J
John Kelly
Hi there,
Yes, I know this is way off topic, but it is so important to readers of
this group that I have no other option but to write about it.
Today I was present when a number of messages arrived and my Anti Virus
system which is set to the most belligerent of settings possible gave a
warning that a virus had been detected. I checked and found that it was
attached to the above persons messages I posted a message in this group to
bring it to both his attention and those unfortunate enough to have
inadequate protection.
As many of you will know I have become annoyed with the antics of Mr. J.
Daniel Smith. So much so that I set my system to scan for all of his
messages. Those messages were put into a directory called :- C:\Program
Files\NewsRover\Projects\3329 Any files that accompany such messages are
placed into the subdirectory C:\Program
Files\NewsRover\Projects\3329\Files\. Mr. Smith now apparently seeing the
error in posting messages with his employers name attached has changed how
he posts his messages. So I modified the search and did a refresh of the
message base. It turns out that It was a very good idea.
And before we go any further, YES I do not care for Mr. Smith, yes I could
have faked all of this, if that's what you think then do not read any
further. On the other hand...its very revealing about what is on his
computer...just look at the name of some of the files.
Just now, and because I had not looked at the virus logs for quite a while
I decided to give them a once over. The top, there fore the most recent,
part of my log file is attached. I have edited out some of my system info
with XXXXXXXXXX
When I did a refresh of the message base today it seems my system had to
deal with rather a lot of inbound virus's . Every line where you see the
subdirectory name of "3329" is a virus of one sort or another that came
attached to messages originated by the above named. You can see the time
and date quite clearly. It also shows how little in the way of virus's
there were from all of the other messages that were also received/scanned.
So Mr. J. Daniel Smith. I hope you are going to do something about this.
From someone who claims to know something about computers this is...well
what can I say.
Category: Virus alerts
Date,Feature,Virus Name,Action Taken,Item Type,Target,Suspicious Action,User
Name,Computer Name,Details
04/12/2003 17:04:20,Auto-Protect,W95.ILMX.1291,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Notepad.exe
04/12/2003 17:04:16,Auto-Protect,Win.WinTiny,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\2E439491.EXE
04/12/2003 17:04:13,Auto-Protect,W2K.Infis.4608,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\30CB0B5D.EXE
04/12/2003 17:04:08,Auto-Protect,W32.Klinge,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\nach.EXE
04/12/2003 17:04:06,Auto-Protect,Trojan Horse,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\HD_Fixing.exe
04/12/2003 17:01:34,Auto-Protect,W32.Sahay.A@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\yahasux.exe
04/12/2003 17:01:33,Auto-Protect,W32.HLLW.Remat,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\VS035448.EXE
04/12/2003 17:01:32,Auto-Protect,W32.Zush@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\I-Worm.Kazus.exe
04/12/2003 17:01:31,Auto-Protect,W32.Buffy.33280.Worm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Buffy2k.exe
04/12/2003 17:01:30,Auto-Protect,W32.HLLP.Scrambler.B,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Scrambler.exe
04/12/2003 17:01:25,Auto-Protect,W32.Buffy.12568.Worm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Buffy.exe
04/12/2003 17:01:22,Auto-Protect,VBS.VBSWG.gen,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\I-Worm.Avalon.vbs
04/12/2003 17:01:22,Auto-Protect,Anna,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Anna.com
04/12/2003 17:01:20,Auto-Protect,W32.HLLP.Sharpei@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Sharp.exe
04/12/2003 16:36:41,Auto-Protect,W32.HLLW.Torvel.B@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\flt-xb5.rar.pif
04/12/2003 16:36:40,Auto-Protect,W32.HLLW.Torvel.B@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\829\Files\flt-xb5.rar.pif
04/12/2003 13:07:04,Auto-Protect,W32.Swen.A@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Install.exe
04/12/2003 10:53:21,Auto-Protect,W32.Swen.A@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\upgrade8255.exe
03/12/2003 18:00:35,Auto-Protect,Backdoor.Litmus.203.b,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\britney_spears.scr
03/12/2003 17:51:41,Auto-Protect,Backdoor.Litmus.203.b,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\britney_spears.scr
03/12/2003
15:26:01,Auto-Protect,W95.ILMX.1291,Repaired,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source:
C:\Program Files\NewsRover\Projects\3329\Files\Notepad.exe
03/12/2003 15:25:40,Auto-Protect,W95.Doggie.gen,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Win32.iwing.exe
03/12/2003
15:25:39,Auto-Protect,W97M.Zina.intd,Repaired,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source:
C:\Program Files\NewsRover\Projects\3329\Files\WM.Larva.doc
03/12/2003 15:25:36,Auto-Protect,W95.Pet_Tick.gen,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\singlung.exe
03/12/2003 15:25:34,Auto-Protect,W32.Updater.gen@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Report.Zip.exe
