-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Tuesday, September 06, 2005 07:29:46
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 4/09/2005
Kaspersky Anti-Virus database records: 138843
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 81896
Number of viruses found: 10
Number of infected objects: 151
Number of suspicious objects: 7
Duration of the scan process: 8603 sec
Infected Object Name - Virus Name
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/27 Jan 2004 23:09 from [email protected]:Hi/body.pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/27 Jan 2004 21:38 from Mail Delivery System:Mail delivery failed.eml/[From [email protected]][Date Tue, 27 Jan 2004 15:35:39 -0600]/UNNAMED/message.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/27 Jan 2004 21:38 from Mail Delivery System:Mail delivery failed.eml/[From [email protected]][Date Tue, 27 Jan 2004 15:35:39 -0600]/UNNAMED Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/27 Jan 2004 21:38 from Mail Delivery System:Mail delivery failed.eml Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/28 Jan 2004 22:38 from System Administrator:Undeliverable: Hi/28 Jan 2004 22:38 to [email protected]:Hi/file.zip/file.txt .exe Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/28 Jan 2004 22:38 from System Administrator:Undeliverable: Hi/28 Jan 2004 22:38 to [email protected]:Hi/file.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/28 Jan 2004 23:23 from [email protected]:Delivery Stat/28 Jan 2004 23:23 from [email protected]:Test/file.zip/file.txt .exe Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/28 Jan 2004 23:23 from [email protected]:Delivery Stat/28 Jan 2004 23:23 from [email protected]:Test/file.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 11:55 from [email protected]:DELIVE/29 Jan 2004 11:45 from [email protected]/document.zip/document.doc .scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 11:55 from [email protected]:DELIVE/29 Jan 2004 11:45 from [email protected]/document.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 16:22 from Mail Delivery Subsystem:Returned mail: Us/29 Jan 2004 16:20 from [email protected]:JCRMOM/text.zip/text.pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 16:22 from Mail Delivery Subsystem:Returned mail: Us/29 Jan 2004 16:20 from [email protected]:JCRMOM/text.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 22:58 from [email protected]:hello/doc.zip/doc.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 22:58 from [email protected]:hello/doc.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 21:32 from [email protected]:.eml/[From [email protected]][Date Thu, 29 Jan 2004 16:32:44 -0500]/UNNAMED/readme.zip/readme.pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 21:32 from [email protected]:.eml/[From [email protected]][Date Thu, 29 Jan 2004 16:32:44 -0500]/UNNAMED/readme.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 21:32 from [email protected]:.eml/[From [email protected]][Date Thu, 29 Jan 2004 16:32:44 -0500]/UNNAMED Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 21:32 from [email protected]:.eml Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 20:57 from [email protected]:hi/message.zip/message.bat Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 20:57 from [email protected]:hi/message.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/30 Jan 2004 19:01 from [email protected]:atuhlipbige/body.zip/body.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/30 Jan 2004 19:01 from [email protected]:atuhlipbige/body.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/01 Feb 2004 23:15 from Mail Delivery Service:Delivery Status Not/01 Feb 2004 23:10 to [email protected]:Mail Transaction F/readme.zip/readme.exe Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/01 Feb 2004 23:15 from Mail Delivery Service:Delivery Status Not/01 Feb 2004 23:10 to [email protected]:Mail Transaction F/readme.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/01 Feb 2004 23:05 from Mail Delivery Subsystem:Returned mail: se/01 Feb 2004 23:05 from [email protected]:TEST/document.zip/document.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/01 Feb 2004 23:05 from Mail Delivery Subsystem:Returned mail: se/01 Feb 2004 23:05 from [email protected]:TEST/document.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/01 Feb 2004 08:51 from [email protected]:Delivery Status No/01 Feb 2004 08:50 to [email protected]:hi/file.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 06:58 from [email protected]:.eml/[From [email protected]][Date Sat, 31 Jan 2004 01:58:18 -0500]/UNNAMED/readme.zip/readme.txt .scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 06:58 from [email protected]:.eml/[From [email protected]][Date Sat, 31 Jan 2004 01:58:18 -0500]/UNNAMED/readme.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 06:58 from [email protected]:.eml/[From [email protected]][Date Sat, 31 Jan 2004 01:58:18 -0500]/UNNAMED Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 06:58 from [email protected]:.eml Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 03:28 from [email protected]:Status/document.pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 01:38 from Mail Delivery System:Mail delivery failed.eml/[From [email protected]][Date Fri, 30 Jan 2004 20:38:25 -0500]/UNNAMED/body.zip/body.txt .scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 01:38 from Mail Delivery System:Mail delivery failed.eml/[From [email protected]][Date Fri, 30 Jan 2004 20:38:25 -0500]/UNNAMED/body.