Hello!
Description:
Last week our browser began displaying numerous separate popup windows. A few of the domains were: rond.starsdoor.com, traveltribe.com, sportskids.com, bid4prizes.com. The virus scanner eventually found "ZQest" and deleted it. After that, dialog boxes popped up saying that func.js and vttc.exe could not be found and threre were no more pop up windows. Using Adaware and Spybot in Safe Mode removed the visible offenders, but the malware programs were reinstalled with each restart of windows. Presistent offenders were Adspy.ttc and Zqest.K8l.
Following the hijackthis log is a list of removal measures tried and results or logs.
The system appeared to operate corrently after running BitDefender. The system is not exhibiting any unusual behavior now, but it is still mostly off the network and not in use. Since each scanner found different and additional problems, I have no confidence that this system is safe to use. I would greatly appreciate a review of the hijackthis log.
I hope I have presented this post appropriately.
TIA,
Lynn
Logfile of HijackThis v1.99.1
Scan saved at 10:11:21 AM, on 5/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
C:\Program Files\Common Files\Pumatech Shared\LiveUpdate Client\PtLUWorker.exe
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\COMPAQ\CPQINET\CPQInet.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\MagicRotation\MagicPvt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows NT\Accessories\MG.EXE
C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {19C0204F-F009-43C3-BEEC-809A61CC0B38} - \
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\PROGRA~1\Yahoo!\common\YIeTagBm.dll
O2 - BHO: (no name) - {72B6E9F8-A3B3-4A8D-AE3B-45A5442A3070} - \
O2 - BHO: (no name) - {988CD4A7-E9A6-40DB-8590-3F53DF6A7E44} - \
O2 - BHO: (no name) - {F0BF64AE-6C63-4622-B61F-F4C3811C9A02} - \
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
-------------------------------------------------------
AVG Anti-Spyware Online Scanner
Didn't find option to save.
Found Trojan.Rond in "C:\System Volume Information\_restore.....
and deleted.
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 7:12:35 AM 5/19/2007
+ Scan result:
C:\System Volume Information\_restore{7BF52158-FE42-499B-869A-CF146DD94F0B}\RP1402\A0113778.exe -> Adware.ZQuest : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BF52158-FE42-499B-869A-CF146DD94F0B}\RP1402\A0113776.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BF52158-FE42-499B-869A-CF146DD94F0B}\RP1402\A0113777.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BF52158-FE42-499B-869A-CF146DD94F0B}\RP1397\A0113566.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).
::Report end
----------------------------------------------------------------
BitDefender Online Scanner -Scan ReportBitDefender Online Scanner
Scan report generated at: Sat, May 19, 2007 - 09:53:48
Scanned File Status
C:\Documents and Settings\Buzz\Local Settings\Temp\CmarP1065.exe=>(NSIS o)=>zlib_nsis0004 Infected with: Trojan.Downloader.VB.AKE
C:\Documents and Settings\Buzz\Local Settings\Temp\CmarP1065.exe=>(NSIS o)=>zlib_nsis0004 Disinfection failed
C:\Documents and Settings\Buzz\Local Settings\Temp\CmarP1065.exe=>(NSIS o)=>zlib_nsis0004 Deleted
C:\Documents and Settings\Buzz\Local Settings\Temp\CmarP1065.exe=>(NSIS o) Update failed
C:\Documents and Settings\Buzz\Local Settings\Temp\xpre.exe Infected with: DeepScan:Generic.Malware.YVddld.57184FDD
C:\Documents and Settings\Buzz\Local Settings\Temp\xpre.exe Disinfection failed
C:\Documents and Settings\Buzz\Local Settings\Temp\xpre.exe Deleted
C:\Documents and Settings\Buzz\Local Settings\Temporary Internet Files\Content.IE5\KADEKA0Z\test[1].htm Detected with: Application.JS.ForcePopup.I
C:\Documents and Settings\Buzz\Local Settings\Temporary Internet Files\Content.IE5\KADEKA0Z\test[1].htm Disinfection failed
C:\Documents and Settings\Buzz\Local Settings\Temporary Internet Files\Content.IE5\KADEKA0Z\test[1].htm Deleted
C:\WINDOWS\system32\SBO\SB1065.exe Infected with: Trojan.Downloader.VB.AKE
C:\WINDOWS\system32\SBO\SB1065.exe Disinfection failed
C:\WINDOWS\system32\SBO\SB1065.exe Deleted
--------------------------------------------------------------------------------
Panda Active Scan
5/19/2007
Incident Status Location
Adware:adware/ucmore Not disinfected Windows Registry
