let me know what you decide.

Please post the Kaspersky log, so I can see what else is present.

Do you have UAC turned off ?
 
Holy Crap!! This computer is a work computer! I spent all night last week (since this took so long to get a reply, I couldn't wait) cleaning and disinfecting it from all of the malware. Currently there is no other malware, daily scans of AVG and Trojan Remover show nothing else present.

Regedit, CMD, Task Manager, etc. all work fine, just like normal. Do you think it's still running somewhere in the background? I am at home now and won't return until tomorrow at 8:30am (CST) to that computer, what should I do first when I get back?

PLEASE respond ASAP so I can ensure that no one else at my work is infected!!!

Help!!
 
If this is a works machine, then I recommend that you contact the IT department/person and inform them of my previous post.
This is a serious infection
# Allows others to access the computer
# Reduces system security

If you are the IT person, then I suggest you backup any files that you deem essential and then reformat.

If confidential data is stored on this machine then the risk involved is too great to try cleaning.

Here is a check list of items that you will need for a reformat.


1 - Backup Your Data
Copy all your data to a separate drive, CD, DVD, etc.
It may be a good idea to check the files that you backup with an online scanner, you don't want to be reinfected.
http://www.kaspersky.com/virusscanner

2 - Back Up Your Drivers
Particularly important if your computer was not delivered with driver CDs

Driver Genius Pro finds updates and backs up your drivers into an exe installer - very simple to re-install
Or there's the free DriverMax from http://www.innovative-sol.com

3 - Download Programs, Installers, and Updates
Make sure you have all the programs you will need to re-install such as an Antivirus, a Firewall, and, if not included on the installation disk, Microsoft's Service Pack 2 for Windows XP.
Take note of all the product keys and serial numbers. These may be on boxes, CDs, or in emails.

4 - Make Sure You Can Get Back Online
Check that you have modem drivers, set up instructions, and log-in details.

5 - Boot From The Windows CD and Install
Physically disconnect your internet cable between the computer and the modem/router
If your computer isn't set to boot from CD, look for the option to enter the BIOS setup during startup - usually Del, F1 or F2
In the BIOS, look for the option to change the order of boot devices
Select the CD drive as the first option
Save and exit

6 - Reload Drivers
Once the Windows installation is complete, re-load the drivers you save in 2 above

7 - Install Security Programs
Install your Antivirus, Firewall, and other security programs

8 - Install Any Microsoft Updates
Reconnect your computer to the internet and go to the Microsoft Updates site: http://update.microsoft.com/microsoftupdate
Download and install any required updates

9 - Install Any Programs
Finally, install any programs you need to run

If you have any questions, don't hesitate to ask.
 
Last edited:
I am the IT person, it's an office of 5 people. As far as confidential data, I am a graphic designer and I have an external hard drive with all of my art files, and the C drive just has essential system files and program files. Nothing too confidential....but where I am scared is that I'm on a network and attached to the network is our accounting computer. I can't have access granted to that computer. It has quick books and all of our customer data on it.

When I cleaned and disinfected it, it removed that "nodd.exe" and that "NTsecurity.exe" file because Trojan Remover said they were backdoor trojans, but do you think something can still be lingering?
 
If those are the only files removed then yes, it is still infected.

At least one of the infections present has the following capabilities
This worm can spread over shared folders and removable media.
http://vil.nai.com/vil/content/v_143930.htm

I strongly suggest that you get a specialist company to check all your machines, and give advice for the future.
Your general security needs to be improved to prevent this happening again.

Unfortunately this forum is designed for private home PC's
We are not really equipped to deal with office networks, as all the machines need to be checked at the same time to prevent reinfection across the network.
 
Please continue to help me. I am going to work tomorrow early in the morning and try to re-install windows on my computer. Can I still post logs from HiJack and Kapersky to ensure that my computer is free? I know you said it might have spread to other computers, but before I go freaking out my boss and the rest of the staff, I need to try and totally clean out and ensure that my computer is clear and that I have the answers.

