StephanieD
New member
My computer has been infected with Smitfraud-C. I've read the "BEFORE you POST" thread and performed the following actions:
1) Installed Spybot - Search & Destroy Version 1.5 and downloaded the latest definitions
2) Ran an online scan with Kaspersky Online Scanner
3) Ran Spybot-S&D in safe mode and removed Smitfraud-C
4) Ran a system scan with Trend Micro HijackThis 2.0.2
It appears that Spybot was able to remove Smitfraud-C. But when I reran the Kaspersky online scanner, it found 10 viruses on my computer. When I reran Spybot, it said no immediate threats were found. Do I need to take any further action?
Thanks for your help,
Stephanie
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, November 24, 2007 10:04:00 PM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/11/2007
Kaspersky Anti-Virus database records: 465157
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 93089
Number of viruses found: 10
Number of infected objects: 43
Number of suspicious objects: 3
Duration of the scan process: 01:17:45
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\034C0000\474DD473.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ath skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\034C0001\474DD56E.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ath skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\034C0003\474DD59D.VBN Infected: Trojan-Downloader.Win32.Small.gll skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\059C0001\47DDDA69.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ath skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\059C0002\47DDDA7B.VBN Infected: Trojan-Downloader.Win32.Agent.fhv skipped
C:\Documents and Settings\All Users\Application Data\VMware\vmnetdhcp.leases Object is locked skipped
C:\Documents and Settings\user\Application Data\Xdrive\Xdrive Desktop\Tray.txt Object is locked skipped
C:\Documents and Settings\user\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\user\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\user\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\user\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\user\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\user\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx/[From "Mailer Daemon" <Kok-khiang_Annnora@juno.com>][Date Tue, 30 Dec 2003 20:59:58 -0400 (EST)]/UNNAMED/fail.hta/test.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx/[From "Mailer Daemon" <Kok-khiang_Annnora@juno.com>][Date Tue, 30 Dec 2003 20:59:58 -0400 (EST)]/UNNAMED/fail.hta Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx/[From "Mailer Daemon" <Kok-khiang_Annnora@juno.com>][Date Tue, 30 Dec 2003 20:59:58 -0400 (EST)]/UNNAMED Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx/[From <qteez@netzero.net>][Date Fri, 27 Jun 2003 0:04:50 --0700]/UNNAMED/your_details.zip/details.pif Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx/[From <qteez@netzero.net>][Date Fri, 27 Jun 2003 0:04:50 --0700]/UNNAMED/your_details.zip Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx/[From <qteez@netzero.net>][Date Fri, 27 Jun 2003 0:04:50 --0700]/UNNAMED Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx Mail MS Outlook 5: infected - 3, suspicious - 3 skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\Inbox.dbx/[From <Dalsjl@microsoft.com>][Date Thu, 20 Nov 2003 23:04:40 -0500]/UNNAMED/Capitalism Infected: Email-Worm.Win32.Tanatos.b skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\Inbox.dbx/[From <Dalsjl@microsoft.com>][Date Thu, 20 Nov 2003 23:04:40 -0500]/UNNAMED Infected: Email-Worm.Win32.Tanatos.b skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\Inbox.dbx Mail MS Outlook 5: infected - 2 skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Sun, 16 May 2004 06:56:57 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Fri, 23 Apr 2004 19:13:10 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Fri, 23 Apr 2004 00:11:39 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\r3ps.dbx Mail MS Outlook 5: infected - 3 skipped
C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\user\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\user\Local Settings\History\History.IE5\MSHist012007112420071125\index.dat Object is locked skipped
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\user\My Documents\vnc-4_1_1-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 skipped
C:\Documents and Settings\user\My Documents\vnc-4_1_1-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\user\My Documents\vnc-4_1_1-x86_win32.exe Inno: infected - 2 skipped
C:\Documents and Settings\user\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\user\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 skipped
