KASPERSKY ONLINE SCANNER REPORT
Thursday, May 31, 2007 8:56:22 PM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 31/05/2007
Kaspersky Anti-Virus database records: 334594
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 45731
Number of viruses found: 21
Number of infected objects: 45
Number of suspicious objects: 31
Duration of the scan process: 01:57:20
Infected Object Name / Virus Name / Last Action
C:\!KillBox\__c00C9AF9.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\!KillBox\__c00C9AF9.dat( 1) Suspicious: Packed.Win32.Morphine.a skipped
C:\!KillBox\__c00C9AF9.dat( 2) Suspicious: Packed.Win32.Morphine.a skipped
C:\!KillBox\__c00C9AF9.dat( 3) Suspicious: Packed.Win32.Morphine.a skipped
C:\!KillBox\__c00C9AF9.dat( 4) Suspicious: Packed.Win32.Morphine.a skipped
C:\avenger\backup.zip/avenger/__c00C9AF9.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\avenger\backup.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Default User\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Default User\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Desktop\update.exe/EXE-file Suspicious: Packed.Win32.Morphine.a skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Desktop\update.exe Embedded EXE: suspicious - 1 skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Desktop\update.exe.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\ApplicationHistory\hpqimzone.exe.3204510e.ini.inuse Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.cdx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.dbf Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\Identities\{7403742A-09EB-49E3-AF81-0206CFDB60A1}\Microsoft\Outlook Express\cleanup.log Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\Identities\{7403742A-09EB-49E3-AF81-0206CFDB60A1}\Microsoft\Outlook Express\Folders.dbx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\Identities\{7403742A-09EB-49E3-AF81-0206CFDB60A1}\Microsoft\Outlook Express\Inbox.dbx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\Identities\{7403742A-09EB-49E3-AF81-0206CFDB60A1}\Microsoft\Outlook Express\Offline.dbx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\Identities\{7403742A-09EB-49E3-AF81-0206CFDB60A1}\Microsoft\Outlook Express\Pop3uidl.dbx Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\Identities\{B16B7DC4-0412-45A2-9627-F28DF0E69755}\Microsoft\Outlook Express\EZ Anti-Spam.dbx/[From Volksbanken Raiffeisenbanken AG][Date Sat, 02 Sep 2006 06:37:34 -0400 (EDT)]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.od skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\Identities\{B16B7DC4-0412-45A2-9627-F28DF0E69755}\Microsoft\Outlook Express\EZ Anti-Spam.dbx/[From Volksbanken Raiffeisenbanken AG][Date Sat, 02 Sep 2006 06:37:34 -0400 (EDT)]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.od skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\Identities\{B16B7DC4-0412-45A2-9627-F28DF0E69755}\Microsoft\Outlook Express\EZ Anti-Spam.dbx Mail MS Outlook 5: infected - 2 skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Application Data\QurbOE\MsgInfo.dat Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\History\History.IE5\MSHist012007053020070531\index.dat Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Temp\~DFB6A9.tmp Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Temp\~DFCBFF.tmp Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\TRANTGP.GPTNOTEBOOK\NTUSER.DAT.LOG Object is locked skipped
C:\Program Files\Common Files\Companion Wizard\WapCHK.dll Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\QooBox\Quarantine\C\WINNT\b122.exe.vir/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\QooBox\Quarantine\C\WINNT\b122.exe.vir/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\QooBox\Quarantine\C\WINNT\b122.exe.vir NSIS: infected - 2 skipped
C:\QooBox\Quarantine\C\WINNT\retadpu1000106.exe.vir Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\QooBox\Quarantine\C\WINNT\retadpu2000219.exe.vir Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\QooBox\Quarantine\C\WINNT\system32\ddcyv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\QooBox\Quarantine\C\WINNT\system32\dikstldr.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINNT\system32\dwckcacl.dll.vir Infected: Trojan.Win32.BH

skipped
C:\QooBox\Quarantine\C\WINNT\system32\iiihe.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\QooBox\Quarantine\C\WINNT\system32\leiancrv.dll.vir Infected: Trojan.Win32.BH