Adware:Adware/Ucmore Not disinfected C:\Documents and Settings\Buzz\Local Settings\Temp\CmarP1065.exe
Virus:W32/Sircam Disinfected C:\Documents and Settings\Buzz\My Documents\Mail\PMAIL\MAIL\FOL016F1.PMM[Rochesdl.xls.pif]
Potentially unwanted tool:Application/Leaktest.A Not disinfected C:\Documents and Settings\Lynn\My Documents\Downloads\leaktest.exe
Virus:W32/Sircam Disinfected C:\GreyBackup\PMAIL\MAIL\FOL016F1.PMM[Rochesdl.xls.pif]
Hacktool:Exploit/iFrame Not disinfected C:\PMAIL\MAIL\FOL0110E.BKM[~0000218.~]
Virus:W32/Klez.I Disinfected C:\PMAIL\MAIL\FOL0110E.BKM[ALIGN.bat]
Hacktool:Exploit/iFrame Not disinfected C:\PMAIL\MAIL\FOL0110E.BKM[~0000225.~]
Virus:W32/Klez.I Disinfected C:\PMAIL\MAIL\FOL0110E.BKM[PASSSIGN.pif]
Hacktool:Exploit/iFrame Not disinfected C:\PMAIL\MAIL\FOL0110E.PMM[~0000198.~]
Virus:W32/Klez.I Disinfected C:\PMAIL\MAIL\FOL0110E.PMM[PASSSIGN.pif]
Hacktool:Exploit/iFrame Not disinfected C:\PMAIL\MAIL\FOL0110E.PMM[~0000204.~]
Virus:W32/Klez.I Disinfected C:\PMAIL\MAIL\FOL0110E.PMM[ALIGN.bat]
Virus:W32/Bugbear.B.Dam Disinfected C:\PMAIL\MAIL\FOL01D36.PMM[My Pictures.jpg.scr]
Virus:W32/Netsky.C.worm Disinfected C:\PMAIL\MAIL\FOL034D2.BKM[~0000163.~][~0000000.~][mail2_paypal.zip][mail2_paypal.pif]
Virus:W32/Netsky.C.worm Disinfected C:\PMAIL\MAIL\FOL034D2.PMM[~0000142.~][~0000000.~][mail2_paypal.zip][mail2_paypal.pif]
(Note: Spyware Cookies deleted for brevity - available on request)
Avast installed VirusScanner
5/19/2007 6:55:46 PM Lynn 968 Sign of "Win32:Agent-GYJ [Trj]" has been found in "C:\Program Files\SkyWatch\Help\Sminx.idx" file.
5/19/2007 7:15:00 PM Lynn 968 Sign of "Win32:CTX" has been found in "C:\System Volume Information\_restore{7BF52158-FE42-499B-869A-CF146DD94F0B}\RP1404\A0113923.dll" file.
Description:
Last week our browser began displaying numerous separate popup windows. A few of the domains were: rond.starsdoor.com, traveltribe.com, sportskids.com, bid4prizes.com. The virus scanner eventually found "ZQest" and deleted it. After that, dialog boxes popped up saying that func.js and vttc.exe could not be found and threre were no more pop up windows. Using Adaware and Spybot in Safe Mode removed the visible offenders, but the malware programs were reinstalled with each restart of windows. Presistent offenders were Adspy.ttc and Zqest.K8l.
Following the hijackthis log is a list of removal measures tried and results or logs.
The system appeared to operate corrently after running BitDefender. The system is not exhibiting any unusual behavior now, but it is still mostly off the network and not in use. Since each scanner found different and additional problems, I have no confidence that this system is safe to use. I would greatly appreciate a review of the hijackthis log.
I hope I have presented this post appropriately.
TIA,
Lynn
Logfile of HijackThis v1.99.1
Scan saved at 10:11:21 AM, on 5/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
C:\Program Files\Common Files\Pumatech Shared\LiveUpdate Client\PtLUWorker.exe
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\COMPAQ\CPQINET\CPQInet.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\MagicRotation\MagicPvt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows NT\Accessories\MG.EXE
C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {19C0204F-F009-43C3-BEEC-809A61CC0B38} - \
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\PROGRA~1\Yahoo!\common\YIeTagBm.dll
O2 - BHO: (no name) - {72B6E9F8-A3B3-4A8D-AE3B-45A5442A3070} - \
O2 - BHO: (no name) - {988CD4A7-E9A6-40DB-8590-3F53DF6A7E44} - \
O2 - BHO: (no name) - {F0BF64AE-6C63-4622-B61F-F4C3811C9A02} - \
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
-------------------------------------------------------
AVG Anti-Spyware Online Scanner
Didn't find option to save.
Found Trojan.Rond in "C:\System Volume Information\_restore.....
and deleted.
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 7:12:35 AM 5/19/2007
+ Scan result:
C:\System Volume Information\_restore{7BF52158-FE42-499B-869A-CF146DD94F0B}\RP1402\A0113778.exe -> Adware.ZQuest : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BF52158-FE42-499B-869A-CF146DD94F0B}\RP1402\A0113776.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BF52158-FE42-499B-869A-CF146DD94F0B}\RP1402\A0113777.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BF52158-FE42-499B-869A-CF146DD94F0B}\RP1397\A0113566.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).
