-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, April 21, 2008 3:49:15 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/04/2008
Kaspersky Anti-Virus database records: 719022
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 165779
Number of viruses found: 25
Number of infected objects: 60
Number of suspicious objects: 3
Duration of the scan process: 02:25:53
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\AAA\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\cert8.db Object is locked skipped
C:\Documents and Settings\AAA\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\history.dat Object is locked skipped
C:\Documents and Settings\AAA\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\key3.db Object is locked skipped
C:\Documents and Settings\AAA\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\AAA\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\AOL OCP\AIM\Storage\data\the1debaser\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Identities\{ECD87E02-F692-4A1E-A80A-9B52EC9836A6}\Microsoft\Outlook Express\Sent Items.dbx/[From "Tyler Grant" <tgrant@orc.ca>][Date Mon, 4 Feb 2008 07:54:15 -0500]/UNNAMED/RemoteDesktopControlInstall.exe Infected: not-a-virus:RemoteAdmin.Win32.RemoteDesktopControl.a skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Identities\{ECD87E02-F692-4A1E-A80A-9B52EC9836A6}\Microsoft\Outlook Express\Sent Items.dbx/[From "Tyler Grant" <tgrant@orc.ca>][Date Mon, 4 Feb 2008 07:54:15 -0500]/UNNAMED Infected: not-a-virus:RemoteAdmin.Win32.RemoteDesktopControl.a skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Identities\{ECD87E02-F692-4A1E-A80A-9B52EC9836A6}\Microsoft\Outlook Express\Sent Items.dbx Mail MS Outlook 5: infected - 2 skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Identities\{ECD87E02-F692-4A1E-A80A-9B52EC9836A6}\Microsoft\Outlook Express\Tyler.dbx/[From JiNN <jinnproduction@gmail.com>][Date Fri, 4 Apr 2008 21:32:50 -0800]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Identities\{ECD87E02-F692-4A1E-A80A-9B52EC9836A6}\Microsoft\Outlook Express\Tyler.dbx/[From JiNN <jinnproduction@gmail.com>][Date Fri, 4 Apr 2008 21:32:50 -0800]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Identities\{ECD87E02-F692-4A1E-A80A-9B52EC9836A6}\Microsoft\Outlook Express\Tyler.dbx Mail MS Outlook 5: suspicious - 2 skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\History\History.IE5\MSHist012008042120080422\index.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Temp\BatSetup.exe Infected: not-a-virus:AdWare.Win32.Rabio.m skipped
C:\Documents and Settings\AAA\Local Settings\Temp\syswcc32.exe/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temp\syswcc32.exe/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temp\syswcc32.exe/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temp\syswcc32.exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temp\syswcc32.exe RarSFX: infected - 4 skipped
C:\Documents and Settings\AAA\Local Settings\Temp\~DFC9CD.tmp Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Temp\~DFE073.tmp Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\93e4c2046fcb4ac4bdc3dbbcc28127fb[1].zip/b155.exe Infected: Trojan.Win32.BHO.bhg skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\93e4c2046fcb4ac4bdc3dbbcc28127fb[1].zip ZIP: infected - 1 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmw skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\syswcc32[1].exe/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\syswcc32[1].exe/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\syswcc32[1].exe/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\syswcc32[1].exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\syswcc32[1].exe RarSFX: infected - 4 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\FBJ9L2VX\17PHolmes[1].cmt Infected: Trojan-Downloader.Win32.Homles.bi skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\FBJ9L2VX\3cd898b13299cb4bc0d5dc64745518ed[1].zip/b156.exe Infected: not-a-virus:AdWare.Win32.Insider.f skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\FBJ9L2VX\3cd898b13299cb4bc0d5dc64745518ed[1].zip ZIP: infected - 1 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\FBJ9L2VX\BatSetup[1].exe Infected: not-a-virus:AdWare.Win32.Rabio.m skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\FBJ9L2VX\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmx skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\XRBJ1TBU\b433b5a80d2cb00f8f1c54387f9aa332[1].zip/b157.exe Infected: Trojan-Downloader.Win32.Agent.jih skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\XRBJ1TBU\b433b5a80d2cb00f8f1c54387f9aa332[1].zip ZIP: infected - 1 skipped
