------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Wednesday, January 31, 2007 1:45:33 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 31/01/2007 Kaspersky Anti-Virus database records: 263744 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan Statistics: Total number of scanned objects: 79594 Number of viruses found: 6 Number of infected objects: 17 / 0 Number of suspicious objects: 0 Duration of the scan process: 02:15:34 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Zane Edwards\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Zane Edwards\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped C:\Documents and Settings\Zane Edwards\Local Settings\Application Data\Ahead\Nero Home\bl.db-journal Object is locked skipped C:\Documents and Settings\Zane Edwards\Local Settings\Application Data\Ahead\Nero Home\is2.db Object is locked skipped C:\Documents and Settings\Zane Edwards\Local Settings\Application Data\Ahead\Nero Home\is2.db-journal Object is locked skipped C:\Documents and Settings\Zane Edwards\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Zane Edwards\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Zane Edwards\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Zane Edwards\Local Settings\History\History.IE5\MSHist012007013120070201\index.dat Object is locked skipped C:\Documents and Settings\Zane Edwards\Local Settings\Temp\~DF1B5B.tmp Object is locked skipped C:\Documents and Settings\Zane Edwards\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Zane Edwards\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Zane Edwards\ntuser.dat.LOG Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\dlg\temp\001.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\002.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\003.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\004.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\005.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\006.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\007.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\008.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\009.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\010.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\011.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\012.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\013.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\014.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\015.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\016.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\017.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\018.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\019.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\020.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\021.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\022.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\023.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\024.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\025.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\026.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\027.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\028.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\029.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\030.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\031.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\032.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\033.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\034.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\035.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\036.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\037.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\038.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\039.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\040.part Object is locked skipped C:\WINDOWS\system32\dlg\temp\041.part Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\vapicwmi.exe/stream.dat/cmdsys.exe Infected: Trojan-Downloader.Win32.Mypay.a skipped C:\WINDOWS\system32\vapicwmi.exe/stream.dat/tmp.ocx Infected: Trojan-Downloader.Win32.Mypay.b skipped C:\WINDOWS\system32\vapicwmi.exe/stream.dat Infected: Trojan-Downloader.Win32.Mypay.b skipped C:\WINDOWS\system32\vapicwmi.exe APackage: infected - 3 skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped D:\WINNT\system32\AST.exe/WISE0006.BIN Infected: Trojan-Downloader.Win32.VB.ah skipped D:\WINNT\system32\AST.exe WiseSFX: infected - 1 skipped D:\WINNT\gsi.exe/data0002/data0136 Infected: not-a-virus:AdWare.Win32.HelpExpress skipped D:\WINNT\gsi.exe/data0002 Infected: not-a-virus:AdWare.Win32.HelpExpress skipped D:\WINNT\gsi.exe/data0003/data0115 Infected: not-a-virus:AdWare.Win32.HelpExpress skipped D:\WINNT\gsi.exe/data0003 Infected: not-a-virus:AdWare.Win32.HelpExpress skipped D:\WINNT\gsi.exe NSIS: infected - 4 skipped D:\WINNT\unast.exe/WISE0006.BIN Infected: Trojan-Downloader.Win32.VB.ah skipped D:\WINNT\unast.exe WiseSFX: infected - 1 skipped D:\Program Files\Norton AntiVirus\Quarantine\4DBE3CA2.EXE Infected: Trojan-Spy.Win32.AdvKeyLogger skipped E:\installs\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped E:\installs\mirc616.exe mIRC: infected - 1 skipped E:\Program Files\mIRC\backup\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped Scan process completed.