Kapersky.20080625.1614.txt
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2008-06-25 16:13
Operating System: Microsoft Windows XP Professional, Service Pack 3 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 23/06/2008
Kaspersky Anti-Virus database records: 881045
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
H:\
Z:\
Scan Statistics:
Total number of scanned objects: 369411
Number of viruses found: 28
Number of infected objects: 138
Number of suspicious objects: 76
Duration of the scan process: 20:14:21
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Documents\PAULD99\spoofmail.src.txt/[From
aw-confirm@ebay.com][Date Thu, 27 May 2004 23:31:39 -0600]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\All Users\Documents\PAULD99\spoofmail.src.txt Mail: suspicious - 1 skipped
C:\Documents and Settings\All Users\Documents\PAULD99\_Urgent Fraud Prevention Group Notice_.eml/[From
aw-confirm@ebay.com][Date Thu, 27 May 2004 23:31:39 -0600]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\All Users\Documents\PAULD99\_Urgent Fraud Prevention Group Notice_.eml Mail: suspicious - 1 skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\pauld99\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\pauld99\Favorites\Compaq Recommended Sites\AltaVista Live.URL Object is locked skipped
C:\Documents and Settings\pauld99\Favorites\Compaq Recommended Sites\AltaVista Search.URL Object is locked skipped
C:\Documents and Settings\pauld99\Favorites\Compaq Recommended Sites\AltaVista.URL Object is locked skipped
C:\Documents and Settings\pauld99\Favorites\Compaq Recommended Sites\Business Community.URL Object is locked skipped
C:\Documents and Settings\pauld99\Favorites\Compaq Recommended Sites\Compaq.URL Object is locked skipped
C:\Documents and Settings\pauld99\Favorites\Compaq Recommended Sites\eCommerce.URL Object is locked skipped
C:\Documents and Settings\pauld99\Local Settings\Application Data\Identities\{EED02091-47AD-4EDD-A0AA-0B2D9D1B9B0F}\Microsoft\Outlook Express\andtatt71@hotmail.com - Deleted Items.dbx/[From increase-si'ze <Brokenheart40@yahoo.com.mx>][Date Tue, 28 Mar 2006 17:15:15 -0800 (EST)]/Brokenheart40_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\pauld99\Local Settings\Application Data\Identities\{EED02091-47AD-4EDD-A0AA-0B2D9D1B9B0F}\Microsoft\Outlook Express\andtatt71@hotmail.com - Deleted Items.dbx MailMSOutlook5: infected - 1 skipped
C:\Documents and Settings\pauld99\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\pauld99\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\pauld99\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\pauld99\Local Settings\History\History.IE5\MSHist012008062420080625\index.dat Object is locked skipped
C:\Documents and Settings\pauld99\Local Settings\Temp\hsperfdata_pauld99\3052 Object is locked skipped
C:\Documents and Settings\pauld99\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\pauld99\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\pauld99\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\pauld99\ntuser.dat.LOG Object is locked skipped
C:\ipsec.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{B22743D3-F062-426E-B1F6-9338BC116202}\RP461\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Personal Folders/Inbox/eBay/Disputes/01 Jun 2004 14:53 from eBay Customer Support:RE: SP91011 - Your .eml/[From "paul aerison" <paulaerison@hotmail.com>][Date tue, 1 jun 2004 08:39:11 -0600]/spoofmail.src.txt/[From
aw-confirm@ebay.com][Date thu, 27 may 2004 23:31:39 -0600]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Personal Folders/Inbox/eBay/Disputes/01 Jun 2004 14:53 from eBay Customer Support:RE: SP91011 - Your .eml/[From "paul aerison" <paulaerison@hotmail.com>][Date tue, 1 jun 2004 08:39:11 -0600]/spoofmail.src.txt Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Personal Folders/Inbox/eBay/Disputes/01 Jun 2004 14:53 from eBay Customer Support:RE: SP91011 - Your .eml/[From "paul aerison" <paulaerison@hotmail.com>][Date tue, 1 jun 2004 08:39:11 -0600]/_urgent/[From from 8bit to quoted-printable by][Date thu, 27 may 2004 23:31:39 -0600]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Personal Folders/Inbox/eBay/Disputes/01 Jun 2004 14:53 from eBay Customer Support:RE: SP91011 - Your .eml/[From "paul aerison" <paulaerison@hotmail.com>][Date tue, 1 jun 2004 08:39:11 -0600]/_urgent Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Personal Folders/Inbox/eBay/Disputes/01 Jun 2004 14:53 from eBay Customer Support:RE: SP91011 - Your .eml Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Personal Folders/Inbox/STUFF/24 Mar 2004 02:14 to
