Logfile of HijackThis v1.99.1
Scan saved at 14:44:20, on 01/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\lentera nuansa\My Documents\Tiyok\hijackthis\HijackThis.exe
F1 - win.ini: run=C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSInfo\
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [OESpamTest] C:\PROGRA~1\KASPER~1\KASPER~1\KASPER~3\OESpamTest.ExE
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = telkom
O17 - HKLM\Software\..\Telephony: DomainName = telkom
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0553B3A-2378-4681-B68F-C767321AF61B}: NameServer = 202.134.0.155 202.134.2.5
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = telkom
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = telkom
O23 - Service: CPUCooLServer Service (CPUCooLServer) - Unknown owner - C:\Program Files\CPUCooL\CooLSrv.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: JRun Service Manager (jsm-default) - Unknown owner - C:\Program Files\Macromedia\Generator 2\bin\jsm.exe
O23 - Service: kavsvc - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Security Suite\Kaspersky Anti-Spam Personal\KAV\KAVSVC.exe (file missing)
O23 - Service: Informix Dynamic Server Message Service (MsgServ) - Unknown owner - C:\WINDOWS\System32\msgserv.exe (file missing)
O23 - Service: Windows Update 64 (nbupd64) - Unknown owner - C:\WINDOWS\System32\nbupd64.exe" -netsvcs (file missing)
O23 - Service: ISM Server (nsrd) - Unknown owner - C:\ISM\2.20\bin\nsrd (file missing)
O23 - Service: ISM Local Execution (nsrexecd) - Unknown owner - C:\ISM\2.20\bin\nsrexecd (file missing)
O23 - Service: Informix IDS - ol_desknote (ol_desknote) - Unknown owner - C:\PROGRA~1\Informix\bin\onscpah.exe
O23 - Service: ISM Portmapper (portmap) - Unknown owner - C:\ISM\2.20\bin\portmap (file missing)
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Thursday, December 01, 2005 14:34:48
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 1/12/2005
Kaspersky Anti-Virus database records: 162545
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 91795
Number of viruses found: 16
Number of infected objects: 100
Number of suspicious objects: 0
Duration of the scan process: 6907 sec
Infected Object Name - Virus Name
C:\Documents and Settings\lentera nuansa\Desktop\l2mfix\backup.zip/dlls/ctmuid.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\Documents and Settings\lentera nuansa\Desktop\l2mfix\backup.zip/dlls/FG20ENU.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\Documents and Settings\lentera nuansa\Desktop\l2mfix\backup.zip/dlls/k0jsla171d.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\Documents and Settings\lentera nuansa\Desktop\l2mfix\backup.zip/dlls/mv84l9lq1.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\Documents and Settings\lentera nuansa\Desktop\l2mfix\backup.zip Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\Documents and Settings\lentera nuansa\Desktop\l2mfix\dlls\ctmuid.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\Documents and Settings\lentera nuansa\Desktop\l2mfix\dlls\FG20ENU.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\Documents and Settings\lentera nuansa\Desktop\l2mfix\dlls\k0jsla171d.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\Documents and Settings\lentera nuansa\Desktop\l2mfix\dlls\mv84l9lq1.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Thu, 24 Nov 2005 05:35:13 UTC]/UNNAMED/downloadm.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Thu, 24 Nov 2005 05:35:13 UTC]/UNNAMED/downloadm.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Thu, 24 Nov 2005 05:35:13 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 00:47:30 GMT]/UNNAMED/downloadm.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 00:47:30 GMT]/UNNAMED/downloadm.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 00:47:30 GMT]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 01:53:18 UTC]/UNNAMED/question_list.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 01:53:18 UTC]/UNNAMED/question_list.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 01:53:18 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 01:49:10 UTC]/UNNAMED/question_list.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 01:49:10 UTC]/UNNAMED/question_list.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 01:49:10 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 01:27:55 UTC]/UNNAMED/mailtext.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 01:27:55 UTC]/UNNAMED/mailtext.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 01:27:55 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 02:23:07 UTC]/UNNAMED/question_list.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 02:23:07 UTC]/UNNAMED/question_list.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 02:23:07 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 05:55:36 UTC]/UNNAMED/mail.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 05:55:36 UTC]/UNNAMED/mail.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 05:55:36 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 06:50:31 UTC]/UNNAMED/mail.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 06:50:31 UTC]/UNNAMED/mail.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 06:50:31 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 08:57:52 UTC]/UNNAMED/list379.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 08:57:52 UTC]/UNNAMED/list379.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 08:57:52 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Thu, 24 Nov 2005 00:35:55 UTC]/UNNAMED/downloadm.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Thu, 24 Nov 2005 00:35:55 UTC]/UNNAMED/downloadm.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Thu, 24 Nov 2005 00:35:55 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Wed, 23 Nov 2005 10:22:19 UTC]/UNNAMED/reg_pass-data.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Wed, 23 Nov 2005 10:22:19 UTC]/UNNAMED/reg_pass-data.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Wed, 23 Nov 2005 10:22:19 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Thu, 24 Nov 2005 05:35:13 UTC]/UNNAMED/downloadm.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Thu, 24 Nov 2005 05:35:13 UTC]/UNNAMED/downloadm.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Thu, 24 Nov 2005 05:35:13 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 00:47:30 GMT]/UNNAMED/downloadm.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 00:47:30 GMT]/UNNAMED/downloadm.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 00:47:30 GMT]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 01:53:18 UTC]/UNNAMED/question_list.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 01:53:18 UTC]/UNNAMED/question_list.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Fri, 25 Nov 2005 01:53:18 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Wed, 23 Nov 2005 10:22:19 UTC]/UNNAMED/reg_pass-data.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Wed, 23 Nov 2005 10:22:19 UTC]/UNNAMED/reg_pass-data.zip Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx/[From