So, could you please continue to help me?
 
The tools we use for cleaning are not recommended for use on office machines, however if you wish to continue please note :-

Neither I nor Safer Networking take any responsibility for damage to or loss of data from office/company computers if you use the tools suggested

==========================
SD Fix

DownloadSDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F5 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log

Please post the Kaspersky log now.=======================
 
Kaspersky Online Scanner .
Your Antivirus and/or Antispyware may give a warning during the scan. This is perfectly normal
Go Here http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html

Read the Requirements and limitations before you click Accept.
Allow the ActiveX download if necessary
Once the database has downloaded, click Next.
Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
Click on "My Computer" and then put the kettle on!
When the scan has completed, click Save Report As...
Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
 
Thank you, scanning now. I will post new log as soon as I finish. Could you also provide me with link to new HiJack program?

Thanks!
 
Click here to download HJTinstall.exe
  • Save HJTinstall.exe to your desktop.
  • Double click on the HJTinstall.exe icon on your desktop.
  • By default it will install to C:\\Program Files\\Trend Micro\\Hijack This.
  • Click I accept
  • Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
  • Click Save to save the log file and then the log will open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
 
Here is latest HiJack Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:46:36 AM, on 1/16/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\corel\CorelDRAW Graphics Suite 13\Programs\CorelDRW.exe
C:\Program Files\adobe\Adobe Illustrator CS3\Support Files\Contents\Windows\Illustrator.exe
C:\Program Files\mozilla firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conime.exe
C:\Program Files\Trend Micro\HijackThis\Crusty.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlbk_device - - C:\Windows\system32\dlbkcoms.exe
O23 - Service: Dell Printer Status Watcher (DLPWD) - Dell Inc. - C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
O23 - Service: Dell Printer Status Database (DLSDB) - Dell Inc. - C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe

--
End of file - 6129 bytes
 
When I tried to run SDFix, it would launch a window and it would close very fast, and nothing would happen. I tried it many times, but to no avail.

Here is kaspersky log (split into numerous posts, it's over 80,000 characters)

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, January 16, 2008 8:38:20 AM
Operating System: Microsoft Windows Vista Professional, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 16/01/2008
Kaspersky Anti-Virus database records: 512843
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\

Scan Statistics:
Total number of scanned objects: 162623
Number of viruses found: 4
Number of infected objects: 542
Number of suspicious objects: 0
Duration of the scan process: 00:52:13

Infected Object Name / Virus Name / Last Action
C:\$Recycle.Bin\S-1-5-21-2708822051-1969383407-3736298607-1000\$I5LGTAB.vbs Infected: Virus.VBS.Agent.aj skipped
C:\$Recycle.Bin\S-1-5-21-2708822051-1969383407-3736298607-1000\$IDHYIJS.vbs Infected: Virus.VBS.Agent.aj skipped
C:\$Recycle.Bin\S-1-5-21-2708822051-1969383407-3736298607-1000\$R5LGTAB.vbs Infected: Virus.VBS.Agent.aj skipped
C:\$Recycle.Bin\S-1-5-21-2708822051-1969383407-3736298607-1000\$RDHYIJS.vbs Infected: Virus.VBS.Agent.aj skipped
C:\$Recycle.Bin\S-1-5-21-2708822051-1969383407-3736298607-1000\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\$Recycle.Bin\S-1-5-21-2708822051-1969383407-3736298607-500\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\$Recycle.Bin\S-1-5-21-2826133206-2312993737-4083541239-500\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\$Recycle.Bin\S-1-5-21-918056312-2952985149-2686913973-500\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Adobe Bridge\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Adobe Bridge CS3\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Adobe Device Central CS3\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Adobe Help Viewer\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Adobe Illustrator CS2\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Adobe Illustrator CS3\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Adobe Photoshop CS3\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Adobe Photoshop CS3\LegalNotices.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Adobe Stock Photos\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Adobe Stock Photos CS3\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Adobe Utilities\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Illustrator 10\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\adobe\Photoshop 7.0\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Apple Software Update\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Apple Software Update\plugins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Bonjour\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Broadcom\ASFConfig\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Broadcom\ASFIPMon\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Broadcom\BACS\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Broadcom\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Broadcom\WMI\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\CCleaner\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\Adobe\Adobe PCD\cache\cache.db Object is locked skipped
C:\Program Files\Common Files\Adobe\Adobe PCD\pcd.db Object is locked skipped
C:\Program Files\Common Files\Adobe\caps\caps.db Object is locked skipped
C:\Program Files\Common Files\Adobe\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\Apple\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\Corel\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\GTK\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\InstallShield\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\Java\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\Macromedia\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\Macrovision Shared\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\microsoft shared\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\ODBC\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\Roxio Shared\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\Services\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\Services\verisign.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\Sonic Shared\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\SpeechEngines\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\SureThing Shared\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\System\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Common Files\Wise Installation Wizard\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\corel\CorelDRAW Graphics Suite 13\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\corel\CorelDRAW Graphics Suite X3 Setup Files\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\corel\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\CyberLink\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\CyberLink\PowerDVD DX\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\CyberLink\Shared Files\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Dell\BAE\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Dell\Dell Welcome\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Dell\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Dell AIO Printer A920\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Dell Printers\Additional Color Laser Software\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Dell Printers\Dell Color Laser 1320c\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Dell Printers\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\DivX\Artwork\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\DivX\AutoUpdate\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\DivX\DivX Content Uploader\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\DivX\DivX Web Player\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\DivX\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\ESET\Eset\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
 
C:\Program Files\ESET\ESET NOD32 Antivirus\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\ESET\Install\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\ESET\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\faxtools\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Foxit Software\Foxit Reader\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Foxit Software\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\GCC Elite Series\Drivers\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\GCC Elite Series\Fonts\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\GCC Elite Series\MenuData\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\GCC Elite Series\MenuData\Printer1.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\GCC Elite Series\MenuData\Printer2.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\GCC Elite Series\MenuData\Printer3.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\GCC Elite Series\MenuData\Printer4.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\GCC Elite Series\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\GCC Elite Series\Network\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\GCC Elite Series\Win98USB\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Google\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\InstallShield Installation Information\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\InstallShield Installation Information\{105F3CE5-FE55-408E-BF30-E78F85BA0B12}\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\InstallShield Installation Information\{281ECE39-F043-492B-8337-F2E546B5604A}\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\InstallShield Installation Information\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\InstallShield Installation Information\{92FD71D5-ED7E-40B2-8DF3-4B5E6F684367}\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\InstallShield Installation Information\{E6E8DE8D-714A-4B5B-A84C-9DE5BBCE390F}\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Intel\Intel Matrix Storage Manager\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Intel\Intel Matrix Storage Manager\Imsm_help_fig1_ENU.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Intel\Intel Matrix Storage Manager\Imsm_help_fig2_ENU.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Intel\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Internet Explorer\en-US\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Internet Explorer\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Internet Explorer\Plugins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Internet Explorer\SIGNUP\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\iPod\Acknowledgements.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\iPod\bin\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\iPod\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\iTunes\About iTunes.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\iTunes\Acknowledgements.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\iTunes\CD Configuration\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\iTunes\iTunes.Resources\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\iTunes\iTunesHelper.Resources\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\iTunes\iTunesMiniPlayer.Resources\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\iTunes\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\iTunes\Mozilla Plugins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\iTunes\Plug-Ins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\j2re1.4.2\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\jre1.6.0\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\jre1.6.0\LICENSE.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\jre1.6.0\LICENSE_de.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\jre1.6.0\LICENSE_es.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\jre1.6.0\LICENSE_fr.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\jre1.6.0\LICENSE_it.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\jre1.6.0\LICENSE_ja.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\jre1.6.0\LICENSE_ko.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\jre1.6.0\LICENSE_sv.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\jre1.6.0\LICENSE_zh_CN.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\jre1.6.0\LICENSE_zh_TW.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\jre1.6.0_03\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Java\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Jetico\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Jetico\Translation\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Last.fm\data\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Last.fm\data\no_artist.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Last.fm\data\no_cover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Last.fm\imageformats\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Last.fm\Microsoft.VC80.CRT\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Last.fm\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\LogMeIn\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\LogMeIn\x64\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\LogMeIn\x86\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\macromedia\Dreamweaver MX\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\macromedia\Extension Manager\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\macromedia\Flash 8\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\macromedia\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Microsoft CAPICOM 2.1.0.2\Lib\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Microsoft CAPICOM 2.1.0.2\License\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Microsoft CAPICOM 2.1.0.2\License\license.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Microsoft CAPICOM 2.1.0.2\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\microsoft office\CLIPART\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\microsoft office\MEDIA\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\microsoft office\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\microsoft office\Office10\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\microsoft office\OFFICE11\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\microsoft office\Stationery\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\microsoft office\Templates\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Miranda IM\Icons\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Miranda IM\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Miranda IM\Plugins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Movie Maker\en-US\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Movie Maker\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Movie Maker\Shared\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Movie Maker\Shared\Sample1.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Movie Maker\Shared\Sample2.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Movie Maker\Shared\Sample3.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Movie Maker\Shared\Sample4.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\chrome\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\components\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\defaults\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\dictionaries\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\extensions\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\greprefs\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\Money.vbs Infected: Virus.VBS.Agent.aj skipped
 