C:\Documents and Settings\AAA\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\AAA\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Norman\Logs\nvc00004.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120007.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.plw skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120061.dll Infected: not-a-virus:AdWare.Win32.Rabio.m skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120065.exe Infected: Trojan-Downloader.Win32.PurityScan.fj skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120066.dll Infected: not-a-virus:AdWare.Win32.PurityScan.hk skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120068.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120071.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120071.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120077.exe Infected: Trojan-Downloader.Win32.Agent.ndt skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120083.exe Infected: Trojan-Downloader.Win32.Agent.nft skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120093.dll Infected: not-a-virus:AdWare.Win32.Rabio.m skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120094.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120095.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120096.exe Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120097.exe Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120099.exe Infected: Trojan-Downloader.Win32.Agent.ezc skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120102.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120103.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120104.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120105.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120106.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120106.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120106.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120106.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120110.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120111.exe Infected: Trojan-Downloader.Win32.Agent.ktb skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120112.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.pmw skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120122.exe Infected: Trojan-Downloader.Win32.Agent.lhu skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120183.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.plw skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120188.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.pmx skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120190.exe Infected: Trojan.Win32.BHO.bhg skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120191.exe Infected: not-a-virus:AdWare.Win32.Insider.f skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120192.exe Infected: Trojan-Downloader.Win32.Agent.jih skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120193.exe Infected: Trojan-Downloader.Win32.Homles.bi skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1802\change.log Object is locked skipped
C:\WINDOWS\b155.exe_old Infected: Trojan.Win32.BHO.bhg skipped
C:\WINDOWS\b156.exe_old Infected: not-a-virus:AdWare.Win32.Insider.f skipped
C:\WINDOWS\b157.exe_old Infected: Trojan-Downloader.Win32.Agent.jih skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{3ECC1DC6-D321-48B5-859D-965E321C4058}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
KASPERSKY ONLINE SCANNER REPORT
Monday, April 21, 2008 3:49:15 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/04/2008
Kaspersky Anti-Virus database records: 719022
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 165779
Number of viruses found: 25
Number of infected objects: 60
Number of suspicious objects: 3
Duration of the scan process: 02:25:53
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\AAA\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\cert8.db Object is locked skipped
C:\Documents and Settings\AAA\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\history.dat Object is locked skipped
C:\Documents and Settings\AAA\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\key3.db Object is locked skipped
C:\Documents and Settings\AAA\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\AAA\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\AOL OCP\AIM\Storage\data\the1debaser\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Identities\{ECD87E02-F692-4A1E-A80A-9B52EC9836A6}\Microsoft\Outlook Express\Sent Items.dbx/[From "Tyler Grant" <tgrant@orc.ca>][Date Mon, 4 Feb 2008 07:54:15 -0500]/UNNAMED/RemoteDesktopControlInstall.exe Infected: not-a-virus:RemoteAdmin.Win32.RemoteDesktopControl.a skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Identities\{ECD87E02-F692-4A1E-A80A-9B52EC9836A6}\Microsoft\Outlook Express\Sent Items.dbx/[From "Tyler Grant" <tgrant@orc.ca>][Date Mon, 4 Feb 2008 07:54:15 -0500]/UNNAMED Infected: not-a-virus:RemoteAdmin.Win32.RemoteDesktopControl.a skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Identities\{ECD87E02-F692-4A1E-A80A-9B52EC9836A6}\Microsoft\Outlook Express\Sent Items.dbx Mail MS Outlook 5: infected - 2 skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Identities\{ECD87E02-F692-4A1E-A80A-9B52EC9836A6}\Microsoft\Outlook Express\Tyler.dbx/[From JiNN <jinnproduction@gmail.com>][Date Fri, 4 Apr 2008 21:32:50 -0800]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Identities\{ECD87E02-F692-4A1E-A80A-9B52EC9836A6}\Microsoft\Outlook Express\Tyler.dbx/[From JiNN <jinnproduction@gmail.com>][Date Fri, 4 Apr 2008 21:32:50 -0800]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Identities\{ECD87E02-F692-4A1E-A80A-9B52EC9836A6}\Microsoft\Outlook Express\Tyler.dbx Mail MS Outlook 5: suspicious - 2 skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Application Data\Mozilla\Firefox\Profiles\x4htbu9q.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\History\History.IE5\MSHist012008042120080422\index.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Temp\BatSetup.exe Infected: not-a-virus:AdWare.Win32.Rabio.m skipped
