Thank you,
Disabling the Workstation Netlogon Service seemed to be the key to killing the infection. Attached is the Panda log and the Hijachthis log. I will be investigating this Panda software, as it seems to be catching more than the McAffee toolset.
Please let me know if there are any other tools you recommend to help keep my system clean (and how I can send you a few $ in thanks for your quick response). I am especially interested in anti-spamware that not only stops the spam, but informs the source ISP (I get 100's of spams a day) ...Ray
----------
Logfile of HijackThis v1.99.1
Scan saved at 4:40:16 AM, on 7/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [msiv32.exe] C:\WINDOWS\msiv32.exe
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) -
http://www.installen...gine/isetup.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
http://h30043.www3.h.../qdiagh.cab?307O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program
Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Iomega App Services - Iomega Corporation -
C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner -
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc -
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc -
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. -
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program
Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation -
C:\Program Files\Iomega\AutoDisk\ADService.exe
----------
Incident Status Location
Virus:W32/Mydoom.AI.worm Disinfected C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Backup\20050529-103850\Users\1\Front\1\M0000000273.msg[body.screply to this email (7.51 KB)]
Virus:W32/Mydoom.AI.worm Disinfected C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Users\1\Front\1\M0000000273.msg[body.screply to this email (7.51 KB)]
Virus:W32/Faribot.A.worm Disinfected C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Users\1\Front\1\M0000001890.msg[text.scr36.6 KB)]
Virus:W32/Mytob.AS.worm Disinfected C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Users\1\Front\1\M0000003367.eml[~000000.@x@][~000000.dat]
Virus:W32/Mytob.V.worm Disinfected C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Users\1\Front\1\M0000011206.msg[doc.scrlivery System (36.7 KB)]
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Ab scissor.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Broadband comparison.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Credit counseling.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Credit report.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Crm software.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Debt credit card.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Escorts.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Fha.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Health insurance.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Help desk software.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Insurance home.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Loan for debt consolidation.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Loan for people with bad credit.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Marketing email.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Mortgage insurance.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Mortgage life insurance.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Nevada corporations.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Online Betting Site.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Online gambling casino.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Online instant loan.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Order phentermine.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Payroll advance.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Personal loans online.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Personal loans with bad credit.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Prescription Drugs Rx Online.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Refinancing my mortgage.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Tahoe vacation rental.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Unsecured bad credit loans.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\Videos.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Owner\Favorites\Sites about\What is hydrocodone.url
Spyware:Spyware/Whazit No disinfected C:\WINDOWS\system32\fiz1
