RipVanWinkle
New member
KOS scan
Wow, this has been an ordeal. Love spending my weekend doing this crap.
I tried to uninstall my Java installations but was unable to because of the following error message:
"The Windows Installer service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support personnel for assistance."
Yeah, no kidding.
Here, finally, is my KOS scan, in two parts due to its size:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, March 22, 2008 5:42:53 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 22/03/2008
Kaspersky Anti-Virus database records: 654855
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 89416
Number of viruses found: 19
Number of infected objects: 133
Number of suspicious objects: 100
Duration of the scan process: 01:41:18
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\56C63F0C.TMP Object is locked skipped
C:\Documents and Settings\Authorized User\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Authorized User\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Authorized User\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Authorized User\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Authorized User\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Authorized User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Authorized User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Authorized User\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Authorized User\Local Settings\History\History.IE5\MSHist012008032220080323\index.dat Object is locked skipped
C:\Documents and Settings\Authorized User\Local Settings\Temp\Perflib_Perfdata_150.dat Object is locked skipped
C:\Documents and Settings\Authorized User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Authorized User\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Authorized User\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc100.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc102.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc103.tmp/[From kienstraconcrete@prodigy.net][Date Mon, 17 Oct 2005 07:50:53 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc103.tmp/[From kienstraconcrete@prodigy.net][Date Mon, 17 Oct 2005 07:50:53 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc103.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc103.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc104.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc105.tmp/[From info@csacw.org][Date Thu, 15 Sep 2005 07:04:55 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc105.tmp/[From info@csacw.org][Date Thu, 15 Sep 2005 07:04:55 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc105.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc105.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc106.tmp/[From greatcustomer@msn.com][Date Wed, 28 Sep 2005 07:00:04 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc106.tmp/[From greatcustomer@msn.com][Date Wed, 28 Sep 2005 07:00:04 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc106.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc106.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc107.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc108.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc109.tmp Infected: Email-Worm.Win32.Bagle.fk skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc110.tmp Infected: Net-Worm.Win32.Mytob.ba skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc111.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc112.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc112.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc112.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc113.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc114.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc115.def Infected: Trojan-Downloader.Win32.Tibs.mn skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc116.tmp Infected: Email-Worm.Win32.NetSky.j skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc119.tmp/[From rneath@ch2m.com][Date Mon, 19 Sep 2005 07:07:38 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc119.tmp/[From rneath@ch2m.com][Date Mon, 19 Sep 2005 07:07:38 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc119.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc119.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc120.tmp/document.txt .exe Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc120.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc120.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc122.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc123.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc124.tmp/document.rtf.scr Infected: Email-Worm.Win32.NetSky.c skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc124.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc124.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc125.tmp/[From dickp@repedrotti.com][Date Fri, 16 Sep 2005 06:50:27 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc125.tmp/[From dickp@repedrotti.com][Date Fri, 16 Sep 2005 06:50:27 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc125.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc125.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc126.tmp Infected: Email-Worm.Win32.Bagle.fk skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc127.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc127.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc127.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc128.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc130.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc130.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc130.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc135.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc136.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc138.tmp/[From rlyrdymix1@aol.com][Date Wed, 26 Oct 2005 07:33:05 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc138.tmp/[From rlyrdymix1@aol.com][Date Wed, 26 Oct 2005 07:33:05 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc138.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc138.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc139.tmp/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc139.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc139.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc140.tmp/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc140.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc140.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc141.tmp Infected: Email-Worm.Win32.Tanatos.b.dam skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc143.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc145.tmp Infected: Email-Worm.Win32.Bagle.fk skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc146.tmp Infected: Net-Worm.Win32.Mytob.be skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc147.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc148.tmp/document.txt .exe Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc148.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc148.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc149.tmp/[From glc77@earthlink.net][Date Mon, 10 Oct 2005 22:01:40 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc149.tmp/[From glc77@earthlink.net][Date Mon, 10 Oct 2005 22:01:40 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc149.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc149.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc150.tmp/[From mark@weaversteel.com][Date Tue, 11 Oct 2005 06:55:25 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc150.tmp/[From mark@weaversteel.com][Date Tue, 11 Oct 2005 06:55:25 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc150.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc150.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc151.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc151.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc151.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc153.tmp Infected: Email-Worm.Win32.Zhelatin.o skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc155.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc156.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc157.tmp Infected: Email-Worm.Win32.Bagle.fj skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc159.tmp/[From cjones@acmegc.com][Date Wed, 31 Aug 2005 09:29:20 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc159.tmp/[From cjones@acmegc.com][Date Wed, 31 Aug 2005 09:29:20 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc159.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc159.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc160.tmp Infected: Email-Worm.Win32.NetSky.j skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc161.tmp/[From info@csacw.org][Date Thu, 29 Sep 2005 07:07:28 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc161.tmp/[From info@csacw.org][Date Thu, 29 Sep 2005 07:07:28 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc161.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc161.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc162.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc163.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc164.tmp Infected: Email-Worm.Win32.Bagle.fk skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc165.tmp/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc165.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc165.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc166.tmp/[From jrobertson@alberici.com][Date Mon, 10 Oct 2005 08:02:12 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc166.tmp/[From jrobertson@alberici.com][Date Mon, 10 Oct 2005 08:02:12 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc166.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc166.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc167.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc167.tmp
Wow, this has been an ordeal. Love spending my weekend doing this crap.
