-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, April 27, 2008 6:48:08 AM
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/04/2008
Kaspersky Anti-Virus database records: 727420
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 16014
Number of viruses found: 26
Number of infected objects: 76
Number of suspicious objects: 5
Duration of the scan process: 00:36:54
Infected Object Name / Virus Name / Last Action
C:\Deckard\System Scanner\main.txt Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\Anthony\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Anthony\Desktop\hijthis.log Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\Anthony\Desktop\OTScanIt\MovedFiles\04192008_094956\Documents and Settings\Anthony\cftmon.exe Infected: Worm.Win32.Socks.bn skipped
C:\Documents and Settings\Anthony\Desktop\OTScanIt\MovedFiles\04192008_094956\gjtxc.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Documents and Settings\Anthony\Desktop\OTScanIt\MovedFiles\04192008_094956\WINDOWS\system32\etfqtjta.drv Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\Anthony\Desktop\OTScanIt\MovedFiles\04192008_094956\WINDOWS\system32\jqhedrgrlbc.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\Anthony\Desktop\OTScanIt\MovedFiles\04192008_094956\WINDOWS\system32\lpecakkacoh.nls Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\Anthony\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Anthony\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Anthony\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Anthony\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Anthony\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Anthony\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Anthony\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Anthony\Local Settings\History\History.IE5\MSHist012008042720080428\index.dat Object is locked skipped
C:\Documents and Settings\Anthony\Local Settings\Temp\famnitalqfe.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\Anthony\Local Settings\Temp\ocgsl.drv Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\Anthony\Local Settings\Temp\sqkqdibei.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Anthony\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Anthony\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\cftmon.exe Infected: Worm.Win32.Socks.bn skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Trend Micro\HijackThis\hijackthis.log Suspicious: Exploit.HTML.Mht skipped
C:\Program Files\Trend Micro\Thisisit\hijackthis.log Suspicious: Exploit.HTML.Mht skipped
C:\Program Files\Trend Micro\Thisisit\Thisfinal.log Suspicious: Exploit.HTML.Mht skipped
C:\QooBox\Quarantine\C\d.exe.vir Infected: Email-Worm.Win32.Locksky.ea skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\PPPATC~1\mshta.exe.vir Infected: Trojan-Downloader.Win32.Agent.kwg skipped
C:\QooBox\Quarantine\C\Program Files\ISM\ism.exe.vir Infected: not-a-virus:AdWare.Win32.AdBand.m skipped
C:\QooBox\Quarantine\C\Program Files\JavaCore\UnInstall.exe.vir Infected: Trojan-Downloader.Win32.Delf.gda skipped
C:\QooBox\Quarantine\C\Program Files\QdrModule\QdrModule13.exe.vir Infected: not-a-virus:AdWare.Win32.Agent.ahs skipped
C:\QooBox\Quarantine\C\WINDOWS\b155.exe.vir Infected: Trojan.Win32.BHO.bfl skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000090.exe.vir/stream/data0004 Infected: not-a-virus:AdWare.Win32.AdBand.w skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000090.exe.vir/stream Infected: not-a-virus:AdWare.Win32.AdBand.w skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000090.exe.vir NSIS: infected - 2 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ayhqhuvk.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.mvn skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\cefmxsak.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\dfwymlog.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.mwq skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\dpkuxiwq.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\shepzptf.dat.vir Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\spools.exe.vir Infected: Worm.Win32.Socks.bn skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\efcCvUoN.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.mcg skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\esovjjdt.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\fpbhyisa.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ftcrjwdk.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\giomrmyg.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ipobkkjl.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\lyokjcew.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.mvn skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mgplevjx.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\msram.dll.vir Infected: not-a-virus:AdWare.Win32.BHO.ajw skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mxnsisgr.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\otgpyydd.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.msm skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\pedllsdi.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ptcilgxp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.msm skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ryvrweka.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\wdjgvilw.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.mwq skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\wmsdkns.exe.vir Infected: not-virus:Hoax.Win32.Renos.bjs skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\wtxwojpt.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\xqaveafy.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.mwq skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\yvgkfqcw.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\catchme2008-02-27_190835.08.zip/iiktduut.dll Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\catchme2008-02-27_190835.08.zip/wvwxx.dll Infected: Packed.Win32.Monder.gen skipped
C:\QooBox\Quarantine\catchme2008-02-27_190835.08.zip ZIP: infected - 2 skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP42\A0054369.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP42\A0054369.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP42\A0054369.exe RarSFX: infected - 2 skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP42\A0054371.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP42\A0054371.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP42\A0054371.exe RarSFX: infected - 2 skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP42\A0054381.sys Infected: Email-Worm.Win32.Locksky.cm skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP42\A0054382.sys Infected: Email-Worm.Win32.Locksky.cm skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP42\A0054383.drv Infected: Email-Worm.Win32.Locksky.cm skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP42\A0054384.exe Infected: Trojan-Downloader.Win32.Agent.lxt skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP42\A0054385.dll Infected: Trojan-Downloader.Win32.Peregar.v skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP43\A0055466.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP43\A0055485.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP45\A0061093.exe Infected: not-virus:Hoax.Win32.Renos.bjs skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP45\A0063159.exe Infected: Worm.Win32.Socks.bn skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP45\A0063160.exe Infected: Trojan-Clicker.Win32.Costrat.fj skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP45\A0063162.exe Infected: Trojan-Downloader.Win32.Small.ujn skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP45\A0063165.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.aw skipped
C:\System Volume Information\_restore{77943BE7-4611-4D04-8EFC-A6657B547EB9}\RP45\change.log Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\explorer.exe Infected: Trojan.Win32.Patched.aa skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\default.htm Infected: not-virus:Hoax.HTML.Secureinvites.b skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\ktkaqel.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\WINDOWS\system32\lsass.exe Infected: Trojan.Win32.Patched.aa skipped
C:\WINDOWS\system32\services.exe Infected: Trojan.Win32.Patched.aa skipped
C:\WINDOWS\system32\spoolsv.exe Infected: Trojan.Win32.Patched.aa skipped
C:\WINDOWS\system32\sqmisoe.nls Infected: Email-Worm.Win32.Locksky.cm skipped
C:\WINDOWS\system32\svchost.exe Infected: Trojan.Win32.Patched.aa skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\winlogon.exe Infected: Trojan.Win32.Patched.aa skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
Scan process completed.