Seems to be a lot more in there then we thought. Any way to clear these without reformatting?
Thanks,
-Tboz
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2007-08-07 16:48
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 7/08/2007
Kaspersky Anti-Virus database records: 353504
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
G:\
Scan Statistics:
Total number of scanned objects: 131121
Number of viruses found: 32
Number of infected objects: 182
Number of suspicious objects: 28
Duration of the scan process: 03:16:53
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Desktop\catchme.zip/ldcore.dll Infected: Trojan-Downloader.Win32.Small.dxm skipped
C:\Documents and Settings\Administrator\Desktop\catchme.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\bot924B.tmp Infected: Trojan-Proxy.Win32.Xorpix.be skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\bot9B0B.tmp Infected: Trojan-Proxy.Win32.Xorpix.be skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\~tmp143 Infected: Trojan-Clicker.Win32.Agent.jp skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temp\bot97C5.tmp Infected: Trojan-Proxy.Win32.Xorpix.be skipped
C:\Documents and Settings\NetworkService\Local Settings\Temp\bot9A20.tmp Infected: Trojan-Proxy.Win32.Xorpix.be skipped
C:\Documents and Settings\NetworkService\Local Settings\Temp\~tmp143 Infected: Trojan-Clicker.Win32.Agent.jp skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\SaraS\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
ckrause@greatermadisonchamber.com][Date Wed, 2 Jun 2004 01:15:24 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
ckrause@greatermadisonchamber.com][Date Wed, 2 Jun 2004 01:15:24 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
ckrause@greatermadisonchamber.com][Date Wed, 2 Jun 2004 01:15:24 -0500]/message.scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
tcandibar@newman.newman-grt.oscar.aol.com][Date Wed, 2 Jun 2004 16:37:04 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
tcandibar@newman.newman-grt.oscar.aol.com][Date Wed, 2 Jun 2004 16:37:04 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
tcandibar@newman.newman-grt.oscar.aol.com][Date Wed, 2 Jun 2004 16:37:04 -0500]/message.scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
charitykirchberg@hotmail.com][Date Wed, 2 Jun 2004 16:46:03 -0500]/UNNAMED/message.zip/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
charitykirchberg@hotmail.com][Date Wed, 2 Jun 2004 16:46:03 -0500]/UNNAMED/message.zip Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
charitykirchberg@hotmail.com][Date Wed, 2 Jun 2004 16:46:03 -0500]/UNNAMED Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
friend@provide.net][Date Wed, 2 Jun 2004 00:32:19 -0500]/UNNAMED/your_document.doc.pif Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
friend@provide.net][Date Wed, 2 Jun 2004 00:32:19 -0500]/UNNAMED Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
ramcgarry@ebnet.org][Date Tue, 1 Jun 2004 19:08:56 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
ramcgarry@ebnet.org][Date Tue, 1 Jun 2004 19:08:56 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
ramcgarry@ebnet.org][Date Tue, 1 Jun 2004 19:08:56 -0500]/message.scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
geoff@roseandcrown.com.au][Date Tue, 1 Jun 2004 19:10:48 -0500]/UNNAMED/attach_sassysls.zip/document.txt .exe Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
geoff@roseandcrown.com.au][Date Tue, 1 Jun 2004 19:10:48 -0500]/UNNAMED/attach_sassysls.zip Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
geoff@roseandcrown.com.au][Date Tue, 1 Jun 2004 19:10:48 -0500]/UNNAMED Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
jdunnum@chorus.net][Date Mon, 31 May 2004 15:13:26 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
jdunnum@chorus.net][Date Mon, 31 May 2004 15:13:26 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
jdunnum@chorus.net][Date Mon, 31 May 2004 15:13:26 -0500]/message.scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
mailadmin@projectcashmail.com][Date Mon, 31 May 2004 19:13:51 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
mailadmin@projectcashmail.com][Date Mon, 31 May 2004 19:13:51 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
mailadmin@projectcashmail.com][Date Mon, 31 May 2004 19:13:51 -0500]/message.scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
opercentangel5868@hotmail.com][Date Mon, 31 May 2004 20:56:24 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
opercentangel5868@hotmail.com][Date Mon, 31 May 2004 20:56:24 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
opercentangel5868@hotmail.com][Date Mon, 31 May 2004 20:56:24 -0500]/message.scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
bmkrbachhuber@aol.com][Date Mon, 31 May 2004 22:29:18 -0500]/UNNAMED/details.zip/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
bmkrbachhuber@aol.com][Date Mon, 31 May 2004 22:29:18 -0500]/UNNAMED/details.zip Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
bmkrbachhuber@aol.com][Date Mon, 31 May 2004 22:29:18 -0500]/UNNAMED Infected: Email-Worm.Win32.NetSky.q skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From Joseph Emerson <jcemerson@uspower.net>][Date Sun, 20 Jun 2004 22:08:31 -0400 (EDT)]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From Joseph Emerson <jcemerson@uspower.net>][Date Sun, 20 Jun 2004 22:08:31 -0400 (EDT)]/UNNAMED/astrolistfinala.txt.exe Infected: Email-Worm.Win32.Tanatos.b skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From Joseph Emerson <jcemerson@uspower.net>][Date Sun, 20 Jun 2004 22:08:31 -0400 (EDT)]/UNNAMED Infected: Email-Worm.Win32.Tanatos.b skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
1058383340336@mailserver2.iexpect.com][Date Sat, 12 Jun 2004 14:44:40 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
1058383340336@mailserver2.iexpect.com][Date Sat, 12 Jun 2004 14:44:40 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
ome118883@vtarget.com][Date Sat, 12 Jun 2004 23:20:38 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
ome118883@vtarget.com][Date Sat, 12 Jun 2004 23:20:38 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
jschemb@optonline.net][Date Thu, 10 Jun 2004 13:05:30 -0500]/UNNAMED/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
jschemb@optonline.net][Date Thu, 10 Jun 2004 13:05:30 -0500]/UNNAMED/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\SaraS\Local Settings\Application Data\Identities\{88D752F8-A13E-4CFD-98FA-A4F6E011A4A7}\Microsoft\Outlook Express\Deleted Items.dbx/[From
jschemb@optonline.net][Date Thu, 10 Jun 2004 13:05:30 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped