——————————————————————————-
KASPERSKY ON-LINE SCANNER REPORT
Thursday, November 10, 2005 21:23:54
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 10/11/2005
Kaspersky Anti-Virus database records: 149556
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 23676
Number of viruses found: 13
Number of infected objects: 31
Number of suspicious objects: 0
Duration of the scan process: 3293 sec
Infected Object Name - Virus Name
C:\Documents and Settings\Bilgic\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-2cb7cc7d-1c4456db.zip/javainstaller/InstallerApplet.class Infected: Trojan-Downloader.Java.OpenStream.w
C:\Documents and Settings\Bilgic\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-2cb7cc7d-1c4456db.zip Infected: Trojan-Downloader.Java.OpenStream.w
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113340.dll Infected: Trojan-Spy.Win32.Small.dg
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113341.exe Infected: P2P-Worm.Win32.Wupeer.a
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113342.exe Infected: Trojan.Win32.StartPage.adi
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113343.exe Infected: Backdoor.Win32.Rbot.adf
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113344.exe Infected: Trojan-Proxy.Win32.Cimuz.bg
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113345.exe Infected: Trojan-PSW.Win32.Agent.bu
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113346.exe Infected: Backdoor.Win32.Agent.pn
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113347.exe Infected: Backdoor.Win32.Rbot.adf
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113355.dll Infected: Trojan-Proxy.Win32.Cimuz.ai
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113382.exe Infected: not-virus:Hoax.Win32.Renos.w
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113385.dll Infected: Trojan-Proxy.Win32.Cimuz.ai
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113388.dll Infected: Trojan-Spy.Win32.Small.dg
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113389.dll Infected: Trojan-Spy.Win32.Small.dg
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113390.exe Infected: Trojan-Downloader.Win32.Agent.xt
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113391.exe Infected: Backdoor.Win32.Agent.pn
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113407.dll Infected: Trojan-Proxy.Win32.Cimuz.ai
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113422.dll Infected: Trojan-Proxy.Win32.Cimuz.ai
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113431.dll Infected: Trojan-Proxy.Win32.Cimuz.ai
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113441.dll Infected: Trojan-Proxy.Win32.Cimuz.ai
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113455.dll Infected: Trojan-Proxy.Win32.Cimuz.ai
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0113464.dll Infected: Trojan-Proxy.Win32.Cimuz.ai
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0114469.dll Infected: Trojan-Proxy.Win32.Cimuz.ai
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0114478.dll Infected: Trojan-Proxy.Win32.Cimuz.ai
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0114481.dll Infected: Trojan-Proxy.Win32.Cimuz.ai
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0114490.dll Infected: Trojan-Proxy.Win32.Cimuz.ai
C:\System Volume Information\_restore{C8B3B1F2-70B6-48C4-AB6F-1F38E0D86BB7}\RP117\A0114493.exe Infected: Trojan-Proxy.Win32.Cimuz.bg
C:\WINDOWS\Downloaded Program Files\load.exe Infected: Trojan-Downloader.Win32.Agent.xq
C:\WINDOWS\TEMP\$_2341233.EXE Infected: Trojan-Dropper.Win32.Agent.aan
C:\WINDOWS\tool2.exe Infected: not-virus:Hoax.Win32.Renos.w
Scan process completed.
en HijackThis loggie:
Logfile of HijackThis v1.99.1
Scan saved at 21:25:06, on 10-11-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\WINDOWS\Microsoft.NET\Framework\v2.0.40607\aspnet_admin.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Bilgic\Mijn documenten\Anti-Virus Actie\HiJack This\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: “C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe” /icon
O4 - HKLM\..\Run: C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot
O4 - HKLM\..\Run: C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKCU\..\Run: “C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE”
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra ‘Tools’ menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF39EFE6-AE7A-40E3-B660-4538026DBE45}: NameServer = 195.121.1.34 195.121.1.66
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
en bedankt voor al je hulp he!! zulke vriendelijke mense kom je niet overal tegen