I tried to uninstall my Java installations but was unable to because of the following error message:
"The Windows Installer service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support personnel for assistance."
Yeah, no kidding.
Here, finally, is my KOS scan, in two parts due to its size:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, March 22, 2008 5:42:53 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 22/03/2008
Kaspersky Anti-Virus database records: 654855
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 89416
Number of viruses found: 19
Number of infected objects: 133
Number of suspicious objects: 100
Duration of the scan process: 01:41:18
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\56C63F0C.TMP Object is locked skipped
C:\Documents and Settings\Authorized User\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Authorized User\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Authorized User\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Authorized User\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Authorized User\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Authorized User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Authorized User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Authorized User\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Authorized User\Local Settings\History\History.IE5\MSHist012008032220080323\index.dat Object is locked skipped
C:\Documents and Settings\Authorized User\Local Settings\Temp\Perflib_Perfdata_150.dat Object is locked skipped
C:\Documents and Settings\Authorized User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Authorized User\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Authorized User\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc100.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc102.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc103.tmp/[From kienstraconcrete@prodigy.net][Date Mon, 17 Oct 2005 07:50:53 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc103.tmp/[From kienstraconcrete@prodigy.net][Date Mon, 17 Oct 2005 07:50:53 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc103.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc103.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc104.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc105.tmp/[From info@csacw.org][Date Thu, 15 Sep 2005 07:04:55 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc105.tmp/[From info@csacw.org][Date Thu, 15 Sep 2005 07:04:55 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc105.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc105.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc106.tmp/[From greatcustomer@msn.com][Date Wed, 28 Sep 2005 07:00:04 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc106.tmp/[From greatcustomer@msn.com][Date Wed, 28 Sep 2005 07:00:04 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc106.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc106.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc107.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc108.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc109.tmp Infected: Email-Worm.Win32.Bagle.fk skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc110.tmp Infected: Net-Worm.Win32.Mytob.ba skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc111.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc112.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc112.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc112.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc113.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc114.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc115.def Infected: Trojan-Downloader.Win32.Tibs.mn skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc116.tmp Infected: Email-Worm.Win32.NetSky.j skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc119.tmp/[From rneath@ch2m.com][Date Mon, 19 Sep 2005 07:07:38 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc119.tmp/[From rneath@ch2m.com][Date Mon, 19 Sep 2005 07:07:38 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc119.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc119.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc120.tmp/document.txt .exe Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc120.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc120.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc122.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc123.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc124.tmp/document.rtf.scr Infected: Email-Worm.Win32.NetSky.c skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc124.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc124.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc125.tmp/[From dickp@repedrotti.com][Date Fri, 16 Sep 2005 06:50:27 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc125.tmp/[From dickp@repedrotti.com][Date Fri, 16 Sep 2005 06:50:27 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc125.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc125.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc126.tmp Infected: Email-Worm.Win32.Bagle.fk skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc127.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc127.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc127.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc128.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc130.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc130.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc130.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc135.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc136.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc138.tmp/[From rlyrdymix1@aol.com][Date Wed, 26 Oct 2005 07:33:05 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc138.tmp/[From rlyrdymix1@aol.com][Date Wed, 26 Oct 2005 07:33:05 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc138.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc138.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc139.tmp/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc139.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc139.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc140.tmp/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc140.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc140.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc141.tmp Infected: Email-Worm.Win32.Tanatos.b.dam skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc143.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc145.tmp Infected: Email-Worm.Win32.Bagle.fk skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc146.tmp Infected: Net-Worm.Win32.Mytob.be skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc147.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc148.tmp/document.txt .exe Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc148.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc148.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc149.tmp/[From glc77@earthlink.net][Date Mon, 10 Oct 2005 22:01:40 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc149.tmp/[From glc77@earthlink.net][Date Mon, 10 Oct 2005 22:01:40 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc149.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc149.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc150.tmp/[From mark@weaversteel.com][Date Tue, 11 Oct 2005 06:55:25 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc150.tmp/[From mark@weaversteel.com][Date Tue, 11 Oct 2005 06:55:25 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc150.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc150.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc151.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc151.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc151.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc153.tmp Infected: Email-Worm.Win32.Zhelatin.o skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc155.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc156.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc157.tmp Infected: Email-Worm.Win32.Bagle.fj skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc159.tmp/[From cjones@acmegc.com][Date Wed, 31 Aug 2005 09:29:20 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc159.tmp/[From cjones@acmegc.com][Date Wed, 31 Aug 2005 09:29:20 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc159.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc159.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc160.tmp Infected: Email-Worm.Win32.NetSky.j skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc161.tmp/[From info@csacw.org][Date Thu, 29 Sep 2005 07:07:28 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc161.tmp/[From info@csacw.org][Date Thu, 29 Sep 2005 07:07:28 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc161.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc161.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc162.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc163.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc164.tmp Infected: Email-Worm.Win32.Bagle.fk skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc165.tmp/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc165.tmp ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc165.tmp CryptFF: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc166.tmp/[From jrobertson@alberici.com][Date Mon, 10 Oct 2005 08:02:12 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc166.tmp/[From jrobertson@alberici.com][Date Mon, 10 Oct 2005 08:02:12 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc166.tmp Mail: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc166.tmp CryptFF: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc167.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\RECYCLER\S-1-5-21-507921405-1532298954-839522115-1004\Dc167.tmp