Service Request Ticket - # 71787

Service Request Information

CONTACT Name Franklin, Brittany   View open tasks   View tasks from last 30 days   Schedule Change Contact Date Apr 12, 2019 08:54 AM
Department University Computing Solutions Phone 89267
Location Email newmanb@wou.edu Request for more information Send 'Keeping in touch' email Send 'I'm thinking of you' email

SR INFO Type WOU #
Priority Equipment Type
Status Flagged
Description

Computer Edit WOU # 20140201[Edit Inv] (opens in a new window) Bldg/Room OFF PDR
Service Tag Description Apple iMac 27-inch #Z0PF
Serial No. D25N712NF8J9 Location PDR 2023 Giveaway

CPU Intel Core i5(3.2GHz, 6MB L3)


OS MAC OS X 10.9 (Mavericks) Software MS Office 2011 Std for MAC from P0095171, Apple Logic Studio(Logic Pro X) renewal on P0095256, Finale 2014c site license on P0095335

Wired NIC 0C:4D:E9:B8:DA:86


Wireless NIC 88:63:DF:A5:03:C3


Bluetooth NIC 88:63:DF:A5:03:C4


TECHS Submitted by Brittany Franklin Contact franklinb@wou.edu 89267
Primary Technician Contact ychen13@wou.edu 889285

Tracking

Entered by Date Memo
Yumin Chen
Email

Public

Entered by Date Memo
Yumin Chen Apr 15, 2019 04:37 PM
Status changed from (1) Pending to (5) Completed
Add Attachment
Yumin Chen Apr 15, 2019 04:36 PM
Re-scan done. No threat found.
Add Attachment
Yumin Chen Apr 15, 2019 12:11 PM
Also met the person who did it.
Add Attachment
Yumin Chen Apr 15, 2019 12:11 PM
Deleted the files and it's scanning right now. 
Going to take some time.
Add Attachment
Megan Thibeault Apr 15, 2019 09:27 AM
Task reassigned to Yumin Chen.
Add Attachment
Brittany Franklin Apr 15, 2019 09:06 AM
It also detected a TROJAN

/Users/zcheng18/Desktop/m18/Project File Backups.zip
/Users/zcheng18/Downloads/S/Project File Backups/autorun.inf
Add Attachment
Robbie Downin Apr 12, 2019 02:48 PM
Deleted the file and 
started a fresh scan
Add Attachment
Brittany Franklin Apr 12, 2019 08:54 AM
Sophos detected this type of malware: VBS/AutoRun-UC
on W20140201, which sounds pretty bad.

Path to malware:
/Users/zcheng18/Downloads/Project File
Backups/Thumb.db

Computer may need to be reimaged...
Add Attachment