03/12/2003 15:25:34,Auto-Protect,Win.WinTiny,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\2E439491.EXE
03/12/2003 15:25:34,Auto-Protect,Win.WinTiny,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\2E439491.EXE
03/12/2003 15:25:31,Auto-Protect,W32.Klinge,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\nach.EXE
03/12/2003 15:25:31,Auto-Protect,W32.Klinge,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\nach.EXE
03/12/2003 15:25:31,Auto-Protect,IRC.Lazirc.a,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\SETUP.EXE
03/12/2003 15:25:31,Auto-Protect,IRC.Lazirc.a,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\SETUP.EXE
03/12/2003 15:25:30,Auto-Protect,W95.Mmorf.1348,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\2m.EXE
03/12/2003 15:25:30,Auto-Protect,W95.Mmorf.1348,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\2m.EXE
03/12/2003 15:25:30,Auto-Protect,Trojan Horse,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\FunnFaCTOR.bat
03/12/2003 15:25:30,Auto-Protect,Trojan Horse,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\FunnFaCTOR.bat
03/12/2003 15:25:28,Auto-Protect,W2K.Infis.4608,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\30CB0B5D.EXE
03/12/2003 15:25:28,Auto-Protect,W2K.Infis.4608,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\30CB0B5D.EXE
03/12/2003 15:24:11,Auto-Protect,W32.HLLW.Torvel.B@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\flt-xb5.rar.pif
03/12/2003 15:24:11,Auto-Protect,W32.HLLW.Torvel.B@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\829\Files\flt-xb5.rar.pif
03/12/2003 15:22:36,Auto-Protect,W32.HLLW.Remat,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\VS035448.EXE
03/12/2003 15:22:34,Auto-Protect,W32.Buffy.33280.Worm,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Buffy2k.exe
03/12/2003 15:22:34,Auto-Protect,W32.Buffy.33280.Worm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Buffy2k.exe
03/12/2003 15:22:31,Auto-Protect,W32.HLLP.Scrambler.B,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Scrambler.exe
03/12/2003 15:22:31,Auto-Protect,W32.HLLP.Scrambler.B,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Scrambler.exe
03/12/2003 15:22:30,Auto-Protect,W32.Buffy.12568.Worm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Buffy.exe
03/12/2003 15:22:30,Auto-Protect,W32.Buffy.12568.Worm,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Buffy.exe
03/12/2003 15:22:29,Auto-Protect,Hacktool,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\cichosz.EXE
03/12/2003 15:22:28,Auto-Protect,Anna,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Anna.com
03/12/2003 15:22:28,Auto-Protect,Anna,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Anna.com
03/12/2003 09:05:40,Auto-Protect,W32.HLLW.Torvel.B@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\flt-xb5.rar.pif
03/12/2003 09:05:40,Auto-Protect,W32.HLLW.Torvel.B@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\829\Files\flt-xb5.rar.pif
02/12/2003 05:52:26,Auto-Protect,W32.HLLW.Torvel.B@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\829\Files\flt-xb5.rar.pif
28/11/2003 07:16:27,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\777\Files\Patch28.exe
28/11/2003 07:16:25,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Patch28.exe
26/11/2003 21:41:33,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Installation45.exe
26/11/2003 21:41:27,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Installation45.exe
26/11/2003 21:41:22,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Installation45.exe
25/11/2003 07:56:19,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\777\Files\britney_spears.scr
25/11/2003 07:56:18,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\britney_spears.scr
25/11/2003 07:56:16,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\britney_spears.scr
25/11/2003 07:56:16,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\britney_spears.scr
25/11/2003 00:16:10,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\777\Files\britney_spears.scr
25/11/2003 00:16:09,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\britney_spears.scr
25/11/2003 00:16:08,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\britney_spears.scr
25/11/2003 00:16:07,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\britney_spears.scr
25/11/2003 00:14:14,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\829\Files\britney_spears.scr
24/11/2003 15:20:01,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Christina_Aguilera.scr
24/11/2003 14:08:45,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\777\Files\Christina_Aguilera.scr
24/11/2003 14:08:44,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Christina_Aguilera.scr
24/11/2003 10:44:26,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\777\Files\Parish_Hilton.scr
24/11/2003 07:45:24,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Parish_Hilton.scr
24/11/2003 07:45:13,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\829\Files\Parish_Hilton.scr
19/11/2003 12:17:23,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\q811565.exe
19/11/2003 12:17:21,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\q811565.exe
19/11/2003 12:17:18,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\q811565.exe
17/11/2003 19:20:33,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Installer72.exe
Yes, I know this is way off topic, but it is so important to readers of
this group that I have no other option but to write about it.
