Scan started: Mon Mar 28 14:50:05 2005



C:\GnuWin32\1.0\home\b21an\Workspace\HOWTO\LG\lg-108.tar.gz: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\\lg-108.tar.gz'

C:\GnuWin32\1.0\home\b21an\Workspace\HOWTO\LG\lg-issue86.tar.gz: moved to 'C:\Documents and Settings\All Users\.clamwin\quarantine\\lg-issue86.tar.gz'

ERROR: Can't open file C:\WINDOWS\SoftwareDistribution\EventCache\86719410-2583-4BF4-8202-94A1CBB34B36.bin

ERROR: Can't open file C:\WINDOWS\SoftwareDistribution\EventCache\EDE1AC3A-2996-4C2C-AB05-F9E3AF5FFE81.bin

ERROR: Can't open file C:\WINDOWS\system32\CatRoot2\tmp.edb

ERROR: Can't open file C:\WINDOWS\system32\config\default

ERROR: Can't open file C:\WINDOWS\system32\config\SAM

ERROR: Can't open file C:\WINDOWS\system32\config\SECURITY

ERROR: Can't open file C:\WINDOWS\system32\config\software

ERROR: Can't open file C:\WINDOWS\system32\config\system



C:\GnuWin32\1.0\home\b21an\Workspace\HOWTO\LG\lg-108.tar.gz: HTML.Phishing.Bank-1 FOUND

C:\GnuWin32\1.0\home\b21an\Workspace\HOWTO\LG\lg-issue86.tar.gz: Exploit.IFrame.Gen FOUND

- -- summary --

Known viruses: 31931

Scanned directories: 4779

Scanned files: 59220

Infected files: 2



Data scanned: 10810.64 MB

I/O buffer size: 131072 bytes

Time: 5137.895 sec (85 m 37 s)

- -------------------

Completed

- -------------------


#!/bin/sh

#http://linuxgazette.net/ftpfiles/
#http://linuxgazette.net/ftpfiles/lg-100.tar.gz
#http://linuxgazette.net/ftpfiles/lg-base.tar.gz
#http://linuxgazette.net/ftpfiles/lg-issue-1to-6.tar.gz
#http://linuxgazette.net/ftpfiles/lg-issue09.tar.gz
#http://linuxgazette.net/ftpfiles/lg-issue99.tar.gz

#wget http://linuxgazette.net/ftpfiles/lg-issue$i.tar.gz
#http://linuxgazette.net/ftpfiles/lg-issue-1to-6.tar.gz

i=100
until [ $i = 114 ];
do {
 if [$i < 7 ]; then
  echo "no-op: $i"
 fi
 if [$i < 10 ]; then
  "C:\windows\system32\UNIX\bin\wget.exe" --random-wait http://linuxgazette.net/ftpfiles/lg-issue0$i.tar.gz
 else
  "C:\windows\system32\UNIX\bin\wget.exe" --random-wait http://linuxgazette.net/ftpfiles/lg-$i.tar.gz
 fi

 let "i += 1"

} done

#"C:\windows\system32\UNIX\bin\wget.exe"
