I came back from a long weekend to find NOD32 and AVG all blown up on my screen with warnings. It was all fine when I left (no accidental clicks or anything that I can recall anytime recently). I immediately ran NOD32, AVG, and Spybot repeatedly (including safe mode), but threats kept reappearing. Logs from Panda and HJT are below... Win32.Agent.pz is the only one still appearing in Spybot scans -- Spybot says it can only fix 1 of 4 related issues, even on reboot scan.
Background: I recently switched to NOD32 (from NIS, about 3 weeks ago). I have a legally licensed version of NOD32 -- the "crack" files in the logs are from when I downloaded it in order to evaluate an unrestricted version before I purchased it. I suppose that is a pretty good guess for the source of these issues...
When I came back from my long weekend, NOD32 was intercepting what looked like trojan downloads from some sketchy URL. AVG was detecting and removing loggers. Of course, I instructed to terminate/clean all of them.
Thanks in advance for your time and assistance.
Panda ActiveScan Log:
Incident Status Location
Virus:trj/torpig.a Disinfected Operating system
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.azjmp.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.belnk.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.cdfreaks.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.club.cdfreaks.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.dist.belnk.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.go.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.gostats.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.xiti.com/]
Virus:Trj/Agent.EHT Disinfected C:\Documents and Settings\Jacob Wills\Local Settings\Temporary Internet Files\Content.IE5\WO94M9YL\czpgdnjtdq[1].htm
Potentially unwanted tool:Application/CloseApp Not disinfected C:\WINDOWS\system32\closeapp.exe
Virus:Bck/Agent.ENA Disinfected C:\WINDOWS\system32\utorrent.exe
Virus:Bck/Agent.ENA Disinfected F:\Downloads\NOD32 2.70.32 + Crack\Crack.exe
Virus:Bck/Agent.ENA Not disinfected F:\Downloads\NOD32 2.70.32 + Crack.rar[NOD32 2.70.32 + Crack\Crack.exe]
Dialer
ialer.Gen Not disinfected Archive Folders\Deleted Items\Have Fun.... You will enjoy...\serials.zip[serials/s2k.serials2k7.1.zip][s2k.hacking.exe]
Hacktool:Exploit/iFrame Not disinfected Archive Folders\Deleted Items\ Re: FW: Tips forTelemarketers & Junk Mail
Hacktool:Exploit/iFrame Not disinfected Archive Folders\Sent Items\RE: Bounce Emails update\Japanese girl VS playboy
Hacktool:Exploit/iFrame Not disinfected Archive Folders\Sent Items\FW: GE Capital spokeswoman said the company closed
Hacktool:Exploit/iFrame Not disinfected Archive Folders\Sent Items\bounce\Undeliverable: Mail Delivery (failure kp@realty.sdcoxmail.com)\Mail Delivery (failure kp@realty.sdcoxmail.com)
Virus:W32/Netsky.P.worm Disinfected Archive Folders\Sent Items\bounce\Undeliverable: Mail Delivery (failure kp@realty.sdcoxmail.com)\Mail Delivery (failure kp@realty.sdcoxmail.com)\message.scr
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Deleted Items\Message
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Inbox\Jun 21 2001 18
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Sent Items\FW: Please try again
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Newport Wireless\FW: Please allow approximately 10 days for
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Newport Wireless\RE: Please allow approximately 10 days for
Hacktool:Exploit/iFrame Not disinfected Archive Folders\Sent Items\FW: Please try again
Virus:Trj/Agent.DIL Disinfected Archive Folders\Personal\hmm\salary_survey_2.exe
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Deleted Items\Re: Merry Chirstmas
Virus:W32/Badtrans.B Disinfected Personal Folders\Deleted Items\Re: Merry Chirstmas\NEWS_DOC.DOC.scr
Dialer
ialer.Gen Not disinfected Personal Folders\technologist.com\Have Fun.... You will enjoy...\serials.zip[serials/s2k.serials2k7.1.zip][s2k.hacking.exe]
Hacktool:Exploit/iFrame Not disinfected Personal Folders\technologist.com\ Re: FW: Tips forTelemarketers & Junk Mail
Virus:Trj/Shutdown.Z Disinfected G:\Software\SmitfraudFix\SmitfraudFix\restart.exe
Potentially unwanted tool:Application/Processor Not disinfected G:\Software\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Virus:Trj/Shutdown.Z Disinfected G:\Software\SmitfraudFix.zip[SmitfraudFix/restart.exe]
-------------------------------------
HJT Log in following post...