C:\Program Files\mozilla firefox\plugins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\plugins\WMP Firefox Plugin License.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\QMCache00\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\arrow.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\arrowd.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\broken-image.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\grabber.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\loading-image.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-add-column-after-active.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-add-column-after-hover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-add-column-after.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-add-column-before-active.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-add-column-before-hover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-add-column-before.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-add-row-after-active.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-add-row-after-hover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-add-row-after.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-add-row-before-active.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-add-row-before-hover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-add-row-before.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-remove-column-active.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-remove-column-hover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-remove-column.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-remove-row-active.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-remove-row-hover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\res\table-remove-row.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\searchplugins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\temp\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\mozilla firefox\uninstall\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\chrome\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\chrome\icons\default\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\chrome\icons\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\chrome\Readme.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\components\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\components\Readme.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\defaults\autoconfig\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\defaults\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\defaults\messenger\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\defaults\pref\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\defaults\profile\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\defaults\Readme.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\dictionaries\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\dictionaries\Readme.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\extensions\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\extensions\Readme.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\greprefs\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\greprefs\Readme.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\isp\en-US\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\isp\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\isp\Readme.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\plugins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\plugins\Microsoft.VC80.CRT\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\plugins\Readme.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\dtd\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\entityTables\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\grabber.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\Readme.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-add-column-after-active.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-add-column-after-hover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-add-column-after.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-add-column-before-active.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-add-column-before-hover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-add-column-before.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-add-row-after-active.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-add-row-after-hover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-add-row-after.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-add-row-before-active.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-add-row-before-hover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-add-row-before.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-remove-column-active.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-remove-column-hover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-remove-column.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-remove-row-active.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-remove-row-hover.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Mozilla Thunderbird\res\table-remove-row.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MSBuild\Microsoft\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MSBuild\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MSN\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MSXML 4.0\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\Chinese_BIG5.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\CZECH.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\Deutsch.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\English.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\Español.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\Français.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\Italiano.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\Macedonian.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\Magyar.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\Nederlands.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\Polski.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\Russian.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Lang\Svenska.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\MWSnap\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Qualcomm\Eudora\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Qualcomm\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\QuickTime\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\QuickTime\PictureViewer.Resources\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\QuickTime\Plugins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\QuickTime\PropertyPanels\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\QuickTime\QTComponents\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\QuickTime\QTSystem\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\QuickTime\QTSystem\QTJava.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\QuickTime\QuickTimePlayer.Resources\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Reference Assemblies\Microsoft\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Reference Assemblies\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Roxio\Express Labeler 2\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Roxio\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Roxio\Update Manager\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Sigmatel\C-Major Audio\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Sigmatel\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Dummies\dummy.dap.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Dummies\dummy.default.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Dummies\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Help\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Includes\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Languages\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Plugins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Skins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Skins\Italia.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Skins\Peace.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Updates\clsid.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Updates\desc.english.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Updates\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Updates\help.english.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Spybot - Search & Destroy\Updates\startup.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\SUPERAntiSpyware\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\SUPERAntiSpyware\Plugins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Uninstall Information\Money.vbs Infected: Virus.VBS.Agent.aj skipped
 