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\system32\in4bdlA.dll
Virus:WM/Pesan.B Disinfected Archive 1999\Archive (inbox)\Performance appraisal for Ray Haller\rh1997jb.doc
Virus:W32/Mytob.DR.worm Disinfected Junk\*WARNING* Your Email Account Will Be Closed\email-doc.zip[email-doc.txt .pif]
Virus:W32/Mytob.DR.worm Disinfected Junk\Security measures\information.zip[information.htm .exe]
Virus:W32/Mytob.DR.worm Disinfected Junk\*WARNING* YOUR EMAIL ACCOUNT WILL BE CLOSED\vzqplzq.zip[vzqplzq.htm .exe]
Virus:W32/Mytob.DR.worm Disinfected Junk\Important Notification\email-doc.zip[email-doc.htm .pif]
Virus:W32/Mytob.DR.worm Disinfected Junk\*WARNING* Your Email Account Will Be Closed\nmqyzmm.zip[nmqyzmm.txt .pif]
Virus:W32/Mytob.DR.worm Disinfected Junk\Account Alert\email-info.zip[email-info.doc .exe]
Virus:W32/Mytob.DR.worm Disinfected Junk\Your Email Account is Suspended For Security Reasons\email-info.zip[email-info.htm .pif]
Virus:W32/Mytob.DR.worm Disinfected Junk\Important Notification\document.zip[document.doc .scr]
Virus:W32/Mytob.DR.worm Disinfected Junk\Your Email Account is Suspended For Security Reasons\info-text.zip[info-text.doc .scr]
Virus:W32/Mytob.DR.worm Disinfected Junk\*WARNING* Your Email Account Will Be Closed\email-info.zip[email-info.txt .pif]
Virus:W32/Mytob.DR.worm Disinfected Junk\*WARNING* Your Email Account Will Be Closed\email-info.zip[email-info.htm .pif]
Virus:W32/Mytob.DR.worm Disinfected Junk\Your Email Account is Suspended For Security Reasons\information.zip[information.htm .pif]
Virus:W32/Mytob.DR.worm Disinfected Junk\Account Alert\email-info.zip[email-info.txt .exe]
Virus:W32/Mytob.DR.worm Disinfected Junk\*DETECTED* Online User Violation\information.zip[information.txt .exe]
Virus:W32/Mytob.DR.worm Disinfected Junk\*DETECTED* Online User Violation\INFO.zip[INFO.htm .exe]
Virus:W32/Mytob.DR.worm Disinfected Junk\Account Alert\email-doc.zip[email-doc.txt .exe]
Virus:W32/Mytob.DR.worm Disinfected Junk\IMPORTANT NOTIFICATION\information.zip[information.txt .scr]
Virus:W32/Mytob.DR.worm Disinfected Junk\Account Alert\information.zip[information.htm .exe]
Virus:W32/Mytob.DR.worm Disinfected Junk\*DETECTED* Online User Violation\info-text.zip[info-text.doc .scr]
Virus:W32/Mytob.DR.worm Disinfected Junk\Your Email Account is Suspended For Security Reasons\email-info.zip[email-info.txt .pif]
Virus:W32/Mytob.V.worm Disinfected Junk\Undelivered Mail Returned to Sender\Mail Delivery System\doc.scr
Virus:W32/Mytob.DN.worm Disinfected Junk\hello\body.exe
Virus:W32/Mytob.DN.worm Disinfected Junk\torumxkggijv\document.exe
Virus:W32/Mytob.DN.worm Disinfected Junk\Hello\document.zip[document.pif]
Virus:W32/Mytob.DN.worm Disinfected Junk\Good day\document.zip[document.pif]
Virus:W32/Mytob.DE.worm Disinfected Junk\Your Email Account is Suspended For Security Reasons\instructions.zip[instructions.txt .scr]
Virus:W32/Mytob.DE.worm Disinfected Junk\Notice: **Last Warning**\email-info.zip[email-info.htm .pif]
Virus:W32/Mytob.DE.worm Disinfected Junk\YOUR EMAIL ACCOUNT IS SUSPENDED FOR SECURITY REASONS\email-info.zip[email-info.exe]
Virus:W32/Mytob.DE.worm Disinfected Junk\Your Email Account is Suspended For Security Reasons\instructions.pif
Virus:W32/Mytob.DE.worm Disinfected Junk\eroa\document.zip[document.txt .scr]
Virus:W32/Mytob.DE.worm Disinfected Junk\SUSPENDED ACCOUNT\account-details.zip[account-details.txt .exe]
Virus:W32/Mytob.DE.worm Disinfected Junk\Your Email Account Has been Blocked\instructions.zip[instructions.pif]
Virus:W32/Mytob.DE.worm Disinfected Junk\Your Email Account Has been Blocked\info-text.zip[info-text.doc .pif]
Virus:W32/Mytob.DE.worm Disinfected Junk\Notice:***Your email account will be suspended***\email-doc.zip[email-doc.doc .exe]
Virus:W32/Mytob.DE.worm Disinfected Junk\Notice: **Last Warning**\email-info.pif
Virus:W32/Mytob.DE.worm Disinfected Junk\SUSPENDED ACCOUNT\instructions.zip[instructions.txt .scr]
Virus:W32/Mytob.DE.worm Disinfected Junk\*WARNING* Your Email Account Will Be Closed\information.zip[information.pif]
Virus:W32/Mytob.DE.worm Disinfected Junk\Your Email Account Has been Blocked\email-info.scr
Virus:W32/Mytob.DE.worm Disinfected Junk\Your Email Account Has been Blocked\email-info.zip[email-info.doc .scr]
Virus:W32/Mytob.DE.worm Disinfected Junk\Your Email Account Has been Blocked\email-info.scr
Virus:W32/Mytob.DE.worm Disinfected Junk\Notice: **Last Warning**\ijv.zip[ijv.exe]
Virus:W32/Mytob.DE.worm Disinfected Junk\Your Email Account Has been Blocked\document.zip[document.htm .pif]