Background: I recently switched to NOD32 (from NIS, about 3 weeks ago). I have a legally licensed version of NOD32 -- the "crack" files in the logs are from when I downloaded it in order to evaluate an unrestricted version before I purchased it. I suppose that is a pretty good guess for the source of these issues...
When I came back from my long weekend, NOD32 was intercepting what looked like trojan downloads from some sketchy URL. AVG was detecting and removing loggers. Of course, I instructed to terminate/clean all of them.
Thanks in advance for your time and assistance.
Panda ActiveScan Log:
Incident Status Location
Virus:trj/torpig.a Disinfected Operating system
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.azjmp.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.belnk.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.cdfreaks.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.club.cdfreaks.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.dist.belnk.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.go.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.gostats.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Jacob Wills\Application Data\Mozilla\Firefox\Profiles\112e7579.default\cookies.txt[.xiti.com/]
Virus:Trj/Agent.EHT Disinfected C:\Documents and Settings\Jacob Wills\Local Settings\Temporary Internet Files\Content.IE5\WO94M9YL\czpgdnjtdq[1].htm
Potentially unwanted tool:Application/CloseApp Not disinfected C:\WINDOWS\system32\closeapp.exe
Virus:Bck/Agent.ENA Disinfected C:\WINDOWS\system32\utorrent.exe
Virus:Bck/Agent.ENA Disinfected F:\Downloads\NOD32 2.70.32 + Crack\Crack.exe
Virus:Bck/Agent.ENA Not disinfected F:\Downloads\NOD32 2.70.32 + Crack.rar[NOD32 2.70.32 + Crack\Crack.exe]
Dialer

Hacktool:Exploit/iFrame Not disinfected Archive Folders\Deleted Items\ Re: FW: Tips forTelemarketers & Junk Mail
Hacktool:Exploit/iFrame Not disinfected Archive Folders\Sent Items\RE: Bounce Emails update\Japanese girl VS playboy
Hacktool:Exploit/iFrame Not disinfected Archive Folders\Sent Items\FW: GE Capital spokeswoman said the company closed
Hacktool:Exploit/iFrame Not disinfected Archive Folders\Sent Items\bounce\Undeliverable: Mail Delivery (failure kp@realty.sdcoxmail.com)\Mail Delivery (failure kp@realty.sdcoxmail.com)
Virus:W32/Netsky.P.worm Disinfected Archive Folders\Sent Items\bounce\Undeliverable: Mail Delivery (failure kp@realty.sdcoxmail.com)\Mail Delivery (failure kp@realty.sdcoxmail.com)\message.scr
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Deleted Items\Message
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Inbox\Jun 21 2001 18
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Sent Items\FW: Please try again
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Newport Wireless\FW: Please allow approximately 10 days for
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Newport Wireless\RE: Please allow approximately 10 days for
Hacktool:Exploit/iFrame Not disinfected Archive Folders\Sent Items\FW: Please try again
Virus:Trj/Agent.DIL Disinfected Archive Folders\Personal\hmm\salary_survey_2.exe
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Deleted Items\Re: Merry Chirstmas
Virus:W32/Badtrans.B Disinfected Personal Folders\Deleted Items\Re: Merry Chirstmas\NEWS_DOC.DOC.scr
Dialer

Hacktool:Exploit/iFrame Not disinfected Personal Folders\technologist.com\ Re: FW: Tips forTelemarketers & Junk Mail
Virus:Trj/Shutdown.Z Disinfected G:\Software\SmitfraudFix\SmitfraudFix\restart.exe
Potentially unwanted tool:Application/Processor Not disinfected G:\Software\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Virus:Trj/Shutdown.Z Disinfected G:\Software\SmitfraudFix.zip[SmitfraudFix/restart.exe]
-------------------------------------
HJT Log in following post...