paulaerison@hotmail.com:Returned mail: see /24 Mar 2004 02:17 from
paulaerison@hotmail.com:Mail Delivery (fa.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Personal Folders/Inbox/STUFF/24 Mar 2004 02:14 to
paulaerison@hotmail.com:Returned mail: see /24 Mar 2004 02:17 from
paulaerison@hotmail.com:Mail Delivery (fa/message.scr Infected: Email-Worm.Win32.NetSky.q skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Personal Folders/Inbox/STUFF/24 Mar 2004 02:14 to
paulaerison@hotmail.com:Returned mail: see /24 Mar 2004 02:17 from
paulaerison@hotmail.com:Mail Delivery (fa.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Personal Folders/Inbox/STUFF/24 Mar 2004 02:14 to
paulaerison@hotmail.com:Returned mail: see /24 Mar 2004 02:17 from
paulaerison@hotmail.com:Mail Delivery (fa/message.scr Infected: Email-Worm.Win32.NetSky.q skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Personal Folders/Sent Items/20 Jul 2006 19:53 from Paul Aerison:Fw: *Urgent Fraud Prevention/spoofmail.src.txt/[From
aw-confirm@ebay.com][Date Thu, 27 May 2004 23:31:39 -0600]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Personal Folders/Sent Items/20 Jul 2006 19:53 from Paul Aerison:Fw: *Urgent Fraud Prevention/spoofmail.src.txt Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Personal Folders/Sent Items/20 Jul 2006 19:53 from Paul Aerison:Fw: *Urgent Fraud Prevention/28 May 2004 04:31 to
paulaerison@hotmail.com:*Urgent Fraud Preve.html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\BABS\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst MailMSMaill: infected - 2, suspicious - 10 skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\Archive.pst/Archive Folders/Sent Items/11 Feb 2002 19:10 to 'cwaite@sdcr.com':radman/radmin20.zip/RADMIN20.EXE/R_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\Archive.pst/Archive Folders/Sent Items/11 Feb 2002 19:10 to 'cwaite@sdcr.com':radman/radmin20.zip/RADMIN20.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\Archive.pst/Archive Folders/Sent Items/11 Feb 2002 19:10 to 'cwaite@sdcr.com':radman/radmin20.zip/RADMIN20.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\Archive.pst/Archive Folders/Sent Items/11 Feb 2002 19:10 to 'cwaite@sdcr.com':radman/radmin20.zip/RADMIN20.EXE/Radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\Archive.pst/Archive Folders/Sent Items/11 Feb 2002 19:10 to 'cwaite@sdcr.com':radman/radmin20.zip/RADMIN20.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\Archive.pst/Archive Folders/Sent Items/11 Feb 2002 19:10 to 'cwaite@sdcr.com':radman/radmin20.zip Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\Archive.pst MailMSMaill: infected - 6 skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/13 May 2002 14:39 from info:952.933.3188.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/14 May 2002 17:41 from info:Re:look,my beautiful girl friend.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/14 May 2002 21:42 from rickd:952.933.3188.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/22 May 2002 15:19 from bob:Language.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/22 May 2002 19:54 from generaldating:Learn more about how we use.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/23 May 2002 20:21 from joon-bj:CNET Networks, Inc. All rights re.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/25 May 2002 03:27 from Lewis:Welcome to my hometown.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/26 May 2002 16:14 from ADDRphishnbs:ONMOUSEOUT.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/27 May 2002 17:28 from welcome:VULGAR TEENS.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/28 May 2002 11:32 from sales:TARGET.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/28 May 2002 14:04 from info:A powful tool.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/29 May 2002 02:35 from mail

on't drink too much.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/29 May 2002 18:39 from scarlett747:ACCESSKEY.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/29 May 2002 21:55 from Mail Delivery Subsystem:Returned mail: se/29 May 2002 21:51 from sales:Marginwidth.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/30 May 2002 03:18 from kmullall

arent.frames.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/30 May 2002 15:45 from daryl:Background.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/30 May 2002 21:33 from Mbright13:So cool a flash,enjoy it.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/31 May 2002 02:21 from EYIWatchDogAP:Height.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/31 May 2002 14:12 from yamelis:Hi,sales,let's be friends.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/31 May 2002 17:01 from can:Welcome to my hometown.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/01 Jun 2002 08:08 from YogaStore:A funny website.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/02 Jun 2002 02:27 from bto4:Let's be friends.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/02 Jun 2002 21:06 from Cyberdetective:Fw:the Garden of Eden.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/03 Jun 2002 02:54 from help:Welcome to my hometown.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/03 Jun 2002 22:47 from name:A good tool.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/04 Jun 2002 03:26 from bVen:A special powful tool.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/05 Jun 2002 02:58 from Munich:34, 291, 99.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/07 Jun 2002 02:40 from 20Prahlada:Honey.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/08 Jun 2002 12:02 from geography:Button to see the latest versio.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/10 Jun 2002 18:57 from xanajdu:Fw:sales,questionnaire.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/11 Jun 2002 16:44 from sales:CELLPADDING.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/11 Jun 2002 18:50 from BobCarlson:Meeting notice.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/12 Jun 2002 03:39 from LA-news:A new website.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/12 Jun 2002 15:49 from sjtincat1:Tabindex.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/13 Jun 2002 00:16 from kfa01:Happy Lady Day.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/13 Jun 2002 01:02 from askus:Navigator.userAgent.indexOf(.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Deleted Items/13 Jun 2002 05:16 from melaniemccormack:A WinXP patch.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Sent Items/29 Apr 2002 15:04 to 'westmarine':RE: Arrow and select a languag.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Sent Items/06 May 2002 14:20 to Paul Dinwiddio (pauld99@ncrscomplete.com):F.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Sent Items/06 May 2002 14:20 to Paul Dinwiddio (pauld99@ncrscomplete.com):F/05 May 2002 20:34 from Karina94:952.933.3188.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Sent Items/22 May 2002 15:40 to 'bob':RE: Language.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst/Personal Folders/Sent Items/30 May 2002 15:42 to 'daryl':RE: Background.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\Drive E\users\arte21\My Documents\mail\personal.pst MailMSMaill: suspicious - 42 skipped
Z:\BACKUPS\Drive E\users\davee94\Arts Portable.zip/NCRS_S.8.02.0033/NCRS-Pro 8.02.0033 source and support/radmin20.zip/RADMIN20.EXE/R_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\Drive E\users\davee94\Arts Portable.zip/NCRS_S.8.02.0033/NCRS-Pro 8.02.0033 source and support/radmin20.zip/RADMIN20.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\Drive E\users\davee94\Arts Portable.zip/NCRS_S.8.02.0033/NCRS-Pro 8.02.0033 source and support/radmin20.zip/RADMIN20.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\Drive E\users\davee94\Arts Portable.zip/NCRS_S.8.02.0033/NCRS-Pro 8.02.0033 source and support/radmin20.zip/RADMIN20.EXE/Radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\Drive E\users\davee94\Arts Portable.zip/NCRS_S.8.02.0033/NCRS-Pro 8.02.0033 source and support/radmin20.zip/RADMIN20.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\Drive E\users\davee94\Arts Portable.zip/NCRS_S.8.02.0033/NCRS-Pro 8.02.0033 source and support/radmin20.zip Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\Drive E\users\davee94\Arts Portable.zip ZIP: infected - 6 skipped
Z:\BACKUPS\emallpos\-_downloads\Serv-U_3.1\susetup.exe/SERVUDAEMON.EXE Infected: not-a-virus:Server-FTP.Win32.Serv-U.3103 skipped
Z:\BACKUPS\emallpos\-_downloads\Serv-U_3.1\susetup.exe ZIP: infected - 1 skipped