skipped
C:\QooBox\Quarantine\C\WINNT\system32\smpi1\lb66.exe.vir/unknown2.bin Infected: not-a-virus:AdWare.Win32.Ucmore.e skipped
C:\QooBox\Quarantine\C\WINNT\system32\smpi1\lb66.exe.vir/UCMTSAIE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore.a skipped
C:\QooBox\Quarantine\C\WINNT\system32\smpi1\lb66.exe.vir/IUCMORE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore skipped
C:\QooBox\Quarantine\C\WINNT\system32\smpi1\lb66.exe.vir ZIP: infected - 3 skipped
C:\QooBox\Quarantine\C\WINNT\system32\smpi1\lb66.exe.vir WiseSFX Dropper: infected - 3 skipped
C:\QooBox\Quarantine\C\WINNT\system32\smpi1\lib06.exe.vir Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\QooBox\Quarantine\C\WINNT\system32\smpi1\lib67.exe.vir Infected: Trojan.Win32.BHO.ab skipped
C:\QooBox\Quarantine\C\WINNT\system32\tuvtrol.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\WINNT\system32\uqmryanc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.kb skipped
C:\QooBox\Quarantine\C\WINNT\system32\ydjfmydl.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINNT\VTTC.exe.vir/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\QooBox\Quarantine\C\WINNT\VTTC.exe.vir NSIS: infected - 1 skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc1 Suspicious: Packed.Win32.Morphine.a skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc11.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc12 Suspicious: Packed.Win32.Morphine.a skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc13 Suspicious: Packed.Win32.Morphine.a skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc14 Suspicious: Packed.Win32.Morphine.a skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc15.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc16 Suspicious: Packed.Win32.Morphine.a skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc2 Suspicious: Packed.Win32.Morphine.a skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc3 Suspicious: Packed.Win32.Morphine.a skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc4.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc5 Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc6 Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc7 Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc8.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\RECYCLER\S-1-5-21-1652376794-1690639982-1337592118-1002\Dc9 Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\TTC.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\VundoFix Backups\csvpfhxg.dll.bad Object is locked skipped
C:\VundoFix Backups\ddcyv.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\VundoFix Backups\leiancrv.dll.bad Infected: Trojan.Win32.BH

skipped
C:\VundoFix Backups\musuloyk.dll.bad Infected: Trojan.Win32.BHO.g skipped
C:\VundoFix Backups\nnnli.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\VundoFix Backups\pjcmhmeo.dll.bad Object is locked skipped
C:\VundoFix Backups\qomjk.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\VundoFix Backups\rqroo.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\VundoFix Backups\tuvtrol.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\vwqnffih.dll.bad Infected: Trojan.Win32.BHO.g skipped
C:\VundoFix Backups\ydwfcnnu.dll.bad Object is locked skipped
C:\WINNT\Cache32\Business Card Designer Plus 7.9.exe Suspicious: Type_Win32 skipped
C:\WINNT\Cache32\C&C Generals_crack.exe Suspicious: Type_Win32 skipped
C:\WINNT\Cache32\GetRight 5.0a.exe Suspicious: Type_Win32 skipped
C:\WINNT\Cache32\Hot Babes XXX Screen Saver.exe Suspicious: Type_Win32 skipped
C:\WINNT\Cache32\IrfanView 4.5.exe Suspicious: Type_Win32 skipped
C:\WINNT\Cache32\Network Cable e ADSL Speed 2.0.5.exe Suspicious: Type_Win32 skipped
C:\WINNT\Cache32\TweakAll 3.8.exe Suspicious: Type_Win32 skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Downloaded Program Files\SbCIe026.dll Infected: not-a-virus:AdWare.Win32.SideStep.c skipped
C:\WINNT\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe Infected: not-a-virus

ownloader.Win32.WinFixer.o skipped
C:\WINNT\Drivers\TPP\tppun.exe Suspicious: Type_Win32 skipped
C:\WINNT\Internet Logs\BLACKDELL.ldb Object is locked skipped
C:\WINNT\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINNT\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINNT\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINNT\Internet Logs\tvDebug.log Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\Sti_Trace.log Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\system32\SBO\SB1065.exe Infected: Trojan-Downloader.Win32.VB.fn skipped
C:\WINNT\Temp\ZLT01175.TMP Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
C:\WINNT\yc.exe/EXE-file Suspicious: Packed.Win32.Morphine.a skipped
C:\WINNT\yc.exe Embedded EXE: suspicious - 1 skipped
C:\WINNT\yc.exe.dat Suspicious: Packed.Win32.Morphine.a skipped
D:\Program Files\KaZaA Lite\TopSearch.dll Infected: not-a-virus:AdWare.Win32.Altnet.o skipped
D:\Program Files\ShareMonkey\unins000.exe Suspicious: Type_Win32 skipped
Scan process completed.