C:\Program Files\uTorrent\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\winace\Backup\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\winace\html\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\winace\license.doc.vbs Object is locked skipped
C:\Program Files\winace\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\winace\projects\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\winace\sfxfiles\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\winace\technote.doc.vbs Object is locked skipped
C:\Program Files\Windows Calendar\en-US\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Calendar\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Defender\en-US\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Defender\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Journal\en-US\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Journal\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Journal\Templates\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Live Safety Center\History\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Live Safety Center\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Mail\en-US\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Mail\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Media Player\en-US\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Media Player\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Media Player\Network Sharing\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Media Player\Network Sharing\wmpnss_bw120.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Media Player\Network Sharing\wmpnss_bw32.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Media Player\Network Sharing\wmpnss_bw48.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Media Player\Network Sharing\wmpnss_color120.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Media Player\Network Sharing\wmpnss_color32.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Media Player\Network Sharing\wmpnss_color48.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Media Player\Skins\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Media Player\Visualizations\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows NT\Accessories\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows NT\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows NT\TableTextService\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Photo Gallery\en-US\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Photo Gallery\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Sidebar\en-US\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Sidebar\Gadgets\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Sidebar\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Windows Sidebar\Shared Gadgets\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Zone Labs\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Program Files\Zone Labs\ZoneAlarm\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Adobe\Adobe PDF\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Adobe\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Adobe\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Adobe\Updater5\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Agnitum\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Agnitum\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Agnitum\Security Suite\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\ALM\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\ALM\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Apple\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Apple\Installer Cache\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Apple\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Apple Computer\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Apple Computer\Installer Cache\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Apple Computer\iTunes\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Apple Computer\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Apple Computer\QuickTime\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\CheckPoint\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\CheckPoint\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\CheckPoint\ZoneAlarm\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Corel\CorelDRAW Graphics Suite 13\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Corel\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Corel\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Dell\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Dell\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Dell\PowerDVD DX\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\ESET\ESET NOD32 Antivirus\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\ESET\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\ESET\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\FLEXnet\adobe_00080000_tsf.data Object is locked skipped
C:\ProgramData\FLEXnet\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\FLEXnet\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Google\Custom Buttons\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Google\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Google\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\ProgramData\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\ProgramData\InstallShield\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\InstallShield\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\InstallShield\UpdateService\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Kaspersky Lab\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Kaspersky Lab\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Last.fm\Client\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Last.fm\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Last.fm\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Assistance\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Crypto\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\DRM\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\HTML Help\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\IdentityCRL\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Machine Debug Manager\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Media Index\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Media Player\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\MF\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\MSDAIPP\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Office\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Provisioning\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\RAC\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.45.Crwl Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.45.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.ci Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wsb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010007.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010008.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000B.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000C.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000E.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010013.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010014.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010015.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010019.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001A.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy146.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped
 
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf363C.tmp Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf363D.tmp Object is locked skipped
C:\ProgramData\Microsoft\Search\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\User Account Pictures\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\User Account Pictures\guest.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\User Account Pictures\user.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Windows\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Windows\Templates\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Windows\Templates\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Windows Defender\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-11022006-050253.log Object is locked skipped
C:\ProgramData\Microsoft\Windows NT\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft\WPD\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft Help\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Microsoft Help\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Readme.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Sonic\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Sonic\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Backups\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Excludes\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Logs\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Recovery\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Recovery\Hupigon.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Recovery\MicrosoftWindowsExplorer.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Recovery\MicrosoftWindowsExplorer1.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSystem.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Snapshots\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\Spybot - Search & Destroy\Snapshots2\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\SUPERAntiSpyware.com\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\SUPERAntiSpyware.com\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\TuneUp Software\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\TuneUp Software\Money.vbs Infected: Virus.VBS.Agent.aj skipped
C:\ProgramData\TuneUp Software\TuneUp Utilities\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\SDFix\apps\dummy.exe Infected: Trojan.Win32.Obfuscated.na skipped
C:\SDFix\apps\MD5File.exe Infected: Trojan.Win32.Obfuscated.na skipped
C:\SDFix\dummy.exe Infected: Trojan.Win32.Obfuscated.na skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\OP_CACHE.ATR Object is locked skipped
C:\System Volume Information\OP_CACHE.IDX Object is locked skipped
C:\Users\Daniel\AppData\Local\Adobe\Updater5\aumLib.log Object is locked skipped
C:\Users\Daniel\AppData\Local\Last.fm\Client\iTunesPlugin.log Object is locked skipped
C:\Users\Daniel\AppData\Local\Last.fm\Client\LastFmHelper.log Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008011620080117\index.dat Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\UsrClass.dat{e3d1d45f-8e38-11dc-9efb-001d090632e6}.TM.blf Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\UsrClass.dat{e3d1d45f-8e38-11dc-9efb-001d090632e6}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Daniel\AppData\Local\Microsoft\Windows\UsrClass.dat{e3d1d45f-8e38-11dc-9efb-001d090632e6}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Daniel\AppData\Local\Mozilla\Firefox\Profiles\nxjljjd5.default\Cache\DD0DBD66d01/data.rar/SDFix/apps/dummy.exe Infected: Trojan.Win32.Obfuscated.na skipped
C:\Users\Daniel\AppData\Local\Mozilla\Firefox\Profiles\nxjljjd5.default\Cache\DD0DBD66d01/data.rar/SDFix/dummy.exe Infected: Trojan.Win32.Obfuscated.na skipped
C:\Users\Daniel\AppData\Local\Mozilla\Firefox\Profiles\nxjljjd5.default\Cache\DD0DBD66d01/data.rar/SDFix/apps/MD5File.exe Infected: Trojan.Win32.Obfuscated.na skipped
C:\Users\Daniel\AppData\Local\Mozilla\Firefox\Profiles\nxjljjd5.default\Cache\DD0DBD66d01/data.rar Infected: Trojan.Win32.Obfuscated.na skipped
C:\Users\Daniel\AppData\Local\Mozilla\Firefox\Profiles\nxjljjd5.default\Cache\DD0DBD66d01 RarSFX: infected - 4 skipped
C:\Users\Daniel\AppData\Local\Mozilla\Firefox\Profiles\nxjljjd5.default\Cache\_CACHE_001_ Object is locked skipped
C:\Users\Daniel\AppData\Local\Mozilla\Firefox\Profiles\nxjljjd5.default\Cache\_CACHE_002_ Object is locked skipped
C:\Users\Daniel\AppData\Local\Mozilla\Firefox\Profiles\nxjljjd5.default\Cache\_CACHE_003_ Object is locked skipped
C:\Users\Daniel\AppData\Local\Mozilla\Firefox\Profiles\nxjljjd5.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\alm.log Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\amt.log Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\FXSAPIDebugLogFile.txt Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\lilo23132 Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\lilo33132 Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\lilo43132 Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\lilo53132 Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\lilo63132 Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT11AB2.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT11AB3.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT11AC3.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT11AC4.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT11AC5.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT11AC6.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT12543.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT12544.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT12545.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT15F4A.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT15F4B.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT15F4C.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT1F82.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT1F83.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\WT1F84.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~DF51.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~DF5617.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~DF5630.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~DFA601.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~DFA61A.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~DFBABD.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~DFBAD6.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~VMBFF4.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~VMBFF5.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~VMBFF6.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~VMBFF7.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~VMBFF8.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~VMBFF9.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~VMBFFA.tmp Object is locked skipped
C:\Users\Daniel\AppData\Local\Temp\~VMC00A.tmp Object is locked skipped
C:\Users\Daniel\AppData\Roaming\Adobe\Logs\AISuitePea.log Object is locked skipped
C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\Girls.vbs Infected: Virus.VBS.Agent.aj skipped
C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\nxjljjd5.default\cert8.db Object is locked skipped
C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\nxjljjd5.default\formhistory.dat Object is locked skipped
C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\nxjljjd5.default\history.dat Object is locked skipped
C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\nxjljjd5.default\key3.db Object is locked skipped
C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\nxjljjd5.default\parent.lock Object is locked skipped
C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\nxjljjd5.default\search.sqlite Object is locked skipped
C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\nxjljjd5.default\urlclassifier2.sqlite Object is locked skipped
 
