Hello,
I received this through use of bittorrent. Since this virus has infected my computer, I have received several instances of AVG detecting a virus called Klone. I have removed the virus several times from my machine. I have also run housecall, spybot s&d, adaware, f-secure and panda to try removing this. No luck.
My most recent scan with panda generated the following log file:
Incident Status Location
Potentially unwanted tool:application/winfixer2005 Not disinfected c:\winnt\downloaded program files\UWA6P_0001_N91M1807NetInstaller.exe
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.atwola.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.overture.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.zedo.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[stats.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[www.drivecleaner.com/]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv698.jar-2ad2754e-3b6f3752.zip[Matrix.class]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\ZeWrestler\Cookies\zewrestler@stats1.reliablestats[2].txt
Virus:W32/Bagle.BB.worm Disinfected Archive Folders\Deleted Items\Re: Thanks
\Price.scr
Virus:Trj/Mitglieder.BO Disinfected Archive Folders\Deleted Items\Delivery Status Notification (Failure)\price_new.zip[Loader/doc_01.exe]
Virus:Trj/Mitglieder.BO Disinfected Archive Folders\Deleted Items\price_08.zip[Loader/doc_01.exe]
Potentially unwanted tool:Application/SystemDoctor2006 Not disinfected C:\Documents and Settings\ZeWrestler\Local Settings\Temporary Internet Files\Content.IE5\YZEOPCD1\SystemDoctor2006FreeInstall[1].exe
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Documents and Settings\ZeWrestler\Local Settings\Temporary Internet Files\Content.IE5\YZEOPCD1\WinAntiVirusPro2006FreeInstall[1].cab[UWA6P_0001_N91M1807NetInstaller.exe]
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINNT\system32\hltwpxir.exe
Virus:W32/Sdbot.ftp.worm Disinfected C:\WINNT\system32\I.0
Spyware:Spyware/Virtumonde Not disinfected C:\WINNT\system32\ljjgdbb.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINNT\system32\qairrugi.exe
Potentially unwanted tool:Application/Restart Not disinfected C:\WINNT\system32\Tools\Restart.exe
I have also run hijackthis, but it appears to crash part way though the scan. I'll post log in the next thread. (too big to post in one post)
I received this through use of bittorrent. Since this virus has infected my computer, I have received several instances of AVG detecting a virus called Klone. I have removed the virus several times from my machine. I have also run housecall, spybot s&d, adaware, f-secure and panda to try removing this. No luck.
My most recent scan with panda generated the following log file:
Incident Status Location
Potentially unwanted tool:application/winfixer2005 Not disinfected c:\winnt\downloaded program files\UWA6P_0001_N91M1807NetInstaller.exe
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.atwola.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.overture.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[.zedo.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[stats.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Mozilla\Firefox\Profiles\ugbfcg3d.default\cookies.txt[www.drivecleaner.com/]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\ZeWrestler\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv698.jar-2ad2754e-3b6f3752.zip[Matrix.class]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\ZeWrestler\Cookies\zewrestler@stats1.reliablestats[2].txt
Virus:W32/Bagle.BB.worm Disinfected Archive Folders\Deleted Items\Re: Thanks

Virus:Trj/Mitglieder.BO Disinfected Archive Folders\Deleted Items\Delivery Status Notification (Failure)\price_new.zip[Loader/doc_01.exe]
Virus:Trj/Mitglieder.BO Disinfected Archive Folders\Deleted Items\price_08.zip[Loader/doc_01.exe]
Potentially unwanted tool:Application/SystemDoctor2006 Not disinfected C:\Documents and Settings\ZeWrestler\Local Settings\Temporary Internet Files\Content.IE5\YZEOPCD1\SystemDoctor2006FreeInstall[1].exe
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Documents and Settings\ZeWrestler\Local Settings\Temporary Internet Files\Content.IE5\YZEOPCD1\WinAntiVirusPro2006FreeInstall[1].cab[UWA6P_0001_N91M1807NetInstaller.exe]
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINNT\system32\hltwpxir.exe
Virus:W32/Sdbot.ftp.worm Disinfected C:\WINNT\system32\I.0
Spyware:Spyware/Virtumonde Not disinfected C:\WINNT\system32\ljjgdbb.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINNT\system32\qairrugi.exe
Potentially unwanted tool:Application/Restart Not disinfected C:\WINNT\system32\Tools\Restart.exe
I have also run hijackthis, but it appears to crash part way though the scan. I'll post log in the next thread. (too big to post in one post)