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 01:38 from Mail Delivery System:Mail delivery failed.eml/[From [email protected]][Date Fri, 30 Jan 2004 20:38:25 -0500]/UNNAMED Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 01:38 from Mail Delivery System:Mail delivery failed.eml Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/03 Feb 2004 06:10 from [email protected]/doc.cmd Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/04 Feb 2004 04:45 from Mail Delivery System:Mail delivery failed.eml/[From [email protected]][Date Tue, 3 Feb 2004 20:41:18 -0800]/UNNAMED/readme.zip/readme.txt .pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/04 Feb 2004 04:45 from Mail Delivery System:Mail delivery failed.eml/[From [email protected]][Date Tue, 3 Feb 2004 20:41:18 -0800]/UNNAMED/readme.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/04 Feb 2004 04:45 from Mail Delivery System:Mail delivery failed.eml/[From [email protected]][Date Tue, 3 Feb 2004 20:41:18 -0800]/UNNAMED Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/04 Feb 2004 04:45 from Mail Delivery System:Mail delivery failed.eml Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/04 Feb 2004 22:50 from TELUS Mail Administrator:Your Message Cou/04 Feb 2004 22:50 from [email protected]:hi/test.pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/05 Feb 2004 02:30 from The Post Office:Delivery reports about yo/05 Feb 2004 01:11 from [email protected]:hello/dclz.zip/dclz.htm .pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/05 Feb 2004 02:30 from The Post Office:Delivery reports about yo/05 Feb 2004 01:11 from [email protected]:hello/dclz.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/05 Feb 2004 15:49 from [email protected]:ydy/document.zip/document.htm .pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/05 Feb 2004 15:49 from [email protected]:ydy/document.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/06 Feb 2004 15:01 from Mail Delivery Subsystem:Returned mail: se/06 Feb 2004 14:54 from [email protected]/file.zip/file.htm .pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/06 Feb 2004 15:01 from Mail Delivery Subsystem:Returned mail: se/06 Feb 2004 14:54 from [email protected]/file.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/07 Feb 2004 00:19 from [email protected]:Delivery Stat/07 Feb 2004 00:18 from [email protected]:Mail Deliver/test.zip/test.doc .scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/07 Feb 2004 00:19 from [email protected]:Delivery Stat/07 Feb 2004 00:18 from [email protected]:Mail Deliver/test.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/07 Feb 2004 00:14 from Mail Delivery System:Mail delivery failed.eml/[From [email protected]][Date Fri, 6 Feb 2004 16:13:06 -0800]/UNNAMED/text.zip/text.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/07 Feb 2004 00:14 from Mail Delivery System:Mail delivery failed.eml/[From [email protected]][Date Fri, 6 Feb 2004 16:13:06 -0800]/UNNAMED/text.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/07 Feb 2004 00:14 from Mail Delivery System:Mail delivery failed.eml/[From [email protected]][Date Fri, 6 Feb 2004 16:13:06 -0800]/UNNAMED Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/07 Feb 2004 00:14 from Mail Delivery System:Mail delivery failed.eml Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/08 Feb 2004 04:36 from Mail Administrator:Mail System Error - Re/08 Feb 2004 04:40 from [email protected]:hello/body.zip/body.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/08 Feb 2004 04:36 from Mail Administrator:Mail System Error - Re/08 Feb 2004 04:40 from [email protected]:hello/body.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/09 Feb 2004 11:31 from [email protected]:Hello/body.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/09 Feb 2004 08:57 from MMS MX119 Notifier:MMS Notification/09 Feb 2004 07:59 to [email protected]:hello/doc.zip/doc.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/09 Feb 2004 08:57 from MMS MX119 Notifier:MMS Notification/09 Feb 2004 07:59 to [email protected]:hello/doc.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Deleted Items/17 Nov 2003 19:27 from Administrator:Undeliverable Message User .rtf Suspicious: Exploit.HTML.Iframe.FileDownload
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Deleted Items/23 Nov 2003 12:11 from Postmaster:returned mail: returned to sen.rtf Suspicious: Exploit.HTML.Iframe.FileDownload
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Deleted Items/22 Nov 2003 12:29 from Inet Mail Delivery System:Error Announcem.rtf Suspicious: Exploit.HTML.Iframe.FileDownload
