parkex
2008-02-05, 01:43
Hi,
I am infected with W32/Bagle.QV.worm and w32/bagle.hx.worm. My SPybot, HIjackThis, Anti-virus, Firewall and anti-spyware are all disabled and they say that they are not a valid W32 application when I try to run them. I cannot boot into safe mode. This is my log from Panda Online Scanner:
Virus:W32/Bagle.QV.worm Disinfected Operating system
Virus:w32/bagle.hx.worm Disinfected Operating system
Spyware:Cookie/RealMedia Not disinfected
C:\Documents and Settings\John\Cookies\john@247realmedia[2].txt Spyware:Cookie/PointRoll Not disinfected
C:\Documents and Settings\John\Cookies\john@ads.pointroll[1].txt Spyware:Cookie/Adserver Not disinfected
C:\Documents and Settings\John\Cookies\john@adserver.easyad[1].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\John\Cookies\john@adtech[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\John\Cookies\john@adultfriendfinder[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\John\Cookies\john@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\John\Cookies\john@atwola[2].txt
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\John\Cookies\john@bravenet[1].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\John\Cookies\john@bs.serving-sys[2].txt
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\John\Cookies\john@citi.bridgetrack[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\John\Cookies\john@com[1].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\John\Cookies\john@did-it[2].txt
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\John\Cookies\john@fortunecity[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\John\Cookies\john@go[1].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\John\Cookies\john@kinghost[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\John\Cookies\john@perf.overture[1].txt
Spyware:Cookie/WegCash Not disinfected C:\Documents and Settings\John\Cookies\john@programs.wegcash[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\John\Cookies\john@realmedia[2].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\John\Cookies\john@revenue[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\John\Cookies\john@server.iad.liveperson[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\John\Cookies\john@serving-sys[2].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\John\Cookies\john@target[1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\John\Cookies\john@toplist[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\John\Cookies\john@trafficmp[1].txt
Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\John\Cookies\john@weborama[2].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\John\Cookies\john@www3.addfreestats[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\John\Cookies\john@xiti[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\John\Cookies\john@yadro[1].txt
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\0UIE304L\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\41XAHKA8\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\EO3TKUQN\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\F09VR1O3\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\HZ4XPO8T\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\K045V6JL\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\P3T59Y6A\b64_1[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\Q4B2NNJR\b64_31[1].jpg
Virus:W32/Bagle.QV.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\TJ8WQ0GC\b64_2[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\WXY78X6F\b64_31[1].jpg
Virus:W32/Bagle.QV.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\X335ZVGQ\b64_2[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\ZMAVY5JP\b64_1[1].jpg
Virus:W32/Bagle.QV.worm Disinfected C:\WINDOWS\system32\drivers\down\14422228.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\14432212.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\14435316.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\46036.exe
Virus:W32/Bagle.QV.worm Disinfected C:\WINDOWS\system32\drivers\down\51103.exe
Virus:W32/Bagle.QV.worm Disinfected C:\WINDOWS\system32\drivers\down\57652.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\59145.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\61738.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\66585.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\66695.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\69870.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\70331.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\72564.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\72634.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\75578.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\mdelk.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\wintems.exe
I am running a GMER scan now and I will post the results. Any help would be greatly appreciated. Thanks.
I am infected with W32/Bagle.QV.worm and w32/bagle.hx.worm. My SPybot, HIjackThis, Anti-virus, Firewall and anti-spyware are all disabled and they say that they are not a valid W32 application when I try to run them. I cannot boot into safe mode. This is my log from Panda Online Scanner:
Virus:W32/Bagle.QV.worm Disinfected Operating system
Virus:w32/bagle.hx.worm Disinfected Operating system
Spyware:Cookie/RealMedia Not disinfected
C:\Documents and Settings\John\Cookies\john@247realmedia[2].txt Spyware:Cookie/PointRoll Not disinfected
C:\Documents and Settings\John\Cookies\john@ads.pointroll[1].txt Spyware:Cookie/Adserver Not disinfected
C:\Documents and Settings\John\Cookies\john@adserver.easyad[1].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\John\Cookies\john@adtech[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\John\Cookies\john@adultfriendfinder[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\John\Cookies\john@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\John\Cookies\john@atwola[2].txt
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\John\Cookies\john@bravenet[1].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\John\Cookies\john@bs.serving-sys[2].txt
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\John\Cookies\john@citi.bridgetrack[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\John\Cookies\john@com[1].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\John\Cookies\john@did-it[2].txt
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\John\Cookies\john@fortunecity[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\John\Cookies\john@go[1].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\John\Cookies\john@kinghost[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\John\Cookies\john@perf.overture[1].txt
Spyware:Cookie/WegCash Not disinfected C:\Documents and Settings\John\Cookies\john@programs.wegcash[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\John\Cookies\john@realmedia[2].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\John\Cookies\john@revenue[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\John\Cookies\john@server.iad.liveperson[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\John\Cookies\john@serving-sys[2].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\John\Cookies\john@target[1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\John\Cookies\john@toplist[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\John\Cookies\john@trafficmp[1].txt
Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\John\Cookies\john@weborama[2].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\John\Cookies\john@www3.addfreestats[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\John\Cookies\john@xiti[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\John\Cookies\john@yadro[1].txt
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\0UIE304L\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\41XAHKA8\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\EO3TKUQN\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\F09VR1O3\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\HZ4XPO8T\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\K045V6JL\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\P3T59Y6A\b64_1[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\Q4B2NNJR\b64_31[1].jpg
Virus:W32/Bagle.QV.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\TJ8WQ0GC\b64_2[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\WXY78X6F\b64_31[1].jpg
Virus:W32/Bagle.QV.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\X335ZVGQ\b64_2[1].jpg
Virus:W32/Bagle.RC.worm Disinfected C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\ZMAVY5JP\b64_1[1].jpg
Virus:W32/Bagle.QV.worm Disinfected C:\WINDOWS\system32\drivers\down\14422228.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\14432212.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\14435316.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\46036.exe
Virus:W32/Bagle.QV.worm Disinfected C:\WINDOWS\system32\drivers\down\51103.exe
Virus:W32/Bagle.QV.worm Disinfected C:\WINDOWS\system32\drivers\down\57652.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\59145.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\61738.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\66585.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\66695.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\69870.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\70331.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\72564.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\72634.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\drivers\down\75578.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\mdelk.exe
Virus:W32/Bagle.RC.worm Disinfected C:\WINDOWS\system32\wintems.exe
I am running a GMER scan now and I will post the results. Any help would be greatly appreciated. Thanks.