hot_b
2006-07-28, 12:12
Hi,
I have a problem wherby my AV software (nod32) detects a new threat regularly whilst Internet Explorer is being used.
I have run Spyboot & found nothing.
Here is the threat log from nod32 (apologies for formatting..):
Time,Module,Object,Name,Threat,Action,User,Information
28/07/2006 09:47,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=5,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 09:09,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=4,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 09:07,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 09:04,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 09:02,AMON,file,D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\32G3JP4L\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted - error while cleaning - operation unavailable for this type of object,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
28/07/2006 09:02,AMON,file,C:\WINDOWS\TEMP\winD3.tmp,Win32/Dialer.PZ trojan,quarantined - deleted - error while cleaning - operation unavailable for this type of object,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
28/07/2006 09:02,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 09:00,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=5,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 08:40,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=4,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 08:38,AMON,file,D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\Q5U9G36B\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted - error while cleaning - operation unavailable for this type of object,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
28/07/2006 08:38,AMON,file,C:\WINDOWS\TEMP\win362.tmp,Win32/Dialer.PZ trojan,quarantined - deleted - error while cleaning - operation unavailable for this type of object,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
28/07/2006 08:38,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 08:36,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 08:34,AMON,file,D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\ZGCSXT3E\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted - error while cleaning - operation unavailable for this type of object,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
28/07/2006 08:34,AMON,file,C:\WINDOWS\TEMP\win1D0.tmp,Win32/Dialer.PZ trojan,quarantined - deleted - error while cleaning - operation unavailable for this type of object,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
28/07/2006 08:34,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 21:50,IMON,self-extracting archive,http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe,Win32/PrcView application,Connection terminated,STUDY_PC\Matt,
27/07/2006 21:50,IMON,self-extracting archive,http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe,Win32/PrcView application,Connection terminated,STUDY_PC\Matt,
27/07/2006 21:40,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=4,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 20:56,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 19:30,AMON,file,C:\WINDOWS\TEMP\win154.tmp,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
27/07/2006 19:30,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 19:30,AMON,file,D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\32G3JP4L\bgates[1].exe,Win32/Dialer.PZ trojan,deleted,NT AUTHORITY\SYSTEM,Event occurred at an attempt to access the file by the application: C:\Program Files\Prevx1\PXAgent.exe.
27/07/2006 19:30,AMON,file,D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\32G3JP4L\bgates[1].exe,Win32/Dialer.PZ trojan,deleted,NT AUTHORITY\SYSTEM,Event occurred at an attempt to access the file by the application: C:\Program Files\Prevx1\PXAgent.exe.
27/07/2006 19:28,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 18:58,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 18:56,AMON,file,D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\MJCVSTUN\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
27/07/2006 18:56,AMON,file,C:\WINDOWS\TEMP\winCB.tmp,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
27/07/2006 18:56,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 18:53,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=5,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
25/07/2006 23:23,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
25/07/2006 22:43,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=5,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
25/07/2006 20:55,AMON,file,D:\DOCUME~1\Matt\LOCALS~1\Temp\AAWTMP\C47309859\ADE1\Setup.exe,Win32/TrojanDropper.VB.NAI trojan,quarantined - deleted,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe. The file was moved to quarantine. You may close this window.
25/07/2006 11:32,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=4,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 11:13,AMON,file,D:\Documents and Settings\Jane\Local Settings\Temporary Internet Files\Content.IE5\NQ9GL3JN\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 11:12,AMON,file,C:\WINDOWS\TEMP\win2F3.tmp,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 11:12,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 10:52,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 10:32,AMON,file,D:\Documents and Settings\Jane\Local Settings\Temporary Internet Files\Content.IE5\TXG283HF\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 10:32,AMON,file,C:\WINDOWS\TEMP\win1D9.tmp,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 10:32,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 10:10,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=5,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 08:20,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=4,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 08:18,AMON,file,D:\Documents and Settings\Jane\Local Settings\Temporary Internet Files\Content.IE5\GHO127KD\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 08:18,AMON,file,C:\WINDOWS\TEMP\win158.tmp,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 08:17,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 08:15,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 08:13,AMON,file,D:\Documents and Settings\Jane\Local Settings\Temporary Internet Files\Content.IE5\NQ9GL3JN\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 08:13,AMON,file,C:\WINDOWS\TEMP\win149.tmp,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 08:13,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 07:45,AMON,file,C:\WINDOWS\system32\hgggdef.dll,Win32/Adware.Virtumonde application,quarantined - deleted,STUDY_PC\Jane,Event occurred on a newly created file. The file was moved to quarantine. You may close this window.
25/07/2006 07:44,IMON,self-extracting archive,http://d.mettere.net/a412/ac_yb.php?m=1&b=1785,a variant of Win32/TrojanDownloader.PurityScan.BV trojan,,STUDY_PC\Jane,
A manual scan also found:
D:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP162\A0019729.exe »NSIS »aaa - Win32/PrcView application - was a part of the deleted object
Panda online scan report to follow
I have a problem wherby my AV software (nod32) detects a new threat regularly whilst Internet Explorer is being used.
I have run Spyboot & found nothing.
Here is the threat log from nod32 (apologies for formatting..):
Time,Module,Object,Name,Threat,Action,User,Information
28/07/2006 09:47,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=5,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 09:09,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=4,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 09:07,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 09:04,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 09:02,AMON,file,D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\32G3JP4L\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted - error while cleaning - operation unavailable for this type of object,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
28/07/2006 09:02,AMON,file,C:\WINDOWS\TEMP\winD3.tmp,Win32/Dialer.PZ trojan,quarantined - deleted - error while cleaning - operation unavailable for this type of object,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
28/07/2006 09:02,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 09:00,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=5,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 08:40,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=4,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 08:38,AMON,file,D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\Q5U9G36B\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted - error while cleaning - operation unavailable for this type of object,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
28/07/2006 08:38,AMON,file,C:\WINDOWS\TEMP\win362.tmp,Win32/Dialer.PZ trojan,quarantined - deleted - error while cleaning - operation unavailable for this type of object,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
28/07/2006 08:38,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 08:36,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
28/07/2006 08:34,AMON,file,D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\ZGCSXT3E\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted - error while cleaning - operation unavailable for this type of object,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
28/07/2006 08:34,AMON,file,C:\WINDOWS\TEMP\win1D0.tmp,Win32/Dialer.PZ trojan,quarantined - deleted - error while cleaning - operation unavailable for this type of object,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
28/07/2006 08:34,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 21:50,IMON,self-extracting archive,http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe,Win32/PrcView application,Connection terminated,STUDY_PC\Matt,
27/07/2006 21:50,IMON,self-extracting archive,http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe,Win32/PrcView application,Connection terminated,STUDY_PC\Matt,
27/07/2006 21:40,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=4,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 20:56,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 19:30,AMON,file,C:\WINDOWS\TEMP\win154.tmp,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
27/07/2006 19:30,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 19:30,AMON,file,D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\32G3JP4L\bgates[1].exe,Win32/Dialer.PZ trojan,deleted,NT AUTHORITY\SYSTEM,Event occurred at an attempt to access the file by the application: C:\Program Files\Prevx1\PXAgent.exe.
27/07/2006 19:30,AMON,file,D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\32G3JP4L\bgates[1].exe,Win32/Dialer.PZ trojan,deleted,NT AUTHORITY\SYSTEM,Event occurred at an attempt to access the file by the application: C:\Program Files\Prevx1\PXAgent.exe.
27/07/2006 19:28,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 18:58,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 18:56,AMON,file,D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\MJCVSTUN\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
27/07/2006 18:56,AMON,file,C:\WINDOWS\TEMP\winCB.tmp,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
27/07/2006 18:56,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Matt,
27/07/2006 18:53,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=5,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
25/07/2006 23:23,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
25/07/2006 22:43,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=5,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Matt,
25/07/2006 20:55,AMON,file,D:\DOCUME~1\Matt\LOCALS~1\Temp\AAWTMP\C47309859\ADE1\Setup.exe,Win32/TrojanDropper.VB.NAI trojan,quarantined - deleted,STUDY_PC\Matt,Event occurred on a new file created by the application: C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe. The file was moved to quarantine. You may close this window.
25/07/2006 11:32,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=4,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 11:13,AMON,file,D:\Documents and Settings\Jane\Local Settings\Temporary Internet Files\Content.IE5\NQ9GL3JN\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 11:12,AMON,file,C:\WINDOWS\TEMP\win2F3.tmp,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 11:12,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 10:52,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 10:32,AMON,file,D:\Documents and Settings\Jane\Local Settings\Temporary Internet Files\Content.IE5\TXG283HF\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 10:32,AMON,file,C:\WINDOWS\TEMP\win1D9.tmp,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 10:32,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 10:10,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=5,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 08:20,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=4,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 08:18,AMON,file,D:\Documents and Settings\Jane\Local Settings\Temporary Internet Files\Content.IE5\GHO127KD\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 08:18,AMON,file,C:\WINDOWS\TEMP\win158.tmp,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 08:17,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 08:15,IMON,file,http://d.mettere.net/a412/a571.php?m=1&b=1785&c=2,Win32/Dialer.U trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 08:13,AMON,file,D:\Documents and Settings\Jane\Local Settings\Temporary Internet Files\Content.IE5\NQ9GL3JN\bgates[1].exe,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 08:13,AMON,file,C:\WINDOWS\TEMP\win149.tmp,Win32/Dialer.PZ trojan,quarantined - deleted,STUDY_PC\Jane,Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
25/07/2006 08:13,IMON,file,http://www.content-loader.com/getexe/?wmid=bgates,Win32/Dialer.PZ trojan,Connection terminated,STUDY_PC\Jane,
25/07/2006 07:45,AMON,file,C:\WINDOWS\system32\hgggdef.dll,Win32/Adware.Virtumonde application,quarantined - deleted,STUDY_PC\Jane,Event occurred on a newly created file. The file was moved to quarantine. You may close this window.
25/07/2006 07:44,IMON,self-extracting archive,http://d.mettere.net/a412/ac_yb.php?m=1&b=1785,a variant of Win32/TrojanDownloader.PurityScan.BV trojan,,STUDY_PC\Jane,
A manual scan also found:
D:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP162\A0019729.exe »NSIS »aaa - Win32/PrcView application - was a part of the deleted object
Panda online scan report to follow