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/20 Aug 2003 07:56 from Mail Delivery System:Mail delivery failed.eml/[From <[email protected]>][Date Wed, 20 Aug 2003 2:57:47 --0500]/UNNAMED/document_9446.pif Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/20 Aug 2003 07:56 from Mail Delivery System:Mail delivery failed.eml/[From <[email protected]>][Date Wed, 20 Aug 2003 2:57:47 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/20 Aug 2003 07:56 from Mail Delivery System:Mail delivery failed.eml Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/22 Aug 2003 15:17 from Randy Kual:RE: failure notice.eml/[From <[email protected]>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED/your_document.pif Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/22 Aug 2003 15:17 from Randy Kual:RE: failure notice.eml/[From <[email protected]>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/22 Aug 2003 15:17 from Randy Kual:RE: failure notice.eml Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/22 Aug 2003 16:21 from Randy Kual:RE: failure notice.eml/[From <[email protected]>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED/your_document.pif Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/22 Aug 2003 16:21 from Randy Kual:RE: failure notice.eml/[From <[email protected]>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/22 Aug 2003 16:21 from Randy Kual:RE: failure notice.eml Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/20 Sep 2003 17:50 from [email protected]/[From "" <[email protected]>][Date Sat, 20 Sep 2003 13:50:24 -0400]/html Suspicious: Exploit.HTML.Iframe.FileDownload
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/20 Sep 2003 17:50 from [email protected]/[From "" <[email protected]>][Date Sat, 20 Sep 2003 13:50:24 -0400]/hqiq.exe Infected: Email-Worm.Win32.Swen
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/20 Sep 2003 17:50 from [email protected] Infected: Email-Worm.Win32.Swen
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/10 Oct 2003 15:23 from Administrator:Returned Message.eml/[From "Administrator" <[email protected]>][Date Fri, 10 Oct 2003 12:19:23 -0200]/html Suspicious: Exploit.HTML.Iframe.FileDownload
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/10 Oct 2003 15:23 from Administrator:Returned Message.eml/[From "Administrator" <[email protected]>][Date Fri, 10 Oct 2003 12:19:23 -0200]/clpsik.exe Infected: Email-Worm.Win32.Swen
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/10 Oct 2003 15:23 from Administrator:Returned Message.eml Infected: Email-Worm.Win32.Swen
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/20 Aug 2003 13:37 to Randy Kual (E-mail); James Szeliga (E-mail).eml/[From <[email protected]>][Date Wed, 20 Aug 2003 2:57:47 --0500]/UNNAMED/document_9446.pif Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/20 Aug 2003 13:37 to Randy Kual (E-mail); James Szeliga (E-mail).eml/[From <[email protected]>][Date Wed, 20 Aug 2003 2:57:47 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/20 Aug 2003 13:37 to Randy Kual (E-mail); James Szeliga (E-mail).eml Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/22 Aug 2003 14:25 to Randy Kual (E-mail); James Szeliga (E-mail).eml/[From <[email protected]>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED/your_document.pif Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/22 Aug 2003 14:25 to Randy Kual (E-mail); James Szeliga (E-mail).eml/[From <[email protected]>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/22 Aug 2003 14:25 to Randy Kual (E-mail); James Szeliga (E-mail).eml Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/22 Aug 2003 15:31 to 'Randy Kual'; 'James Szeliga (E-mail)':RE: .eml/[From <[email protected]>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED/your_document.pif Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/22 Aug 2003 15:31 to 'Randy Kual'; 'James Szeliga (E-mail)':RE: .eml/[From <[email protected]>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/22 Aug 2003 15:31 to 'Randy Kual'; 'James Szeliga (E-mail)':RE: .eml Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:02 from Didi Hadas:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:01 from Didi Hadas:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:06 from Amir Schnabel:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:05 from Dov Brand:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:09 from Ronny Weisman:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:09 from Tzahi Bahar:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:09 from David Saada:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:09 from Ronny Weisman:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:08 from Ronny Weisman:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:08 from Tzahi Bahar:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:08 from David Saada:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:07 from Ronny Weisman:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:07 from Amir Schnabel:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:06 from Amir Schnabel:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:06 from Dov Brand:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:06 from Amir Schnabel:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:15 from Yehiel Etah:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:14 from Zohar Halachmi:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:14 