C:\Documents and Settings\AAA\Local Settings\Temp\syswcc32.exe/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temp\syswcc32.exe/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temp\syswcc32.exe/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temp\syswcc32.exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temp\syswcc32.exe RarSFX: infected - 4 skipped
C:\Documents and Settings\AAA\Local Settings\Temp\~DFC9CD.tmp Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Temp\~DFE073.tmp Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\93e4c2046fcb4ac4bdc3dbbcc28127fb[1].zip/b155.exe Infected: Trojan.Win32.BHO.bhg skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\93e4c2046fcb4ac4bdc3dbbcc28127fb[1].zip ZIP: infected - 1 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmw skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\syswcc32[1].exe/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\syswcc32[1].exe/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\syswcc32[1].exe/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\syswcc32[1].exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\6XYLDZO4\syswcc32[1].exe RarSFX: infected - 4 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\FBJ9L2VX\17PHolmes[1].cmt Infected: Trojan-Downloader.Win32.Homles.bi skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\FBJ9L2VX\3cd898b13299cb4bc0d5dc64745518ed[1].zip/b156.exe Infected: not-a-virus:AdWare.Win32.Insider.f skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\FBJ9L2VX\3cd898b13299cb4bc0d5dc64745518ed[1].zip ZIP: infected - 1 skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\FBJ9L2VX\BatSetup[1].exe Infected: not-a-virus:AdWare.Win32.Rabio.m skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\FBJ9L2VX\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmx skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\XRBJ1TBU\b433b5a80d2cb00f8f1c54387f9aa332[1].zip/b157.exe Infected: Trojan-Downloader.Win32.Agent.jih skipped
C:\Documents and Settings\AAA\Local Settings\Temporary Internet Files\Content.IE5\XRBJ1TBU\b433b5a80d2cb00f8f1c54387f9aa332[1].zip ZIP: infected - 1 skipped
C:\Documents and Settings\AAA\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\AAA\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Norman\Logs\nvc00004.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120007.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.plw skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120061.dll Infected: not-a-virus:AdWare.Win32.Rabio.m skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120065.exe Infected: Trojan-Downloader.Win32.PurityScan.fj skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120066.dll Infected: not-a-virus:AdWare.Win32.PurityScan.hk skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120068.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120071.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120071.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120077.exe Infected: Trojan-Downloader.Win32.Agent.ndt skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120083.exe Infected: Trojan-Downloader.Win32.Agent.nft skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120093.dll Infected: not-a-virus:AdWare.Win32.Rabio.m skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120094.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120095.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120096.exe Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120097.exe Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120099.exe Infected: Trojan-Downloader.Win32.Agent.ezc skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120102.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120103.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120104.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120105.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120106.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120106.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120106.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120106.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120110.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120111.exe Infected: Trojan-Downloader.Win32.Agent.ktb skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120112.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.pmw skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120122.exe Infected: Trojan-Downloader.Win32.Agent.lhu skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120183.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.plw skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120188.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.pmx skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120190.exe Infected: Trojan.Win32.BHO.bhg skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120191.exe Infected: not-a-virus:AdWare.Win32.Insider.f skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120192.exe Infected: Trojan-Downloader.Win32.Agent.jih skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1801\A0120193.exe Infected: Trojan-Downloader.Win32.Homles.bi skipped
C:\System Volume Information\_restore{0F65BE6B-68D0-4B00-BD4F-4FC8C52408FA}\RP1802\change.log Object is locked skipped
C:\WINDOWS\b155.exe_old Infected: Trojan.Win32.BHO.bhg skipped
C:\WINDOWS\b156.exe_old Infected: not-a-virus:AdWare.Win32.Insider.f skipped
C:\WINDOWS\b157.exe_old Infected: Trojan-Downloader.Win32.Agent.jih skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{3ECC1DC6-D321-48B5-859D-965E321C4058}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.