KASPERSKY ONLINE SCANNER REPORT
Monday, March 31, 2008 4:55:59 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/03/2008
Kaspersky Anti-Virus database records: 605479
Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
I:\
J:\
N:\
P:\
S:\
U:\
Z:\
Scan Statistics
Total number of scanned objects 253008
Number of viruses found 10
Number of infected objects 24
Number of suspicious objects 8
Duration of the scan process 07:02:22
Infected Object Name Virus Name Last Action
C:\99gcpf.exe Infected: Trojan-Downloader.Win32.Tiny.alr skipped
C:\Documents and Settings\ABrown\Application Data\PreCast\terrapin.xdb Object is locked skipped
C:\Documents and Settings\ABrown\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\ABrown\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\ABrown\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\ABrown\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{89C66A0C-3DAA-4B4D-8FA9-59F06D3CFE35} Object is locked skipped
C:\Documents and Settings\ABrown\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\ABrown\Local Settings\History\History.IE5\MSHist012008033120080401\index.dat Object is locked skipped
C:\Documents and Settings\ABrown\ntuser.dat Object is locked skipped
C:\Documents and Settings\ABrown\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\AccessProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\BufferOverflowProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\EmailOnDeliveryLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-03272008-153837.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_GA125-110321.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_GA125-110321.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/updatetc.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant2.zip/180ax.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant3.zip/sais.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant3.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zango2.zip/zango.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zango2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\f34z2n.exe Infected: Trojan-Downloader.Win32.Tiny.alr skipped
C:\Program Files\lotus\notes\data\as_ABrown.nsf Object is locked skipped
C:\Program Files\lotus\notes\data\bookmark.nsf Object is locked skipped
C:\Program Files\lotus\notes\data\Cache.NDK Object is locked skipped
C:\Program Files\lotus\notes\data\desktop6.ndk Object is locked skipped
C:\Program Files\lotus\notes\data\headline.nsf Object is locked skipped
C:\Program Files\lotus\notes\data\IBM_TECHNICAL_SUPPORT\console.log Object is locked skipped
C:\Program Files\lotus\notes\data\log.nsf Object is locked skipped
C:\Program Files\lotus\notes\data\names.nsf Object is locked skipped
C:\Program Files\lotus\notes\data\perweb.nsf Object is locked skipped
C:\Program Files\Microsoft Office\OFFICE11\STARTUP\PDFMaker.dot Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{EA486083-850A-442C-89A8-CC22CCC15A5A}\RP5\change.log Object is locked skipped
C:\Temp\NAILogs\UpdaterUI_GA125-110321.log Object is locked skipped
C:\Temp\NLPgaa.tmp Object is locked skipped
C:\Temp\NLPhaa.tmp Object is locked skipped
C:\Temp\NLPiaa.tmp Object is locked skipped
C:\Temp\rsyncini.exe Infected: Trojan.Win32.Shutdowner.em skipped
C:\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Temp\~DF5366.tmp Object is locked skipped
C:\Temp\~DF5E25.tmp Object is locked skipped
C:\Temp\~DF632C.tmp Object is locked skipped
C:\Temp\~DFF80E.tmp Object is locked skipped
C:\Temp\~WRF0001.tmp Object is locked skipped
C:\Temp\~WRS0000.tmp Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\dvvid32.exe Object is locked skipped
C:\WINDOWS\pfirewall.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\L98ZGS3E\backsp32[1].exe Infected: not-virus:Hoax.Win32.Renos.bhz skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\sbwltbxa.exe Infected: not-virus:Hoax.Win32.Renos.bhz skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
I:\IRMS5\DB\DBAE.ldb Object is locked skipped
I:\IRMS5\DB\DBAE.mdb Object is locked skipped
I:\IRMS5\DB\DbData.ldb Object is locked skipped
I:\IRMS5\DB\DbData.mdb Object is locked skipped
I:\IRMS5\DB\DbReqs.ldb Object is locked skipped
I:\IRMS5\DB\DbReqs.mdb Object is locked skipped
J:\PHSG\Exit Info\Turnover\2008 Turnover Analysis - SOS.xls Object is locked skipped
S:\ARCHIVE (Master)\Past Employee User Folders\Deana\I T\Profiles\jcarozza\My Documents\PST folders\CHARPER.PST/Personal Folders/Inbox/22 Nov 2001 06:28 from
CECEAug2@aol.com
no subject)/message.ZIP/MI48244.txt/[Date Sat, 17 Nov 2001 22:28:32 -0800]/START.EXE Infected: Email-Worm.Win32.Magistr.a skipped
S:\ARCHIVE (Master)\Past Employee User Folders\Deana\I T\Profiles\jcarozza\My Documents\PST folders\CHARPER.PST/Personal Folders/Inbox/22 Nov 2001 06:28 from
CECEAug2@aol.com
no subject)/message.ZIP/MI48244.txt Infected: Email-Worm.Win32.Magistr.a skipped
S:\ARCHIVE (Master)\Past Employee User Folders\Deana\I T\Profiles\jcarozza\My Documents\PST folders\CHARPER.PST/Personal Folders/Inbox/22 Nov 2001 06:28 from
CECEAug2@aol.com
no subject)/message.ZIP Infected: Email-Worm.Win32.Magistr.a skipped
S:\ARCHIVE (Master)\Past Employee User Folders\Deana\I T\Profiles\jcarozza\My Documents\PST folders\CHARPER.PST Mail MS Mail: infected - 3 skipped
S:\ARCHIVE (Master)\Past Employee User Folders\Deana\I T\Profiles\jcarozza\My Documents\PST folders\DTEPSIC.PST/Personal Folders/Deleted Items/05 Jul 2001 17:09 to 'auntdean@hotmail.com':FW: July Newsletter .rtf Infected: Email-Worm.VBS.KakWorm skipped
S:\ARCHIVE (Master)\Past Employee User Folders\Deana\I T\Profiles\jcarozza\My Documents\PST folders\DTEPSIC.PST/Personal Folders/Deleted Items/05 Jul 2001 16:27 to 'Hackler':RE: .rtf Infected: Email-Worm.VBS.KakWorm skipped
S:\ARCHIVE (Master)\Past Employee User Folders\Deana\I T\Profiles\jcarozza\My Documents\PST folders\DTEPSIC.PST/Personal Folders/Inbox/MSLs/American Red Cross/06 Jul 2000 20:15 from Lowry, Scott:Metric Schmetric!!!!/Lowry Metric June 2000 Infected: Virus.MSOffice.Triplicate.c skipped
S:\ARCHIVE (Master)\Past Employee User Folders\Deana\I T\Profiles\jcarozza\My Documents\PST folders\DTEPSIC.PST/Personal Folders/Inbox/MSLs/American Red Cross/08 Jun 2000 17:53 from Lowry, Scott:RE: Metric from Lowry/Metric West 5 2000 Infected: Virus.MSOffice.Triplicate.c skipped
S:\ARCHIVE (Master)\Past Employee User Folders\Deana\I T\Profiles\jcarozza\My Documents\PST folders\DTEPSIC.PST/Personal Folders/Inbox/MSLs/American Red Cross/09 May 2000 17:12 from Lowry, Scott:Bi weekly report + Metric/Metric lowry 4 00 Infected: Virus.MSOffice.Triplicate.c skipped
S:\ARCHIVE (Master)\Past Employee User Folders\Deana\I T\Profiles\jcarozza\My Documents\PST folders\DTEPSIC.PST/Personal Folders/Inbox/MSLs/Resumes/Recruiters, etc./30 Oct 2000 14:07 from Matt Scully

harmacy Today.rtf Infected: Email-Worm.VBS.KakWorm skipped
S:\ARCHIVE (Master)\Past Employee User Folders\Deana\I T\Profiles\jcarozza\My Documents\PST folders\DTEPSIC.PST Mail MS Mail: infected - 6 skipped
S:\ARCHIVE (Master)\Proposal templates\LCM Proposal.doc Object is locked skipped
S:\ARCHIVE (Master)\Proposal templates\Med Svcs PSA Template.doc Object is locked skipped
S:\ARCHIVE (Master)\Proposal templates\MSL Proposal.doc Object is locked skipped
S:\ARCHIVE (Master)\Proposal templates\MSL Training Program Proposal.doc Object is locked skipped
S:\ARCHIVE (Master)\SOS Capabilities.pps Object is locked skipped
S:\BUSINESS DEVELOPMENT (Master)\FORMS\FORM profile.ppt Object is locked skipped
S:\IT (Master)\backup\Evan\Backup-(2006-02-23).ipd Object is locked skipped
S:\IT (Master)\backup\Jason\Marlon\Oct182006.bkf/\az.exe Infected: IM-Worm.Win32.Kelvir.al skipped
S:\IT (Master)\backup\Jason\Marlon\Oct182006.bkf/\ce1pt.exe Infected: IM-Worm.Win32.Kelvir.al skipped
S:\IT (Master)\backup\Jason\Marlon\Oct182006.bkf/\cept.exe Infected: IM-Worm.Win32.Kelvir.al skipped
S:\IT (Master)\backup\Jason\Marlon\Oct182006.bkf/\dnx.exe Infected: IM-Worm.Win32.Kelvir.al skipped
S:\IT (Master)\backup\Jason\Marlon\Oct182006.bkf/\fdld.exe Infected: IM-Worm.Win32.Kelvir.al skipped
S:\IT (Master)\backup\Jason\Marlon\Oct182006.bkf/\ldfl.exe Infected: IM-Worm.Win32.Kelvir.ab skipped
S:\IT (Master)\backup\Jason\Marlon\Oct182006.bkf/\rofl.exe Infected: IM-Worm.Win32.Kelvir.az skipped
S:\IT (Master)\backup\Jason\Marlon\Oct182006.bkf MTF: infected - 7 skipped
S:\IT (Master)\backup\restore\Egwu\EgwuBackup-(2006-05-25).ipd Object is locked skipped
S:\IT (Master)\backups\RMurphy\My Documents\LimeWire\.NetworkShare\LimeWirePackedJars4.10.9.7z Object is locked skipped
S:\IT (Master)\backups\RMurphy\My Documents\LimeWire\.NetworkShare\LimeWireWin4.10.9.exe Object is locked skipped
S:\IT (Master)\backups\RMurphy\My Documents\LimeWire\LimeWire On Startup.lnk Object is locked skipped
S:\IT (Master)\backups\RMurphy\My Documents\LimeWire\LimeWire.exe Object is locked skipped
S:\IT (Master)\backups\RMurphy\My Documents\LimeWire\LimeWire.ico Object is locked skipped
S:\IT (Master)\backups\RMurphy\My Documents\LimeWire\LimeWire.jar Object is locked skipped
S:\IT (Master)\backups\RMurphy\My Documents\LimeWire\LimeWire20.dll Object is locked skipped
S:\IT (Master)\backups\RMurphy\My Documents\LimeWire\root\magnet10\limewire.gif Object is locked skipped