from Moshe Stein:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:13 from Moshe Stein:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:13 from Zohar Halachmi:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:12 from Yehiel Etah:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:11 from Yehiel Etah:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:11 from Shlomo Grinshpon:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:18 from Raz Herbst:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:18 from Daniel Cohen (FAST INTERNET):Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:17 from Shmulik Shechter:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:17 from Haim Kashi:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:17 from Shmulik Shechter:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:17 from Haim Kashi:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:15 from Lev Shapiro:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:15 from Yehiel Etah:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:15 from Moshe Stein:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:15 from Lev Shapiro:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:25 from Moshe Stein:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:22 from Uzi Drori:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:22 from Zohar Halachmi:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:22 from Daniel Cohen (FAST INTERNET):Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:22 from Raz Herbst:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:26 from Uzi Drori:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:41 from Gilad Tam:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:41 from Eli Friedlander:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:41 from Gilad Tam:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:41 from Lori Bernardi:FW: Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:42 from Eli Friedlander:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:41 from Eli Friedlander:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 18:18 from Eli Friedlander:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 18:18 from Gilad Tam:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 18:18 from Eli Friedlander:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 10:22 from Yossi Friedman:Check this/LINKS21.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 10:21 from Yossi Friedman:Check this/LINKS21.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 10:17 from Yossi Friedman:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 10:16 from Yossi Friedman:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 08:47 from Roy Kinamon:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 08:46 from Roy Kinamon:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 03:12 from Haim Kashi:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 03:12 from Raz Herbst:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/09 Feb 2000 08:24 from Gilad Ayalon:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/09 Feb 2000 08:23 from Gilad Ayalon:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst Infected: Virus.VBS.Freelink
C:\Documents and Settings\default\Local Settings\Temp\12A.tmp Infected: Backdoor.Win32.Afcore.cm
C:\Documents and Settings\default\Local Settings\Temp\1AA.tmp Infected: Backdoor.Win32.Afcore.cm
C:\Documents and Settings\default\Local Settings\Temp\CF.tmp Infected: Backdoor.Win32.Afcore.cm
C:\Program Files\Aprps\CxtPls.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\Program Files\Aprps\CxtPls.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\WINDOWS\All Users\Application Data\Spybot - Search & Destroy\Recovery\BonziBuddy.zip/WCInst.exe Suspicious: Password-protected-EXE
C:\WINDOWS\All Users\Application Data\Spybot - Search & Destroy\Recovery\BonziBuddy.zip Suspicious: Password-protected-EXE
C:\WINDOWS\optimize.exe Infected: Trojan-Downloader.Win32.Dyfuca.ab
C:\WINDOWS\SYSTEM32\netdteht.dll Infected: Backdoor.Win32.Afcore.cm
C:\WINDOWS\SYSTEM32\w130713.Stub.exe Infected: Trojan-Downloader.Win32.Delmed.a
Scan process completed.
Logfile of HijackThis v1.99.1
Scan saved at 7:32:43 AM, on 9/6/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\system32\stisvc.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\My Documents\Hijack\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_10_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125078722\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [ntdll.dll] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] C:\PROGRA~1\MESSEN~1\msmsgs.exe /background
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O4 - Global Startup: strings.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com/ (file missing) (HKCU)
O12 - Plugin for .hpb: C:\PROGRA~1\INTERN~1\PLUGINS\nphpipb.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {B160422D-0A48-11D4-BD9B-00A0C9B0AB7B} (Download Class) - http://expressit.bro...in/Download.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalci...6.1.7_en_dl.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?312
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe