ok thanks for that both reports below,
i will delete all quaritened files from norton, as for Outlook backup files as they are not likely to be opened and will be overwritten i will leave for now unless you suggest otherwise.
The nove incoming files i will delete, but what about last item in Kaspersky report about system information being infected. I also have not yet disabled and re-abled system restore i would assume that is the last thing i do before i re-boot?
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 10:07:53, 08/01/2006
+ Report-Checksum: 62C5B987
+ Scan result:
C:\Documents and Settings\Amy\Cookies\amy@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\cgzq2jqd.default\coo kies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
C:\Documents and Settings\Russell\Cookies\russell@112.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Russell\Cookies\russell@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
C:\Documents and Settings\Russell\Local Settings\Temporary Internet Files\Content.IE5\S1YNGD23\mm[1].
js -> Spyware.Chitika : Cleaned with backup
H:\nova incoming\Winamp.Pro.v5.04.Winall.Incl.Keymaker-Core\keygen_winamp.exe -> Spyware.Hijacker.Generic : Cleaned with backup
H:\nova incoming\Winamp.Pro.v5.04.Winall.Incl.Keymaker-Core.zip/keygen_winamp.exe -> Spyware.Hijacker.Generic : Error during cleaning
-----------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Sunday, January 08, 2006 11:41:47
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 8/01/2006
Kaspersky Anti-Virus database records: 169724
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
Scan Statistics:
Total number of scanned objects: 73636
Number of viruses found: 9
Number of infected objects: 71
Number of suspicious objects: 4
Duration of the scan process: 4154 sec
Infected Object Name - Virus Name
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\030A1596.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\030A1596.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0EF07C76.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0EF07C76.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0F805D48.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0F805D48.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\17E7157D.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\17E7157D.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1AA660E9.tmp Infected: Email-Worm.Win32.NetSky.c
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1D7D5101.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1D7D5101.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1ED40987.tmp Infected: Trojan-Proxy.Win32.Agent.hx
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\31D160AF.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\31D160AF.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\33566503.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\33566503.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\38614F2F.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\38614F2F.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\38CA7300.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\38CA7300.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3AC406DC.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3D371EAC.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3D371EAC.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3DC00215.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3DC00215.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\453D698F.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\453D698F.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\456B355D.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\456B355D.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\45AE0962.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\45AE0962.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\468A3C02.tmp Infected: Email-Worm.Win32.NetSky.c
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\48EB31D1.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\48EB31D1.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4E120856.tmp/death.txt.scr Infected: Email-Worm.Win32.NetSky.c
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4E120856.tmp Infected: Email-Worm.Win32.NetSky.c
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4E9E1345.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4E9E1345.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\562D3742.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\562D3742.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5AF05C4D.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5AF05C4D.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5E8D3AC1.tmp Infected: Email-Worm.Win32.NetSky.c
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\63A3174D.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\63A3174D.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\63D40D17.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\63D40D17.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\64227CC1.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\64227CC1.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\71197F0F.tmp/[From
20george.hall@docutex.co.uk][Date Fri, 7 Oct 2005 07:52:13 +0100]/yours.pif Infected: Email-Worm.Win32.NetSky.d
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\71197F0F.tmp Infected: Email-Worm.Win32.NetSky.d
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\716E42B1.tmp/[From
prescott_thomas@compuserve.com][Date Fri, 7 Oct 2005 12:50:39 +0100]/my_details.pif Infected: Email-Worm.Win32.NetSky.d
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\716E42B1.tmp Infected: Email-Worm.Win32.NetSky.d
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7C511CFA.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7C511CFA.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7C5E44EB.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7C5E44EB.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7E2D2E5A.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7E2D2E5A.tmp Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7EA63FD6.tmp/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7EA63FD6.tmp Infected: Email-Worm.Win32.Sober.y
H:\backup\outlook\08-01-06.pst/Personal Folders/Sent Items/11 Jun 2003 16:33 to
support@nildram.net:FW: De Savary.rtf Suspicious: Exploit.HTML.Iframe.FileDownload
H:\backup\outlook\08-01-06.pst/Personal Folders/Sent Items/14 Jun 2003 07:37 to
abuse@nildram.net:FW: De Savary.rtf Suspicious: Exploit.HTML.Iframe.FileDownload
H:\backup\outlook\08-01-06.pst/Personal Folders/Norton AntiSpam Folder/26 Dec 2005 17:19 from eBay:[Norton AntiSpam] eBay Official Upda.rtf Infected: Trojan-Spy.HTML.Bayfraud.hn
H:\backup\outlook\08-01-06.pst/Personal Folders/Norton AntiSpam Folder/03 Jan 2006 10:08 from eBay Inc:[Norton AntiSpam] eBay - importa.rtf Infected: Trojan-Spy.HTML.Bayfraud.hn
H:\backup\outlook\08-01-06.pst/Personal Folders/Norton AntiSpam Folder/07 Jan 2006 07:58 from Halifax bank:[Norton AntiSpam] Halifax In.rtf Infected: Trojan-Spy.HTML.Bankfraud.hs
H:\backup\outlook\08-01-06.pst/Personal Folders/Norton AntiSpam Folder/07 Jan 2006 10:51 from eBay:[Norton AntiSpam] ATTENTION EBAY CLI.rtf Infected: Trojan-Spy.HTML.Bayfraud.hn
H:\backup\outlook\08-01-06.pst Infected: Trojan-Spy.HTML.Bayfraud.hn
H:\backup\outlook\sent.pst/Personal Folders/Sent Items/11 Jun 2003 16:33 to
support@nildram.net:FW: De Savary.html Suspicious: Exploit.HTML.Iframe.FileDownload
H:\backup\outlook\sent.pst/Personal Folders/Sent Items/14 Jun 2003 07:37 to
abuse@nildram.net:FW: De Savary.html Suspicious: Exploit.HTML.Iframe.FileDownload
H:\backup\outlook\sent.pst/Personal Folders/Norton AntiSpam Folder/27 Sep 2005 05:33 from
support@paypal.com:[Norton AntiSpam] PayP.html Infected: Trojan-Spy.HTML.Paylap.fg
H:\backup\outlook\sent.pst Infected: Trojan-Spy.HTML.Paylap.fg
H:\nova incoming\Winamp.Pro.v5.04.Winall.Incl.Keymaker-Core.zip/keygen_winamp.exe Infected: Trojan.Win32.StartPage.sr
H:\nova incoming\Winamp.Pro.v5.04.Winall.Incl.Keymaker-Core.zip Infected: Trojan.Win32.StartPage.sr
H:\System Volume Information\_restore{077E512F-B1F7-4523-B328-F38C485E528C}\RP106\A0053426.exe Infected: Trojan.Win32.StartPage.sr
Scan process completed.