Z:\BACKUPS\emallpos\-_downloads\ServerSoftware\radmin21 + key.zip/RADMIN21.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\emallpos\-_downloads\ServerSoftware\radmin21 + key.zip/RADMIN21.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\emallpos\-_downloads\ServerSoftware\radmin21 + key.zip/RADMIN21.EXE/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
Z:\BACKUPS\emallpos\-_downloads\ServerSoftware\radmin21 + key.zip/RADMIN21.EXE/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
Z:\BACKUPS\emallpos\-_downloads\ServerSoftware\radmin21 + key.zip/RADMIN21.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
Z:\BACKUPS\emallpos\-_downloads\ServerSoftware\radmin21 + key.zip ZIP: infected - 5 skipped
Z:\BACKUPS\emallpos\-_downloads\ServerSoftware\tightvnc-1.2.6-setup.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
Z:\BACKUPS\emallpos\-_downloads\ServerSoftware\tightvnc-1.2.6-setup.exe Inno: infected - 1 skipped
Z:\BACKUPS\emallpos\-_inetpub\www\
www.thecashdrawer.com\downloads\RADMIN21.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\emallpos\-_inetpub\www\
www.thecashdrawer.com\downloads\RADMIN21.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\emallpos\-_inetpub\www\
www.thecashdrawer.com\downloads\RADMIN21.EXE/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
Z:\BACKUPS\emallpos\-_inetpub\www\
www.thecashdrawer.com\downloads\RADMIN21.EXE/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
Z:\BACKUPS\emallpos\-_inetpub\www\
www.thecashdrawer.com\downloads\RADMIN21.EXE Gentee: infected - 4 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\susetup3.0.0.16.exe/SERVUDAEMON.EXE Infected: not-a-virus:Server-FTP.Win32.Serv-U.3016 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\susetup3.0.0.16.exe ZIP: infected - 1 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\susetup3.0.0.17.exe/SERVUDAEMON.EXE Infected: not-a-virus:Server-FTP.Win32.Serv-U.3017 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\susetup3.0.0.17.exe ZIP: infected - 1 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b12\ServU3b12.zip/Setup.exe/SERVUDAEMON.EXE Infected: not-a-virus:Server-FTP.Win32.Serv-U.gen skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b12\ServU3b12.zip/Setup.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.gen skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b12\ServU3b12.zip ZIP: infected - 2 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b13\ServU3b13.zip/Setup.exe/SERVUDAEMON.EXE Infected: not-a-virus:Server-FTP.Win32.Serv-U.gen skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b13\ServU3b13.zip/Setup.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.gen skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b13\ServU3b13.zip ZIP: infected - 2 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b15\ServU3b15.zip/Setup.exe/SERVUDAEMON.EXE Infected: not-a-virus:Server-FTP.Win32.Serv-U.3015 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b15\ServU3b15.zip/Setup.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.3015 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b15\ServU3b15.zip ZIP: infected - 2 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b9\serv-u (ftpD).zip/Setup.exe/SERV-U32.EXE Infected: not-a-virus:Server-FTP.Win32.Serv-U.25.i skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b9\serv-u (ftpD).zip/Setup.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.25.i skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b9\serv-u (ftpD).zip ZIP: infected - 2 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b9\ServU3b9.zip/Setup.exe/SERVUDAEMON.EXE Infected: not-a-virus:Server-FTP.Win32.Serv-U.30 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b9\ServU3b9.zip/Setup.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.30 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\FTP-SERV-U\v3b9\ServU3b9.zip ZIP: infected - 2 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\radmin20.zip/RADMIN20.EXE/R_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\radmin20.zip/RADMIN20.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\radmin20.zip/RADMIN20.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\radmin20.zip/RADMIN20.EXE/Radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\radmin20.zip/RADMIN20.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\radmin20.zip ZIP: infected - 5 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\radmin21.zip/RADMIN21.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\radmin21.zip/RADMIN21.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\radmin21.zip/RADMIN21.EXE/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\radmin21.zip/RADMIN21.EXE/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\radmin21.zip/RADMIN21.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\radmin21.zip ZIP: infected - 5 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\serv-u.ace/serv-u\ServUDaemon.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.30 skipped
