Does this warning mean I am still infected (F secure)

K

kilowatt

Scanning Report
31 August 2005 13:37:29 - 15:03:58
Computer name: P4-2G
Target: C:\ D:\ H:\


--------------------------------------------------------------------------------

Result: 2 viruses found
C:\Documents and Settings\Terry\Local Settings\Temporary Internet
Files\Content.IE5\OPAVGDAN\index[3].htm Suspected infection:
Exploit.HTML.Mht
C:\Documents and Settings\Terry\Local Settings\Temporary Internet
Files\Content.IE5\FR57ZDWC\0006_regular[1].cab\istactivex.dll
Infection: Trojan-Downloader.Win32.IstBar.gen


--------------------------------------------------------------------------------

Statistics
Files:
Scanned: 89939
Infected: 1
Suspected: 1
Disinfected: 0
Renamed: 0
Deleted: 0
Not scanned: 21
Boot Sectors:
Scanned: 1
Infected: 0
Suspected: 0
Disinfected: 0
Files not scanned:
Cannot open file C:\pagefile.sys
Cannot open file C:\WINDOWS\system32\config\default
File C:\Program
Files\Yahoo!\YPSR\Quarantine\20050504193406.zip\irsetup.exe is
encrypted
Scanning of C:\MSOCache\All
Users\90000409-6000-11D3-8CFE-0150048383C9\E2561410.CAB\EXCEL.EXE was
aborted [F-Secure AVP]
Scanning of C:\MSOCache\All
Users\90000409-6000-11D3-8CFE-0150048383C9\O1561403.CAB\MSO.DLL was
aborted [F-Secure AVP]
File C:\Documents and Settings\All Users\Application Data\Spybot -
Search & Destroy\Recovery\AlexaRelated.zip\related.htm is encrypted
File C:\Documents and Settings\All Users\Application Data\Spybot -
Search & Destroy\Recovery\DSOExploit.zip\sbRecovery.reg is encrypted
File C:\Documents and Settings\All Users\Application Data\Spybot -
Search & Destroy\Recovery\DSOExploit1.zip\sbRecovery.reg is encrypted
File C:\Documents and Settings\All Users\Application Data\Spybot -
Search & Destroy\Recovery\DSOExploit2.zip\sbRecovery.reg is encrypted
File C:\Documents and Settings\All Users\Application Data\Spybot -
Search & Destroy\Recovery\DSOExploit3.zip\sbRecovery.reg is encrypted
File C:\Documents and Settings\All Users\Application Data\Spybot -
Search & Destroy\Recovery\DSOExploit4.zip\sbRecovery.reg is encrypted
File C:\Documents and Settings\All Users\Application Data\Spybot -
Search & Destroy\Recovery\SpyHunter.zip\sbRecovery.ini is encrypted
File C:\Documents and Settings\All Users\Application Data\Spybot -
Search & Destroy\Recovery\WildTangent.zip\Apps/CDA/ActiveLauncher.ini
is encrypted
File C:\Documents and Settings\All Users\Application Data\Spybot -
Search & Destroy\Recovery\WildTangent1.zip\sbRecovery.reg is encrypted
File C:\Documents and Settings\All Users\Application Data\Spybot -
Search & Destroy\Recovery\WildTangent2.zip\4.1.1/actorobject.dll is
encrypted
File C:\Documents and Settings\All Users\Application Data\Spybot -
Search & Destroy\Recovery\WildTangent3.zip\wcmdmgr.exe is encrypted
File C:\Documents and Settings\All Users\Application Data\Spybot -
Search &
Destroy\Recovery\WildTangent4.zip\CDALogger/4.1.0.001/files/CDALogger0401.dll
is encrypted
File H:\[z Cd Images\Might and Magic
VIII\mytmm801.zip\install.dat\1.jpg is encrypted
Scanning of H:\apps\Peachtree First
Accounting\e-efi201\Data1.cab\peachfa.chm was aborted [F-Secure AVP]
Scanning of H:\apps\Peachtree First
Accounting\e-efi201\Data1.cab\stamps.exe was aborted [F-Secure AVP]
Cannot open a file in archive H:\apps\Plus! for Windows XP\Plus! for
Windows XP.part01.rar\Plus! for Windows
XP\Common\SpeechEngines\Microsoft\SR\1033\l1033.ini


--------------------------------------------------------------------------------

Options
Virus definitions version:
2005-08-31_03
Scanning Engines:
F-Secure AVP: 6.0.167.6190, 2005-08-31
F-Secure Libra: 2.01.10, 2005-08-31
F-Secure Orion: 1.02.33, 2005-08-31
Scanning options:
Files scanned with extensions: ACM ASD ASP AX BAT BIN BOO CHM CNV COM
CPL CSC DLL DO? DRV EML EXE HLP HTA HTM HTML HTT INF INI JS JSE LNK MDB
MPD MPP MPT MSG MSO NWS OBD OBT OCX OV? PCI PDF PIF POT PP? PRC PWZ QWE
RTF SBF SCR SHB SHS SWF SYS TD0 TLB TSP TT6 VBE VBS VWP VXD WBK WBT WIZ
WML WPC WSC WSF WSH XL? ZL? . {* AVB CEO CMD LSP MAP MHT MIF TAR TGZ
PHP ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2
Scan inside archives: on
Action:
Disinfect infected files

--------------------------------------------------------------------------------

Copyright © 1998-2004 Product support | Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by
third parties that F-Secure World Wide Web pages have a link to. Unless
you have clearly stated otherwise, by submitting material to any of our
servers, for example by E-mail or via our F-Secure's CGI E-mail, you
agree that the material you make available may be published in the
F-Secure World Wide Pages or hard-copy publications. You will reach
F-Secure public web site by clicking on underlined links. While doing
this, your access will be logged to our private access statistics with
your domain name. This information will not be given to any third
party. You agree not to take action against us in relation to material
that you submit. Unless you have clearly stated otherwise, by
submitting material you warrant that F-Secure may incorporate any
concepts described in it in the F-Secure products/publications without
liability.
 
D

David H. Lipman

From: <[email protected]>

| Scanning Report
| 31 August 2005 13:37:29 - 15:03:58
| Computer name: P4-2G
| Target: C:\ D:\ H:\
|
| --------------------------------------------------------------------------------
|
| Result: 2 viruses found
| C:\Documents and Settings\Terry\Local Settings\Temporary Internet
| Files\Content.IE5\OPAVGDAN\index[3].htm Suspected infection:
| Exploit.HTML.Mht
| C:\Documents and Settings\Terry\Local Settings\Temporary Internet
| Files\Content.IE5\FR57ZDWC\0006_regular[1].cab\istactivex.dll
| Infection: Trojan-Downloader.Win32.IstBar.gen
|
| --------------------------------------------------------------------------------

< report snipped >

Dump the contents of your IE cache then scan again.
Start --> settings --> control panel --> Internet options --> delete files

Suggested size of the cache: ~10MB
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top