Today I was present when a number of messages arrived and my Anti Virus
system which is set to the most belligerent of settings possible gave a
warning that a virus had been detected. I checked and found that it was
attached to the above persons messages I posted a message in this group to
bring it to both his attention and those unfortunate enough to have
inadequate protection.
As many of you will know I have become annoyed with the antics of Mr. J.
Daniel Smith. So much so that I set my system to scan for all of his
messages. Those messages were put into a directory called :- C:\Program
Files\NewsRover\Projects\3329 Any files that accompany such messages are
placed into the subdirectory C:\Program
Files\NewsRover\Projects\3329\Files\. Mr. Smith now apparently seeing the
error in posting messages with his employers name attached has changed how
he posts his messages. So I modified the search and did a refresh of the
message base. It turns out that It was a very good idea.
And before we go any further, YES I do not care for Mr. Smith, yes I could
have faked all of this, if that's what you think then do not read any
further. On the other hand...its very revealing about what is on his
computer...just look at the name of some of the files.
Just now, and because I had not looked at the virus logs for quite a while
I decided to give them a once over. The top, there fore the most recent,
part of my log file is attached. I have edited out some of my system info
with XXXXXXXXXX
When I did a refresh of the message base today it seems my system had to
deal with rather a lot of inbound virus's . Every line where you see the
subdirectory name of "3329" is a virus of one sort or another that came
attached to messages originated by the above named. You can see the time
and date quite clearly. It also shows how little in the way of virus's
there were from all of the other messages that were also received/scanned.
So Mr. J. Daniel Smith. I hope you are going to do something about this.
From someone who claims to know something about computers this is...well
what can I say.
Category: Virus alerts
Date,Feature,Virus Name,Action Taken,Item Type,Target,Suspicious Action,User
Name,Computer Name,Details
04/12/2003 17:04:20,Auto-Protect,W95.ILMX.1291,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Notepad.exe
04/12/2003 17:04:16,Auto-Protect,Win.WinTiny,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\2E439491.EXE
04/12/2003 17:04:13,Auto-Protect,W2K.Infis.4608,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\30CB0B5D.EXE
04/12/2003 17:04:08,Auto-Protect,W32.Klinge,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\nach.EXE
04/12/2003 17:04:06,Auto-Protect,Trojan Horse,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\HD_Fixing.exe
04/12/2003 17:01:34,Auto-Protect,W32.Sahay.A@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\yahasux.exe
04/12/2003 17:01:33,Auto-Protect,W32.HLLW.Remat,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\VS035448.EXE
04/12/2003 17:01:32,Auto-Protect,W32.Zush@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\I-Worm.Kazus.exe
04/12/2003 17:01:31,Auto-Protect,W32.Buffy.33280.Worm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Buffy2k.exe
04/12/2003 17:01:30,Auto-Protect,W32.HLLP.Scrambler.B,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Scrambler.exe
04/12/2003 17:01:25,Auto-Protect,W32.Buffy.12568.Worm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Buffy.exe
04/12/2003 17:01:22,Auto-Protect,VBS.VBSWG.gen,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\I-Worm.Avalon.vbs
04/12/2003 17:01:22,Auto-Protect,Anna,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Anna.com
04/12/2003 17:01:20,Auto-Protect,W32.HLLP.Sharpei@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Sharp.exe
04/12/2003 16:36:41,Auto-Protect,W32.HLLW.Torvel.B@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\flt-xb5.rar.pif
04/12/2003 16:36:40,Auto-Protect,W32.HLLW.Torvel.B@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\829\Files\flt-xb5.rar.pif
04/12/2003 13:07:04,Auto-Protect,W32.Swen.A@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Install.exe
04/12/2003 10:53:21,Auto-Protect,W32.Swen.A@mm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\upgrade8255.exe
03/12/2003 18:00:35,Auto-Protect,Backdoor.Litmus.203.b,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\britney_spears.scr
03/12/2003 17:51:41,Auto-Protect,Backdoor.Litmus.203.b,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\britney_spears.scr
03/12/2003
15:26:01,Auto-Protect,W95.ILMX.1291,Repaired,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source:
C:\Program Files\NewsRover\Projects\3329\Files\Notepad.exe
03/12/2003 15:25:40,Auto-Protect,W95.Doggie.gen,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Win32.iwing.exe
03/12/2003
15:25:39,Auto-Protect,W97M.Zina.intd,Repaired,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source:
C:\Program Files\NewsRover\Projects\3329\Files\WM.Larva.doc
03/12/2003 15:25:36,Auto-Protect,W95.Pet_Tick.gen,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\singlung.exe
03/12/2003 15:25:34,Auto-Protect,W32.Updater.gen@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Report.Zip.exe
03/12/2003 15:25:34,Auto-Protect,Win.WinTiny,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\2E439491.EXE