Z:\BACKUPS\inetpub.bak\shared\ServerSoftware\serv-u.ace ACE: infected - 1 skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace/Documents and Settings\ADMINISTRATOR.NCRSCOMPLETE\Local Settings\Temp\RADMIN20.EXE/R_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace/Documents and Settings\ADMINISTRATOR.NCRSCOMPLETE\Local Settings\Temp\RADMIN20.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace/Documents and Settings\ADMINISTRATOR.NCRSCOMPLETE\Local Settings\Temp\RADMIN20.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace/Documents and Settings\ADMINISTRATOR.NCRSCOMPLETE\Local Settings\Temp\RADMIN20.EXE/Radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace/Documents and Settings\ADMINISTRATOR.NCRSCOMPLETE\Local Settings\Temp\RADMIN20.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace/Documents and Settings\ADMINISTRATOR.NCRSCOMPLETE\Local Settings\Temporary Internet Files\Content.IE5\KTATWL67\excursion[1].zip/Excursion/Excursion9.2.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.601 skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace/Documents and Settings\ADMINISTRATOR.NCRSCOMPLETE\Local Settings\Temporary Internet Files\Content.IE5\KTATWL67\excursion[1].zip/Excursion/Addons/Nukenabber/protec.exe Infected: not-a-virus:NetTool.Win32.NukeNabber.21 skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace/Documents and Settings\ADMINISTRATOR.NCRSCOMPLETE\Local Settings\Temporary Internet Files\Content.IE5\KTATWL67\excursion[1].zip Infected: not-a-virus:NetTool.Win32.NukeNabber.21 skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace/Documents and Settings\ADMINISTRATOR.NCRSCOMPLETE\Local Settings\Temporary Internet Files\Content.IE5\4G2UJTNP\pc_tkct6[1].zip/TUTOR.EXE Infected: VirTool.Win32.Magazine skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace/Documents and Settings\ADMINISTRATOR.NCRSCOMPLETE\Local Settings\Temporary Internet Files\Content.IE5\4G2UJTNP\pc_tkct6[1].zip Infected: VirTool.Win32.Magazine skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace/Documents and Settings\ADMINISTRATOR.NCRSCOMPLETE\Local Settings\Temporary Internet Files\Content.IE5\4XMZW9U3\TMD.Recruit[1].zip/TMD_Recruit/MIRC32.EXE Infected: not-a-virus:Client-IRC.Win32.mIRC.591 skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace/Documents and Settings\ADMINISTRATOR.NCRSCOMPLETE\Local Settings\Temporary Internet Files\Content.IE5\4XMZW9U3\TMD.Recruit[1].zip Infected: not-a-virus:Client-IRC.Win32.mIRC.591 skipped
Z:\BACKUPS\ncrs\ncrs.MrWarner_Backup.Documents And Settings.ace ACE: infected - 12 skipped
Z:\BACKUPS\pauld99\angelsofwar.org.ace/bigvar\www\angelsofwar.org\files\irc\nnscript352.exe/data0004 Infected: not-a-virus:Client-IRC.Win32.mIRC.601 skipped
Z:\BACKUPS\pauld99\angelsofwar.org.ace/bigvar\www\angelsofwar.org\files\irc\nnscript352.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.601 skipped
Z:\BACKUPS\pauld99\angelsofwar.org.ace ACE: infected - 2 skipped
Z:\BACKUPS\pauld99\fastpush.ace/fastpush\TightVNC2\VNCHooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
Z:\BACKUPS\pauld99\fastpush.ace/fastpush\vnc9\VNCHooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
Z:\BACKUPS\pauld99\fastpush.ace/fastpush\vnc9\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
Z:\BACKUPS\pauld99\fastpush.ace/fastpush\vnc\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
Z:\BACKUPS\pauld99\fastpush.ace/fastpush\vnc9\WinVNC.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
Z:\BACKUPS\pauld99\fastpush.ace/fastpush\vnc\WinVNC.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
Z:\BACKUPS\pauld99\fastpush.ace ACE: infected - 6 skipped
Z:\BACKUPS\pauld99\Program Files.ace/Program Files\Serv-U\ServUDaemon.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.40 skipped
Z:\BACKUPS\pauld99\Program Files.ace ACE: infected - 1 skipped