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0037NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0860NAV~.TMP Object is locked skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Internet Logs\tvDebug.log Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\Sti_Trace.log Object is locked skipped
C:\WINNT\system32\CompleteLog.txt Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\system32\Service.txt Object is locked skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\Inbox.dbx/[From Dalsjl@microsoft.com][Date Thu, 20 Nov 2003 23:04:40 -0500]/UNNAMED/Capitalism Infected: Email-Worm.Win32.Tanatos.b skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\Inbox.dbx/[From Dalsjl@microsoft.com][Date Thu, 20 Nov 2003 23:04:40 -0500]/UNNAMED Infected: Email-Worm.Win32.Tanatos.b skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\Inbox.dbx/[From Dalsjl@microsoft.com][Date Thu, 20 Nov 2003 23:04:40 -0500]/UNNAMED/Capitalism Infected: Email-Worm.Win32.Tanatos.b skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\Inbox.dbx/[From Dalsjl@microsoft.com][Date Thu, 20 Nov 2003 23:04:40 -0500]/UNNAMED Infected: Email-Worm.Win32.Tanatos.b skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\Inbox.dbx Mail MS Outlook 5: infected - 4 skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Fri, 23 Apr 2004 00:11:39 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Fri, 23 Apr 2004 19:13:10 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Sun, 16 May 2004 06:56:57 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Fri, 23 Apr 2004 00:11:39 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Fri, 23 Apr 2004 19:13:10 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Sun, 16 May 2004 06:56:57 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx Mail MS Outlook 5: infected - 6 skipped
D:\drive_c_Dell\Documents and Settings\user\My Documents\vnc-4_1_1-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 skipped
D:\drive_c_Dell\Documents and Settings\user\My Documents\vnc-4_1_1-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
D:\drive_c_Dell\Documents and Settings\user\My Documents\vnc-4_1_1-x86_win32.exe Inno: infected - 2 skipped
D:\d_drive_2pups\archive\vnc-4_1_1-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 skipped
D:\d_drive_2pups\archive\vnc-4_1_1-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
D:\d_drive_2pups\archive\vnc-4_1_1-x86_win32.exe Inno: infected - 2 skipped
Scan process completed.
1) Installed Spybot - Search & Destroy Version 1.5 and downloaded the latest definitions
2) Ran an online scan with Kaspersky Online Scanner
3) Ran Spybot-S&D in safe mode and removed Smitfraud-C
4) Ran a system scan with Trend Micro HijackThis 2.0.2
It appears that Spybot was able to remove Smitfraud-C. But when I reran the Kaspersky online scanner, it found 10 viruses on my computer. When I reran Spybot, it said no immediate threats were found. Do I need to take any further action?
Thanks for your help,
Stephanie
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, November 24, 2007 10:04:00 PM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/11/2007
Kaspersky Anti-Virus database records: 465157
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 93089
Number of viruses found: 10
Number of infected objects: 43
Number of suspicious objects: 3
Duration of the scan process: 01:17:45
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\034C0000\474DD473.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ath skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\034C0001\474DD56E.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ath skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\034C0003\474DD59D.VBN Infected: Trojan-Downloader.Win32.Small.gll skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\059C0001\47DDDA69.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ath skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\059C0002\47DDDA7B.VBN Infected: Trojan-Downloader.Win32.Agent.fhv skipped
C:\Documents and Settings\All Users\Application Data\VMware\vmnetdhcp.leases Object is locked skipped
C:\Documents and Settings\user\Application Data\Xdrive\Xdrive Desktop\Tray.txt Object is locked skipped
C:\Documents and Settings\user\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\user\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\user\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\user\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\user\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\user\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx/[From "Mailer Daemon" <Kok-khiang_Annnora@juno.com>][Date Tue, 30 Dec 2003 20:59:58 -0400 (EST)]/UNNAMED/fail.hta/test.