03/12/2003 15:25:34,Auto-Protect,Win.WinTiny,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\2E439491.EXE
03/12/2003 15:25:31,Auto-Protect,W32.Klinge,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\nach.EXE
03/12/2003 15:25:31,Auto-Protect,W32.Klinge,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\nach.EXE
03/12/2003 15:25:31,Auto-Protect,IRC.Lazirc.a,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\SETUP.EXE
03/12/2003 15:25:31,Auto-Protect,IRC.Lazirc.a,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\SETUP.EXE
03/12/2003 15:25:30,Auto-Protect,W95.Mmorf.1348,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\2m.EXE
03/12/2003 15:25:30,Auto-Protect,W95.Mmorf.1348,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\2m.EXE
03/12/2003 15:25:30,Auto-Protect,Trojan Horse,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\FunnFaCTOR.bat
03/12/2003 15:25:30,Auto-Protect,Trojan Horse,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\FunnFaCTOR.bat
03/12/2003 15:25:28,Auto-Protect,W2K.Infis.4608,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\30CB0B5D.EXE
03/12/2003 15:25:28,Auto-Protect,W2K.Infis.4608,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\30CB0B5D.EXE
03/12/2003 15:24:11,Auto-Protect,W32.HLLW.Torvel.B@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\flt-xb5.rar.pif
03/12/2003 15:24:11,Auto-Protect,W32.HLLW.Torvel.B@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\829\Files\flt-xb5.rar.pif
03/12/2003 15:22:36,Auto-Protect,W32.HLLW.Remat,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\VS035448.EXE
03/12/2003 15:22:34,Auto-Protect,W32.Buffy.33280.Worm,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Buffy2k.exe
03/12/2003 15:22:34,Auto-Protect,W32.Buffy.33280.Worm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Buffy2k.exe
03/12/2003 15:22:31,Auto-Protect,W32.HLLP.Scrambler.B,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Scrambler.exe
03/12/2003 15:22:31,Auto-Protect,W32.HLLP.Scrambler.B,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Scrambler.exe
03/12/2003 15:22:30,Auto-Protect,W32.Buffy.12568.Worm,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Buffy.exe
03/12/2003 15:22:30,Auto-Protect,W32.Buffy.12568.Worm,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Buffy.exe
03/12/2003 15:22:29,Auto-Protect,Hacktool,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\cichosz.EXE
03/12/2003 15:22:28,Auto-Protect,Anna,Access
denied,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Anna.com
03/12/2003 15:22:28,Auto-Protect,Anna,Repair
failed,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\Anna.com
03/12/2003 09:05:40,Auto-Protect,W32.HLLW.Torvel.B@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\3329\Files\flt-xb5.rar.pif
03/12/2003 09:05:40,Auto-Protect,W32.HLLW.Torvel.B@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\829\Files\flt-xb5.rar.pif
02/12/2003 05:52:26,Auto-Protect,W32.HLLW.Torvel.B@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\829\Files\flt-xb5.rar.pif
28/11/2003 07:16:27,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\777\Files\Patch28.exe
28/11/2003 07:16:25,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Patch28.exe
26/11/2003 21:41:33,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Installation45.exe
26/11/2003 21:41:27,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Installation45.exe
26/11/2003 21:41:22,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Installation45.exe
25/11/2003 07:56:19,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\777\Files\britney_spears.scr
25/11/2003 07:56:18,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\britney_spears.scr
25/11/2003 07:56:16,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\britney_spears.scr
25/11/2003 07:56:16,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\britney_spears.scr
25/11/2003 00:16:10,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\777\Files\britney_spears.scr
25/11/2003 00:16:09,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\britney_spears.scr
25/11/2003 00:16:08,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\britney_spears.scr
25/11/2003 00:16:07,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\britney_spears.scr
25/11/2003 00:14:14,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\829\Files\britney_spears.scr
24/11/2003 15:20:01,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Christina_Aguilera.scr
24/11/2003 14:08:45,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\777\Files\Christina_Aguilera.scr
24/11/2003 14:08:44,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Christina_Aguilera.scr
24/11/2003 10:44:26,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\777\Files\Parish_Hilton.scr
24/11/2003 07:45:24,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Parish_Hilton.scr
24/11/2003 07:45:13,Auto-Protect,Backdoor.Litmus.203.b,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\829\Files\Parish_Hilton.scr
19/11/2003 12:17:23,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\q811565.exe
19/11/2003 12:17:21,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\q811565.exe
19/11/2003 12:17:18,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\q811565.exe
17/11/2003 19:20:33,Auto-Protect,W32.Swen.A@mm,Automatically
deleted,File,N/A,N/A,XXXXXXXXXX,XXXXXXXXXX,Source: C:\Program
Files\NewsRover\Projects\121\Files\Installer72.exe