Z:\BACKUPS\pauld99\techdev1.ace/techdev1\apache\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE/R_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\pauld99\techdev1.ace/techdev1\apache\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\pauld99\techdev1.ace/techdev1\apache\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\pauld99\techdev1.ace/techdev1\apache\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE/Radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\pauld99\techdev1.ace/techdev1\apache\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\pauld99\techdev1.ace/techdev1\apache\htdocs\Downloads\radmin\Radmin.ace Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\pauld99\techdev1.ace ACE: infected - 6 skipped
Z:\BACKUPS\pauld99\techdev1\apache\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE/R_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\pauld99\techdev1\apache\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\pauld99\techdev1\apache\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\pauld99\techdev1\apache\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE/Radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\pauld99\techdev1\apache\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\pauld99\techdev1\apache\htdocs\Downloads\radmin\Radmin.ace ACE: infected - 5 skipped
Z:\BACKUPS\techdev01\apache.techdev.ace/apache.techdev\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE/R_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\techdev01\apache.techdev.ace/apache.techdev\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\techdev01\apache.techdev.ace/apache.techdev\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\techdev01\apache.techdev.ace/apache.techdev\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE/Radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\techdev01\apache.techdev.ace/apache.techdev\htdocs\Downloads\radmin\Radmin.ace/RADMIN20.EXE Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\techdev01\apache.techdev.ace/apache.techdev\htdocs\Downloads\radmin\Radmin.ace Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
Z:\BACKUPS\techdev01\apache.techdev.ace ACE: infected - 6 skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var\var\drweb\infected\drweb.quarantine.TWwXka/[From eBay Inc <custservice_9323895@ebay.com>][Date Fri, 22 Jul 2005 10:59:50 +0500]/html Infected: Trojan-Spy.HTML.Bayfraud.hn skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var\var\drweb\infected\drweb.quarantine.TWwXka Mail: infected - 1 skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/drweb/infected/drweb.quarantine.TWwXka/[From eBay Inc <custservice_9323895@ebay.com>][Date Fri, 22 Jul 2005 10:59:50 +0500]/html Infected: Trojan-Spy.HTML.Bayfraud.hn skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/drweb/infected/drweb.quarantine.TWwXka Infected: Trojan-Spy.HTML.Bayfraud.hn skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816050.M961863P2913V0000000000008215I1F0F012B_/[From mail.vanderhouwen.com [198.107.53.230]][Date Tue, 23 Mar 2004 21:17:26 -0500 (EST)]/UNNAMED/[From
paulaerison@hotmail.com][Date Tue, 23 Mar 2004 18:14:00 -0800]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816050.M961863P2913V0000000000008215I1F0F012B_/[From mail.vanderhouwen.com [198.107.53.230]][Date Tue, 23 Mar 2004 21:17:26 -0500 (EST)]/UNNAMED/[From
paulaerison@hotmail.com][Date Tue, 23 Mar 2004 18:14:00 -0800]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816050.M961863P2913V0000000000008215I1F0F012B_/[From mail.vanderhouwen.com [198.107.53.230]][Date Tue, 23 Mar 2004 21:17:26 -0500 (EST)]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816050.M961863P2913V0000000000008215I1F0F012B_ Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816053.M537901P2913V0000000000008215I1F0F012C_ Suspicious: Exploit.HTML.Iframe.FileDownload skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip/real337/othread2.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip/real337/winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip/realb4/wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip/tight128/VNCHooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip/tight128/winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip/tridia152/WinVNC.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1540 skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip/utils/xCmd.exe Infected: not-a-virus:RemoteAdmin.Win32.RemoteExec skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip/vnc4/winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.403 skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip/vnc4/wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.403 skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip/vnc9/VNCHooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip/vnc9/vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip/vnc9/WinVNC.