------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Tuesday, April 22, 2008 7:44:48 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 22/04/2008 Kaspersky Anti-Virus database records: 720686 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ Scan Statistics: Total number of scanned objects: 169865 Number of viruses found: 6 Number of infected objects: 9 Number of suspicious objects: 0 Duration of the scan process: 01:20:23 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\HPPAppActivity.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\HPPHomePageActivity.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-04-21_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\04C77C8C.htm Infected: Worm.Win32.Fujack.al skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\56024C84.htm Infected: Worm.Win32.Fujack.al skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\560F7475.htm Infected: Exploit.JS.Agent.do skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\56121E72.htm Infected: Exploit.JS.Agent.do skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6E152135.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped C:\Documents and Settings\Brendan\Application Data\BitTorrent\bittorrent.log Object is locked skipped C:\Documents and Settings\Brendan\Application Data\GTek\GTUpdate\AUpdate\NMSSupport\AUNet.log Object is locked skipped C:\Documents and Settings\Brendan\Application Data\GTek\GTUpdate\AUpdate\NMSSupport\AUNetDevs.log Object is locked skipped C:\Documents and Settings\Brendan\Application Data\GTek\GTUpdate\AUpdate\NMSSupport\IntelHCTAgent.log Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Microsoft\MSNLiveFav\LiveFavorites.xml Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Mozilla\Firefox\Profiles\s4jd7w5e.default\cert8.db Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Mozilla\Firefox\Profiles\s4jd7w5e.default\history.dat Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Mozilla\Firefox\Profiles\s4jd7w5e.default\key3.db Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Mozilla\Firefox\Profiles\s4jd7w5e.default\parent.lock Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Mozilla\Firefox\Profiles\s4jd7w5e.default\search.sqlite Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Mozilla\Firefox\Profiles\s4jd7w5e.default\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\call256.dbb Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\callmember256.dbb Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\chat512.dbb Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\chatmember256.dbb Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\chatmsg256.dbb Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\chatmsg512.dbb Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\contactgroup256.dbb Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\dyncontent\bundle.dat Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\index2.dat Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\profile256.dbb Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\user1024.dbb Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\user16384.dbb Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\user4096.dbb Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Skype\rionprower\voicemail256.dbb Object is locked skipped C:\Documents and Settings\Brendan\Application Data\Symantec\PendingAlertsQueue.log Object is locked skipped C:\Documents and Settings\Brendan\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Brendan\Desktop\OTScanIt\MovedFiles\04212008_193327\w2ngo.com Infected: Worm.Win32.AutoRun.dit skipped C:\Documents and Settings\Brendan\Local Settings\Application Data\ApplicationHistory\CLI.EXE.c88dbd71.ini.inuse Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\Application Data\ApplicationHistory\SysMonitor.exe.49302a1.ini.inuse Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\Application Data\Mozilla\Firefox\Profiles\s4jd7w5e.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\Application Data\Mozilla\Firefox\Profiles\s4jd7w5e.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\Application Data\Mozilla\Firefox\Profiles\s4jd7w5e.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\Application Data\Mozilla\Firefox\Profiles\s4jd7w5e.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\History\History.IE5\MSHist012008042220080423\index.dat Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\Temp\Perflib_Perfdata_13f0.dat Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\Temp\Perflib_Perfdata_14f0.dat Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\Temp\Perflib_Perfdata_9d0.dat Object is locked skipped C:\Documents and Settings\Brendan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Brendan\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Brendan\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\IUSR_NMPR\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\IUSR_NMPR\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\IUSR_NMPR\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML Object is locked skipped C:\Documents and Settings\IUSR_NMPR\NTUSER.DAT Object is locked skipped C:\Documents and Settings\IUSR_NMPR\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_collectiondb.mdb1 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_collectiondb.mdb2 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_collectionnameindex.mdb1 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_collectionnameindex.mdb2 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_collectionrevindex.mdb1 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_collectionrevindex.mdb2 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_collectiontypedateindex.mdb1 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_collectiontypedateindex.mdb2 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_collectiontypeindex.mdb1 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_collectiontypeindex.mdb2 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_collectiontypenameindex.mdb1 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_collectiontypenameindex.mdb2 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_content.mdb1 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_content.mdb2 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_creationdateindex.mdb1 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_creationdateindex.mdb2 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_propdb.mdb1 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_propdb.mdb2 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_typenameindex.mdb1 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_typenameindex.mdb2 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_urldb.mdb1 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_urldb.mdb2 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_urlindex.mdb1 Object is locked skipped C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\db\mb_urlindex.mdb2 Object is locked skipped C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped C:\Program Files\Norton AntiVirus\Savrt\0887NAV~.TMP Object is locked skipped C:\Program Files\Norton AntiVirus\Savrt\0905NAV~.TMP Object is locked skipped C:\Program Files\RealVNC\VNC4\vncclipboard.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.427 skipped C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped C:\System Volume Information\_restore{F425D7A6-1FDD-41A0-910F-9EDC736C094C}\RP151\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\ModemLog_Motorola SM56 Speakerphone Modem.txt Object is locked skipped C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{D91119AA-19A1-4BDE-AA3F-9F3B92E09C03}.crmlog Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\IntelDH.evt Object is locked skipped C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped D:\System Volume Information\_restore{F425D7A6-1FDD-41A0-910F-9EDC736C094C}\RP151\change.log Object is locked skipped D:\w2ngo.com Infected: Worm.Win32.AutoRun.dit skipped Scan process completed.