Hi Guys,
Had great help from you guys back in Feb and I seem to have been attacked again. Have done a Panda Scan, Spybot S&D then Hijack this report. All are below:
Incident Status Location Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\iesplg.dll
Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\imsmn.exe
Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\imsmain.exe
Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\iesmn.exe
Adware:adware/safetybar Not disinfected c:\documents and settings\all users\escritorio\Online Security Guide.url
Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\iesbunst.exe
Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\iesunst.exe
Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\imsunst.exe
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\pc\Cookies\pc@adserver.terra[1].txt
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\pc\Cookies\pc@adserver.terra[3].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\pc\Cookies\pc@adultfriendfinder[2].txt
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\pc\Cookies\pc@anm.co[1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\pc\Cookies\pc@toplist[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\pc\Cookies\pc@xiti[1].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\pc\Cookies\pc@xmts[1].txt
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\fixwareout\FindT\nircmd.exe
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\failure notice
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Re: Hi\detail3.zl9
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Protected Mail System\message.doc .scr
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Returned mail: see transcript for details
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Returned mail: see transcript for details\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Returned mail: see transcript for details
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Returned mail: see transcript for details\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Returned mail: see transcript for details
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\failure notice
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\important_info.zl9
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Re: Hello\detail3_info.zip[document.txt .exe]
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\details.zip[document.txt .exe]
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Re: Failure\msg.zip[document.txt .exe]
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Re: Virus Sample\datfiles.zip[details.txt .pif]
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Returned mail: see transcript for details
Virus:W32/Nurech.A.worm Disinfected Carpetas locales\Elementos eliminados\Forever and Ever\Greeting Postcard.exe
Virus:Trj/Alanchum.OD Disinfected Carpetas locales\Elementos eliminados\Chinese missile shot down Russian aircraft\More Here.exe
Had great help from you guys back in Feb and I seem to have been attacked again. Have done a Panda Scan, Spybot S&D then Hijack this report. All are below:
Incident Status Location Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\iesplg.dll
Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\imsmn.exe
Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\imsmain.exe
Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\iesmn.exe
Adware:adware/safetybar Not disinfected c:\documents and settings\all users\escritorio\Online Security Guide.url
Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\iesbunst.exe
Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\iesunst.exe
Adware:Adware/VideoActiveXObject Not disinfected C:\Archivos de programa\Video ActiveX Access\imsunst.exe
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\pc\Cookies\pc@adserver.terra[1].txt
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\pc\Cookies\pc@adserver.terra[3].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\pc\Cookies\pc@adultfriendfinder[2].txt
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\pc\Cookies\pc@anm.co[1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\pc\Cookies\pc@toplist[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\pc\Cookies\pc@xiti[1].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\pc\Cookies\pc@xmts[1].txt
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\fixwareout\FindT\nircmd.exe
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\failure notice
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Re: Hi\detail3.zl9
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Protected Mail System\message.doc .scr
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Returned mail: see transcript for details
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Returned mail: see transcript for details\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Returned mail: see transcript for details
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Returned mail: see transcript for details\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Returned mail: see transcript for details
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\failure notice
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\important_info.zl9
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Re: Hello\detail3_info.zip[document.txt .exe]
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\details.zip[document.txt .exe]
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Re: Failure\msg.zip[document.txt .exe]
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Re: Virus Sample\datfiles.zip[details.txt .pif]
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Virus:W32/Netsky.P.worm Disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)\message.zlq
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Mail Delivery (failure info@theguardiana.com)
Hacktool:Exploit/iFrame Not disinfected Carpetas locales\Bandeja de entrada\Returned mail: see transcript for details
Virus:W32/Nurech.A.worm Disinfected Carpetas locales\Elementos eliminados\Forever and Ever\Greeting Postcard.exe
Virus:Trj/Alanchum.OD Disinfected Carpetas locales\Elementos eliminados\Chinese missile shot down Russian aircraft\More Here.exe