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_/[From "Paul Aerison" <PAerison@alservices.com>][Date Mon, 8 Dec 2003 16:05:58 -0700]/vnc7.zip Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/cur/1116816114.M392381P2913V0000000000008215I1F0F0169_ Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.Mail.Ebay/cur/1116880654.M337076P20000V00000000000082/[From "paul aerison" <paulaerison@hotmail.com>][Date tue, 1 jun 2004 08:39:11 -0600]/spoofmail.src.txt/[From
aw-confirm@ebay.com][Date thu, 27 may 2004 23:31:39 -0600]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.Mail.Ebay/cur/1116880654.M337076P20000V00000000000082/[From "paul aerison" <paulaerison@hotmail.com>][Date tue, 1 jun 2004 08:39:11 -0600]/spoofmail.src.txt Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.Mail.Ebay/cur/1116880654.M337076P20000V00000000000082/[From "paul aerison" <paulaerison@hotmail.com>][Date tue, 1 jun 2004 08:39:11 -0600]/_urgent/[From from 8bit to quoted-printable by][Date thu, 27 may 2004 23:31:39 -0600]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.Mail.Ebay/cur/1116880654.M337076P20000V00000000000082/[From "paul aerison" <paulaerison@hotmail.com>][Date tue, 1 jun 2004 08:39:11 -0600]/_urgent Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.Mail.Ebay/cur/1116880654.M337076P20000V00000000000082 Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.drafts/cur/1116994138.M181191P14626V0000000000008215I/[From
aw-confirm@ebay.com][Date Thu, 27 May 2004 23:31:39 -0600]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.drafts/cur/1116994138.M181191P14626V0000000000008215I Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.Sent Items-may-2005/cur/1116817059.M474111P8769V00000/[From "Paul Aerison" <paulaerison@hotmail.com>][Date Tue, 1 Jun 2004 08:39:11 -0600]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.Sent Items-may-2005/cur/1116817059.M474111P8769V00000/[From "Paul Aerison" <paulaerison@hotmail.com>][Date Tue, 1 Jun 2004 08:39:11 -0600]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.Sent Items-may-2005/cur/1116817059.M474111P8769V00000/[From "Paul Aerison" <paulaerison@hotmail.com>][Date Tue, 1 Jun 2004 08:39:11 -0600]/spoofmail.src.txt/[From
aw-confirm@ebay.com][Date Thu, 27 May 2004 23:31:39 -0600]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.Sent Items-may-2005/cur/1116817059.M474111P8769V00000/[From "Paul Aerison" <paulaerison@hotmail.com>][Date Tue, 1 Jun 2004 08:39:11 -0600]/spoofmail.src.txt Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.Sent Items-may-2005/cur/1116817059.M474111P8769V00000/[From "Paul Aerison" <paulaerison@hotmail.com>][Date Tue, 1 Jun 2004 08:39:11 -0600]/_Urgent/[From
aw-confirm@ebay.com][Date Thu, 27 May 2004 23:31:39 -0600]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.Sent Items-may-2005/cur/1116817059.M474111P8769V00000/[From "Paul Aerison" <paulaerison@hotmail.com>][Date Tue, 1 Jun 2004 08:39:11 -0600]/_Urgent Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed/var/qmail/mailnames/gwzi.net/pauld99/Maildir/.Sent Items-may-2005/cur/1116817059.M474111P8769V00000 Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz/packed Infected: Trojan-Spy.HTML.Fraud.gen skipped
Z:\BACKUPS\YACKO\backups\vdshm1.gwzi.net\var.tar.gz GZIP: infected - 17, suspicious - 19 skipped
Z:\BACKUPS\YACKO\Program Files\Deerfield.com\DNS2Go\vncsetup.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 skipped
Z:\BACKUPS\YACKO\Program Files\Deerfield.com\DNS2Go\vncsetup.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
Z:\BACKUPS\YACKO\Program Files\Deerfield.com\DNS2Go\vncsetup.exe Inno: infected - 2 skipped
Z:\BACKUPS\YACKO\Program Files\orl\vnc\WinVNC.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
Z:\DOWNLOADS\_INCOMING\[GAME][E-TOOLS]\Wizards of the Coast.ace/Wizards of the Coast\eTools\eTools.exe Infected: Virus.Win32.Parite.b skipped
Z:\DOWNLOADS\_INCOMING\[GAME][E-TOOLS]\Wizards of the Coast.ace ACE: infected - 1 skipped
Z:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Z:\System Volume Information\_restore{B22743D3-F062-426E-B1F6-9338BC116202}\RP462\change.log Object is locked skipped
Scan process completed.