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. .. .. ... /[From "Donatas Pater" <Paterwbrmt@fechtclub.ch>][Date Sat, 15 Dec 2007 23:36:20 ... /card.scr Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. .. .. ... /[From "Donatas Pater" <Paterwbrmt@fechtclub.ch>][Date Sat, 15 Dec 2007 23:36:20 +0100]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. .. ... /[From "ioanna Plevyak" <ioanna461@readiminds.com>][Date Sat, 15 Dec 2007 13:05:07 +0100]/text Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. ... / . .. ... / ... /[From Cindy Gaither <cjgaither@mac.com>][Date Fri, 14 Dec 2007 14:45:25 -0600]/text Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. ... / . .. ... /[From "info" <Sales@jewelboxhousesdesign.com>][Date Thu, 13 Dec 2007 22:42:26 +0000]/text Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. ... / . ... /[From "Jamie Willis" <jamie.willis@121cc.com>][Date Thu, 13 Dec 2007 16:34:35 -0600]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. ... / ... /[From "YouSendIt" <services@news.yousendit.com>][Date Wed, 12 Dec 2007 12:08:01 -0800]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. ... /[From "Emily Ulbri ... /[From rick.henson@verizon.com][Date Mon, 10 Dec 2007 15:09:07 -0600]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. ... /[From "Emily Ulbrich CTMS" <emily.ulbrich@gcisd.net>][Date Mon, 10 Dec 2007 15:03:20 -060 ... /html Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. ... /[From "Emily Ulbrich CTMS" <emily.ulbrich@gcisd.net>][Date Mon, 10 Dec 2007 15:03:20 -060 ... /text Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. ... /[From "Emily Ulbrich CTMS" <emily.ulbrich@gcisd.net>][Date Mon, 10 Dec 2007 15:03:20 -0600]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. ... /[From "Emily Ulbrich CTMS" <emily.ulbrich@gcisd.net>][Date Mon, 10 Dec 2007 14:57:55 -060 ... /html Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. ... /[From "Emily Ulbrich CTMS" <emily.ulbrich@gcisd.net>][Date Mon, 10 Dec 2007 14:57:55 -060 ... /text Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12. ... /[From "Emily Ulbrich CTMS" <emily.ulbrich@gcisd.net>][Date Mon, 10 Dec 2007 14:57:55 -0600]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12.88. . ... /[From "taylor martinez" <nitramrolyat@gmail.com>][Date Mon, 10 Dec 2007 14:50:29 - ... /UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12.88. . ... /[From "taylor martinez" <nitramrolyat@gmail.com>][Date Mon, 10 Dec 2007 14:50:29 -0600]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12.88. ... /[From "Emily Ulbrich CTMS" <emily.ulbrich@gcisd.net>][Date Mon, 10 Dec 2007 14:49:45 - ... /html Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12.88. ... /[From "Emily Ulbrich CTMS" <emily.ulbrich@gcisd.net>][Date Mon, 10 Dec 2007 14:49:45 -0600]/text Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD ... /[From from 76.186.41.193 by webmail-mf11.sysops.aol.com (64.12.88.224) with HTTP (WebMailUI); Mon, 10 Dec 2007 15:13:05 -0500][Date Mon, 10 Dec 2007 15:13:05 -0500]/text Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD.org>][Date ¬§ÈÛ=‡ ð‡ È=P‚Ø5‡ ... /[From "Emily Ulbrich CTMS" <emily.ulbrich@gcisd.net>][Date Mon, 10 Dec 2007 13:43:31 - ... /html Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD.org>][Date ¬§ÈÛ=‡ ð‡ È=P‚Ø5‡ ... /[From "Emily Ulbrich CTMS" <emily.ulbrich@gcisd.net>][Date Mon, 10 Dec 2007 13:43:31 -0600]/text Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD.org>][Date ¬§ÈÛ=‡ ð‡ È=P‚Ø5‡ п‡ Jdi€8+‡ ... /[From Kellertrophy@aol.com][Date Mon, 10 Dec 2007 13:08:27 EST]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@c ... /[From "Zach Meeks" <zmeeks@SJD.org>][Date ¬§ÈÛ=‡ ð‡ È=P‚Ø5‡ п‡ Jdi€8+‡ x¬’‡ 475712E3.6040909@valleyviewproductions.com>]/text Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 10:07:41 -0700]/html/[From "Andrea Ochsner" <apochsner@kellerisd.net>][Date Wed, 05 Dec 2007 14:33:45 -0600]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 10:07:41 -0700]/html Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED/[From dave@crosstimbersmarketing.com][Date Wed, 05 Dec 2007 09:36:33 -0700]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED/[From "Stan Maddox" <stan@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:46:50 -0600]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox/[From <daniel@valleyviewproductions.com>][Date Wed, 5 Dec 2007 09:18:10 -0600]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Inbox Mail Berkeley mbox: infected - 28 skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Junk/[From "Strategies@Work, LLC" <info@StrategiesWork.com>][Date Thu, 06 Dec 2007 00:13:44 +0000]/UNNAMED/[From "Lonnie D. Price" <lonnie.price_eo@baxter.com>][Date Sun, 16 Dec 2007 21:54:01 -0700]/card.zip/card.scr Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Junk/[From "Strategies@Work, LLC" <info@StrategiesWork.com>][Date Thu, 06 Dec 2007 00:13:44 +0000]/UNNAMED/[From "Lonnie D. Price" <lonnie.price_eo@baxter.com>][Date Sun, 16 Dec 2007 21:54:01 -0700]/card.zip Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Junk/[From "Strategies@Work, LLC" <info@StrategiesWork.com>][Date Thu, 06 Dec 2007 00:13:44 +0000]/UNNAMED Infected: Trojan-Downloader.Win32.Agent.gbu skipped
C:\Users\Daniel\AppData\Roaming\Thunderbird\Profiles\5bdq9v3a.default\Mail\Local Folders\Junk Mail Berkeley mbox: infected - 3 skipped
C:\Users\Daniel\Desktop\SDFix.exe/data.rar/SDFix/apps/dummy.exe Infected: Trojan.Win32.Obfuscated.na skipped
C:\Users\Daniel\Desktop\SDFix.exe/data.rar/SDFix/dummy.exe Infected: Trojan.Win32.Obfuscated.na skipped
C:\Users\Daniel\Desktop\SDFix.exe/data.rar/SDFix/apps/MD5File.exe Infected: Trojan.Win32.Obfuscated.na skipped
C:\Users\Daniel\Desktop\SDFix.exe/data.rar Infected: Trojan.Win32.Obfuscated.na skipped
C:\Users\Daniel\Desktop\SDFix.exe RarSFX: infected - 4 skipped
C:\Users\Daniel\Desktop\Security Programs\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
 
Alright, I've got a lot more, but I wanted to wait until I heard back from you if you want me to continue posting the log. It's WAY TOO LONG! As you can already tell I'm sure.

Please respond with further instructions for me.
 
Back
Top