Virus:W32/Mytob.DE.worm Disinfected Junk\Notice:***Your email account will be suspended***\email-info.zip[email-info.pif]
Virus:W32/Mytob.DE.worm Disinfected Junk\Your Email Account Has been Blocked\email-info.exe
Virus:W32/Mytob.DE.worm Disinfected Junk\YOUR EMAIL ACCOUNT IS SUSPENDED FOR SECURITY REASONS\information.zip[information.scr]
Virus:W32/Mytob.DE.worm Disinfected Junk\*WARNING* Your Email Account Will Be Closed\information.pif
Virus:W32/Mytob.DE.worm Disinfected Junk\YOUR EMAIL ACCOUNT HAS BEEN BLOCKED\information.zip[information.scr]
Virus:W32/Mytob.DE.worm Disinfected Junk\*WARNING* Your Email Account Will Be Closed\account-details.zip[account-details.pif]
Virus:W32/Mytob.DE.worm Disinfected Junk\*WARNING* YOUR EMAIL ACCOUNT WILL BE CLOSED\account-details.zip[account-details.pif]
Virus:W32/Mytob.DE.worm Disinfected Junk\FXPWTN\information.zip[information.exe]
Virus:W32/Mytob.DE.worm Disinfected Junk\SUSPENDED ACCOUNT\document.zip[document.pif]
Virus:W32/Mytob.DE.worm Disinfected Junk\*IMPORTANT* Please Validate Your Email Account\account-details.zip[account-details.txt .scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\Your Email Account is Suspended For Security Reasons\email-doc.scr
Virus:W32/Mytob.DB.worm Disinfected Junk\NOTICE:***YOUR EMAIL ACCOUNT WILL BE SUSPENDED***\email-doc.exe
Virus:W32/Mytob.DB.worm Disinfected Junk\Your email account access is restricted\IMPORTANT.zip[IMPORTANT.pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\your_details.pif
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice: **Last Warning**\INFO.zip[INFO.pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\*IMPORTANT* Please Validate Your Email Account\document_full.zip[document_full.scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\Your Email Account is Suspended For Security Reasons\email-info.zip[email-info.txt .scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\email-doc.pif
Virus:W32/Mytob.DB.worm Disinfected Junk\*IMPORTANT* PLEASE VALIDATE YOUR EMAIL ACCOUNT\email-text.zip[email-text.htm .pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\NOTICE: **LAST WARNING**\info-text.zip[info-text.scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\Security measures\your_details.zip[your_details.exe]
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\info-text.zip[info-text.htm .exe]
Virus:W32/Mytob.DB.worm Disinfected Junk\Your Email Account is Suspended For Security Reasons\email-info.zip[email-info.pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\Email Account Suspension\INFO.zip[INFO.pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\*IMPORTANT* Your Account Has Been Locked\bnwur.scr
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\IMPORTANT.zip[IMPORTANT.doc .pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\Your email account access is restricted\email-info.zip[email-info.scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\YOUR EMAIL ACCOUNT IS SUSPENDED FOR SECURITY REASONS\information.zip[information.bat]
Virus:W32/Mytob.DB.worm Disinfected Junk\Utbiaehurjnjhlkm\email-info.scr
Virus:W32/Mytob.DB.worm Disinfected Junk\Your email account access is restricted\email-doc.zip[email-doc.scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\Jualwri\information.scr
Virus:W32/Mytob.DB.worm Disinfected Junk\NOTICE:***YOUR EMAIL ACCOUNT WILL BE SUSPENDED***\email-doc.zip[email-doc.txt .exe]
Virus:W32/Mytob.DB.worm Disinfected Junk\Your email account access is restricted\email-doc.scr
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\email-doc.zip[email-doc.txt .pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\Your email account access is restricted\email-info.pif
Virus:W32/Mytob.DB.worm Disinfected Junk\Your email account access is restricted\IMPORTANT.scr
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\your_details.zip[your_details.scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\*IMPORTANT* Please Validate Your Email Account\info-text.pif
Virus:W32/Mytob.DB.worm Disinfected Junk\Email Account Suspension\email-info.zip[email-info.doc .pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\Your Email Account is Suspended For Security Reasons\email-text.zip[email-text.pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\info-text.zip[info-text.pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\Security measures\IMPORTANT.zip[IMPORTANT.scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\INFO.scr
