View Single Post
Old 12-07-2008, 01:09 PM   #7 (permalink)
tamaraecho
Registered User
 
Join Date: Apr 2008
Posts: 14
OS: windows xp


Re: winweb security popups

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Sunday, December 7, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Sunday, December 07, 2008 03:56:00
Records in database: 1441542
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\

Scan statistics:
Files scanned: 76055
Threat name: 2
Infected objects: 3
Suspicious objects: 0
Duration of the scan: 01:51:46


File name / Threat name / Threats count
C:\Program Files\Lycos\IEagent\CSBIINST.DLL Infected: not-a-virus:AdWare.Win32.ClearSearch.c 1
C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\1933087776\915340387.exe.vir Infected: not-a-virus:FraudTool.Win32.WinwebSecurity.d 1
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1790\A0149428.exe Infected: not-a-virus:FraudTool.Win32.WinwebSecurity.d 1

The selected area was scanned.

2003-01-30 12:52:48 AC------ 12,073 C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\FAD.sys.vir
2008-12-03 10:14:42 A------- 1,070,115 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\1933087776\915340387.exe.vir
2008-12-03 10:14:52 A------- 198,741 C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\ws.dll.vir
2008-12-06 09:18:33 A------- 170 C:\Qoobox\Quarantine\catchme.log
2008-12-06 09:53:44 A------- 6,851 C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2008-12-06 09:55:09 A------- 0 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-CFSServ.exe.reg.dat
2008-12-06 09:55:09 A------- 0 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-NDSTray.exe.reg.dat
2008-12-06 09:55:09 A------- 0 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TFncKy.reg.dat
2008-12-06 09:55:17 A------- 155 C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-MoneyAgent.reg.dat
tamaraecho is offline