[email protected]][Date Wed, 23 Nov 2005 10:22:19 UTC]/UNNAMED Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{5E34EEC8-E7FE-405D-9054-208B0DEF5A25}\Microsoft\Outlook Express\Inbox.dbx Infected: Email-Worm.Win32.Sober.y
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{C7FF2983-EB30-41EF-B366-84041FA944C8}\Microsoft\Outlook Express\Deleted Items.dbx/[From eBay <
[email protected]>][Date Mon, 07 Nov 2005 10:05:36 -0100]/UNNAMED/html Infected: Trojan-Spy.HTML.Bayfraud.hn
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{C7FF2983-EB30-41EF-B366-84041FA944C8}\Microsoft\Outlook Express\Deleted Items.dbx/[From eBay <
[email protected]>][Date Mon, 07 Nov 2005 10:05:36 -0100]/UNNAMED Infected: Trojan-Spy.HTML.Bayfraud.hn
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{C7FF2983-EB30-41EF-B366-84041FA944C8}\Microsoft\Outlook Express\Deleted Items.dbx/[From
[email protected]][Date Wed, 16 Nov 2005 16:52:41 +0800]/UNNAMED/file.zip/document.txt .exe Infected: Email-Worm.Win32.NetSky.q
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{C7FF2983-EB30-41EF-B366-84041FA944C8}\Microsoft\Outlook Express\Deleted Items.dbx/[From
[email protected]][Date Wed, 16 Nov 2005 16:52:41 +0800]/UNNAMED/file.zip Infected: Email-Worm.Win32.NetSky.q
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{C7FF2983-EB30-41EF-B366-84041FA944C8}\Microsoft\Outlook Express\Deleted Items.dbx/[From
[email protected]][Date Wed, 16 Nov 2005 16:52:41 +0800]/UNNAMED Infected: Email-Worm.Win32.NetSky.q
C:\Documents and Settings\lentera nuansa\Local Settings\Application Data\Identities\{C7FF2983-EB30-41EF-B366-84041FA944C8}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Email-Worm.Win32.NetSky.q
C:\Documents and Settings\lentera nuansa\Local Settings\Temp\GLB41.tmp/unknown2.bin Infected: not-a-virus:AdWare.Win32.Ucmore.e
C:\Documents and Settings\lentera nuansa\Local Settings\Temp\GLB41.tmp Infected: not-a-virus:AdWare.Win32.Ucmore.e
C:\Documents and Settings\lentera nuansa\Local Settings\Temporary Internet Files\Content.IE5\4TKTSFG5\MediaGateway[1].exe Infected: not-a-virus:AdWare.Win32.WinAD.bs
C:\Program Files\Common Files\Download\mc-58-12-0000141.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.l
C:\Program Files\Common Files\InetGet\mc-58-12-0000141.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.h
C:\Program Files\Common Files\mc-58-12-0000141.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.j
C:\Program Files\Common Files\Windows\mc-58-12-0000141.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.h
C:\Program Files\Opera\download\newretrievefile.cgi/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Opera\download\newretrievefile.cgi Infected: Email-Worm.Win32.Sober.y
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-1011\Dc5\Uninstall.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.BargainBuddy.y
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-1011\Dc5\Uninstall.exe/stream Infected: not-a-virus:AdWare.Win32.BargainBuddy.y
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-1011\Dc5\Uninstall.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.y
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\07EA160E/document.txt .exe Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\07EA160E Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\27665B69/document.txt .exe Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\27665B69 Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\2A2332C0/document.txt .exe Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\2A2332C0 Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\401245DB/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\401245DB Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\53001126/document.txt .exe Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\53001126 Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\601756BF/document.txt .exe Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\601756BF Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\68A2607D/document.txt .exe Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\68A2607D Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\711A472B/document.txt .exe Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\711A472B Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\7B9617A1/document.txt .exe Infected: Email-Worm.Win32.NetSky.q
C:\RECYCLER\S-1-5-21-436374069-813497703-854245398-500\Dc8\Norton Antivirus\Quarantine\7B9617A1 Infected: Email-Worm.Win32.NetSky.q
C:\WINDOWS\hdbyksr.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.s
C:\WINDOWS\system32\3obia8a5.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao
C:\WINDOWS\system32\i Infected: Trojan-Downloader.BAT.Ftp.ab
C:\WINDOWS\weirdontheweb_topc.exe/data0002 Infected: not-a-virus:AdWare.Win32.WeirWeb.b
C:\WINDOWS\weirdontheweb_topc.exe Infected: not-a-virus:AdWare.Win32.WeirWeb.b
D:\Musik\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.603
D:\data_joniku\joniku\Kump_PSMOP_Smg\dd\data\data D\GOZILLA.EXE/WISE0023.BIN Infected: not-a-virus:AdWare.Win32.Aureate.a
D:\data_joniku\joniku\Kump_PSMOP_Smg\dd\data\data D\GOZILLA.EXE/WISE0024.BIN Infected: not-a-virus:AdWare.Win32.Aureate.a
D:\data_joniku\joniku\Kump_PSMOP_Smg\dd\data\data D\GOZILLA.EXE Infected: not-a-virus:AdWare.Win32.Aureate.a
Scan process completed.