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice: **Last Warning**\information.zip[information.txt .pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\YOUR EMAIL ACCOUNT ACCESS IS RESTRICTED\information.zip[information.exe]
Virus:W32/Mytob.DB.worm Disinfected Junk\NOTICE:***YOUR EMAIL ACCOUNT WILL BE SUSPENDED***\email-doc.zip[email-doc.doc .exe]
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\email-text.zip[email-text.pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\Your email account access is restricted\info-text.zip[info-text.exe]
Virus:W32/Mytob.DB.worm Disinfected Junk\NOTICE: **LAST WARNING**\your_details.zip[your_details.txt .exe]
Virus:W32/Mytob.DB.worm Disinfected Junk\NOTICE:***YOUR EMAIL ACCOUNT WILL BE SUSPENDED***\your_details.zip[your_details.pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\Security measures\IMPORTANT.zip[IMPORTANT.scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\*IMPORTANT* YOUR ACCOUNT HAS BEEN LOCKED\email-doc.zip[email-doc.pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\Email Account Suspension\IMPORTANT.zip[IMPORTANT.scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\email-info.zip[email-info.pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\info-text.zip[info-text.doc .pif]
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\your_details.zip[your_details.scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\NOTICE:***YOUR EMAIL ACCOUNT WILL BE SUSPENDED***\email-info.zip[email-info.txt .scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice:***Your email account will be suspended***\INFO.zip[INFO.scr]
Virus:W32/Mytob.DB.worm Disinfected Junk\Notice: **Last Warning**\your_details.zip[your_details.pif]
Virus:W32/Mytob.CP.worm Disinfected Junk\Hello\MAIL.exe
Virus:W32/Mytob.CP.worm Disinfected Junk\Here is your documents.\ATTACHMENT.zip[ATTACHMENT.htm .pif]
Virus:W32/Mydoom.BM.worm Disinfected Junk\Your Email Account is Suspended For Security Reasons\email-doc.zip[email-doc.pif]
Virus:W32/Mytob.CP.worm Disinfected Junk\SOMETHING FOR YOU\wgioz.zip[wgioz.pif]
Virus:W32/Mytob.CP.worm Disinfected Junk\Here is your documents.\DOCUMENT.scr
Virus:W32/Mytob.CP.worm Disinfected Junk\HERE IS YOUR DOCUMENTS.\MAIL.zip[MAIL.htm .pif]
Virus:W32/Mytob.CP.worm Disinfected Junk\Here is your documents.\DOCUMENT.zip[DOCUMENT.pif]
Virus:W32/Mytob.CP.worm Disinfected Junk\Status\DOCUMENT.zip[DOCUMENT.scr]
Virus:W32/Mytob.CP.worm Disinfected Junk\Here is your documents.\FILE.zip[FILE.scr]
Virus:W32/Mytob.CP.worm Disinfected Junk\HERE IS YOUR DOCUMENTS.\ATTACHMENT.zip[ATTACHMENT.pif]
Virus:W32/Mytob.CP.worm Disinfected Junk\MAIL.scr
Virus:W32/Mytob.CP.worm Disinfected Junk\Mail Delivery System\PayPal.zip[PayPal.pif]
Virus:W32/Mytob.CP.worm Disinfected Junk\something for you\FILE.zip[FILE.pif]
Virus:W32/Mytob.CP.worm Disinfected Junk\HERE IS YOUR DOCUMENTS.\DOCUMENT.zip[DOCUMENT.doc .scr]
Virus:W32/Mytob.CP.worm Disinfected Junk\Hello\PayPal.zip[PayPal.pif]
Virus:W32/Mytob.CP.worm Disinfected Junk\something for you\LETTER.zip[LETTER.htm .scr]
Virus:W32/Mytob.CP.worm Disinfected Junk\Error\DOCUMENT.zip[DOCUMENT.txt .exe]
Virus:W32/Mytob.CP.worm Disinfected Junk\Mail Transaction Failed\ATTACHMENT.zip[ATTACHMENT.scr]
Virus:W32/Mytob.CP.worm Disinfected Junk\HERE IS YOUR DOCUMENTS.\DOCUMENT.zip[DOCUMENT.pif]
Virus:W32/Mytob.CP.worm Disinfected Junk\Here is your documents.\ATTACHMENT.exe
Virus:W32/Mytob.CP.worm Disinfected Junk\HERE IS YOUR DOCUMENTS.\README.exe
Virus:W32/Mytob.CP.worm Disinfected Junk\README.scr
Virus:W32/Mytob.CP.worm Disinfected Junk\Mail Delivery System\ndwd.scr
Virus:W32/Mytob.CP.worm Disinfected Junk\HELLO\PayPal.zip[PayPal.exe]
Virus:W32/Mytob.CP.worm Disinfected Junk\Hello\DOCUMENT.zip[DOCUMENT.scr]
Virus:W32/Mydoom.BL.worm Disinfected Junk\HELLO\MAIL.pif
Virus:W32/Mydoom.BL.worm Disinfected Junk\something for you\LETTER.scr
Virus:W32/Mytob.BL.worm Disinfected Junk\Delivery Status Notification (Failure)\Hello\nizp.scr
Virus:W32/Mytob.BL.worm Disinfected Junk\HERE IS YOUR DOCUMENTS.\TEXT.zip[TEXT.scr]
Virus:W32/Mydoom.BL.worm Disinfected Junk\Here is your documents.\DOCUMENT.pif
Virus:W32/Mytob.BL.worm Disinfected Junk\something for you\ATTACHMENT.pif
Virus:W32/Mydoom.BL.worm Disinfected Junk\Delivery Status Notification (Failure)\README.zip[README.txt .exe]
Virus:W32/Mytob.AD.worm Disinfected Junk\Server Report\readme.zip[readme.txt .pif]
Virus:W32/Mytob.AD.worm Disinfected Junk\Server Report\body.pif
Virus:W32/Mytob.AD.worm Disinfected Junk\Good day\docume