::Report end
----------------------------------------------------------------
BitDefender Online Scanner -Scan ReportBitDefender Online Scanner
Scan report generated at: Sat, May 19, 2007 - 09:53:48
Scanned File Status
C:\Documents and Settings\Buzz\Local Settings\Temp\CmarP1065.exe=>(NSIS o)=>zlib_nsis0004 Infected with: Trojan.Downloader.VB.AKE
C:\Documents and Settings\Buzz\Local Settings\Temp\CmarP1065.exe=>(NSIS o)=>zlib_nsis0004 Disinfection failed
C:\Documents and Settings\Buzz\Local Settings\Temp\CmarP1065.exe=>(NSIS o)=>zlib_nsis0004 Deleted
C:\Documents and Settings\Buzz\Local Settings\Temp\CmarP1065.exe=>(NSIS o) Update failed
C:\Documents and Settings\Buzz\Local Settings\Temp\xpre.exe Infected with: DeepScan:Generic.Malware.YVddld.57184FDD
C:\Documents and Settings\Buzz\Local Settings\Temp\xpre.exe Disinfection failed
C:\Documents and Settings\Buzz\Local Settings\Temp\xpre.exe Deleted
C:\Documents and Settings\Buzz\Local Settings\Temporary Internet Files\Content.IE5\KADEKA0Z\test[1].htm Detected with: Application.JS.ForcePopup.I
C:\Documents and Settings\Buzz\Local Settings\Temporary Internet Files\Content.IE5\KADEKA0Z\test[1].htm Disinfection failed
C:\Documents and Settings\Buzz\Local Settings\Temporary Internet Files\Content.IE5\KADEKA0Z\test[1].htm Deleted
C:\WINDOWS\system32\SBO\SB1065.exe Infected with: Trojan.Downloader.VB.AKE
C:\WINDOWS\system32\SBO\SB1065.exe Disinfection failed
C:\WINDOWS\system32\SBO\SB1065.exe Deleted
--------------------------------------------------------------------------------
Panda Active Scan
5/19/2007
Incident Status Location
Adware:adware/ucmore Not disinfected Windows Registry
Adware:Adware/Ucmore Not disinfected C:\Documents and Settings\Buzz\Local Settings\Temp\CmarP1065.exe
Virus:W32/Sircam Disinfected C:\Documents and Settings\Buzz\My Documents\Mail\PMAIL\MAIL\FOL016F1.PMM[Rochesdl.xls.pif]
Potentially unwanted tool:Application/Leaktest.A Not disinfected C:\Documents and Settings\Lynn\My Documents\Downloads\leaktest.exe
Virus:W32/Sircam Disinfected C:\GreyBackup\PMAIL\MAIL\FOL016F1.PMM[Rochesdl.xls.pif]
Hacktool:Exploit/iFrame Not disinfected C:\PMAIL\MAIL\FOL0110E.BKM[~0000218.~]
Virus:W32/Klez.I Disinfected C:\PMAIL\MAIL\FOL0110E.BKM[ALIGN.bat]
Hacktool:Exploit/iFrame Not disinfected C:\PMAIL\MAIL\FOL0110E.BKM[~0000225.~]
Virus:W32/Klez.I Disinfected C:\PMAIL\MAIL\FOL0110E.BKM[PASSSIGN.pif]
Hacktool:Exploit/iFrame Not disinfected C:\PMAIL\MAIL\FOL0110E.PMM[~0000198.~]
Virus:W32/Klez.I Disinfected C:\PMAIL\MAIL\FOL0110E.PMM[PASSSIGN.pif]
Hacktool:Exploit/iFrame Not disinfected C:\PMAIL\MAIL\FOL0110E.PMM[~0000204.~]
Virus:W32/Klez.I Disinfected C:\PMAIL\MAIL\FOL0110E.PMM[ALIGN.bat]
Virus:W32/Bugbear.B.Dam Disinfected C:\PMAIL\MAIL\FOL01D36.PMM[My Pictures.jpg.scr]
Virus:W32/Netsky.C.worm Disinfected C:\PMAIL\MAIL\FOL034D2.BKM[~0000163.~][~0000000.~][mail2_paypal.zip][mail2_paypal.pif]
Virus:W32/Netsky.C.worm Disinfected C:\PMAIL\MAIL\FOL034D2.PMM[~0000142.~][~0000000.~][mail2_paypal.zip][mail2_paypal.pif]
(Note: Spyware Cookies deleted for brevity - available on request)
Avast installed VirusScanner
5/19/2007 6:55:46 PM Lynn 968 Sign of "Win32:Agent-GYJ [Trj]" has been found in "C:\Program Files\SkyWatch\Help\Sminx.idx" file.
5/19/2007 7:15:00 PM Lynn 968 Sign of "Win32:CTX" has been found in "C:\System Volume Information\_restore{7BF52158-FE42-499B-869A-CF146DD94F0B}\RP1404\A0113923.dll" file.