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx/[From "Mailer Daemon" <Kok-khiang_Annnora@juno.com>][Date Tue, 30 Dec 2003 20:59:58 -0400 (EST)]/UNNAMED/fail.hta Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx/[From "Mailer Daemon" <Kok-khiang_Annnora@juno.com>][Date Tue, 30 Dec 2003 20:59:58 -0400 (EST)]/UNNAMED Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx/[From <qteez@netzero.net>][Date Fri, 27 Jun 2003 0:04:50 --0700]/UNNAMED/your_details.zip/details.pif Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx/[From <qteez@netzero.net>][Date Fri, 27 Jun 2003 0:04:50 --0700]/UNNAMED/your_details.zip Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx/[From <qteez@netzero.net>][Date Fri, 27 Jun 2003 0:04:50 --0700]/UNNAMED Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\apdoug.dbx Mail MS Outlook 5: infected - 3, suspicious - 3 skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\Inbox.dbx/[From <Dalsjl@microsoft.com>][Date Thu, 20 Nov 2003 23:04:40 -0500]/UNNAMED/Capitalism Infected: Email-Worm.Win32.Tanatos.b skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\Inbox.dbx/[From <Dalsjl@microsoft.com>][Date Thu, 20 Nov 2003 23:04:40 -0500]/UNNAMED Infected: Email-Worm.Win32.Tanatos.b skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\Inbox.dbx Mail MS Outlook 5: infected - 2 skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Sun, 16 May 2004 06:56:57 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Fri, 23 Apr 2004 19:13:10 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Fri, 23 Apr 2004 00:11:39 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
C:\Documents and Settings\user\Local Settings\Application Data\Identities\{D5A3D873-CB96-4E0D-958A-87ADE802487E}\Microsoft\Outlook Express\r3ps.dbx Mail MS Outlook 5: infected - 3 skipped
C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\user\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\user\Local Settings\History\History.IE5\MSHist012007112420071125\index.dat Object is locked skipped
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\user\My Documents\vnc-4_1_1-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 skipped
C:\Documents and Settings\user\My Documents\vnc-4_1_1-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\user\My Documents\vnc-4_1_1-x86_win32.exe Inno: infected - 2 skipped
C:\Documents and Settings\user\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\user\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 skipped
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0037NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0860NAV~.TMP Object is locked skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Internet Logs\tvDebug.log Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\Sti_Trace.log Object is locked skipped
C:\WINNT\system32\CompleteLog.txt Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\system32\Service.txt Object is locked skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\Inbox.dbx/[From Dalsjl@microsoft.com][Date Thu, 20 Nov 2003 23:04:40 -0500]/UNNAMED/Capitalism Infected: Email-Worm.Win32.Tanatos.b skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\Inbox.dbx/[From Dalsjl@microsoft.com][Date Thu, 20 Nov 2003 23:04:40 -0500]/UNNAMED Infected: Email-Worm.Win32.Tanatos.b skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\Inbox.dbx/[From Dalsjl@microsoft.com][Date Thu, 20 Nov 2003 23:04:40 -0500]/UNNAMED/Capitalism Infected: Email-Worm.Win32.Tanatos.b skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\Inbox.dbx/[From Dalsjl@microsoft.com][Date Thu, 20 Nov 2003 23:04:40 -0500]/UNNAMED Infected: Email-Worm.Win32.Tanatos.b skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\Inbox.dbx Mail MS Outlook 5: infected - 4 skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Fri, 23 Apr 2004 00:11:39 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Fri, 23 Apr 2004 19:13:10 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Sun, 16 May 2004 06:56:57 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Fri, 23 Apr 2004 00:11:39 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Fri, 23 Apr 2004 19:13:10 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx/[From <aw-suspension@ebay.com>][Date Sun, 16 May 2004 06:56:57 -0400]/html Infected: Trojan-Spy.HTML.Bayfraud.co skipped
D:\drive_c_Dell\Documents and Settings\user\Local Settings\Application Data\Identities\{7A024F6A-BEFB-4051-97BA-32C6738A9799}\Microsoft\Outlook Express\r3ps.dbx Mail MS Outlook 5: infected - 6 skipped
D:\drive_c_Dell\Documents and Settings\user\My Documents\vnc-4_1_1-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 skipped
D:\drive_c_Dell\Documents and Settings\user\My Documents\vnc-4_1_1-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
D:\drive_c_Dell\Documents and Settings\user\My Documents\vnc-4_1_1-x86_win32.exe Inno: infected - 2 skipped
D:\d_drive_2pups\archive\vnc-4_1_1-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 skipped
D:\d_drive_2pups\archive\vnc-4_1_1-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
D:\d_drive_2pups\archive\vnc-4_1_1-x86_win32.exe Inno: infected - 2 skipped
Scan process completed.