View Single Post
Old 08-07-2007, 06:03 PM   #4 (permalink)
zipzappy
Registered User
 
Join Date: May 2007
Posts: 208
OS: XP


Re: Trojans & Adware

There was to much text to put all 4 logs in one post lol, so heres the
BitDefender Log that you asked for as well, i ran a Deep System Scan.





//-----------------------------------------------------------------
//
// ProductBitDefender Antivirus Plus v10
// Product10.2
//
// Created on: 07/08/2007 14:51:10
//
//-----------------------------------------------------------------


Virus Statistics

Scan path : C:\
Folders : 11910
Files : 615887
Memory processes scanned : 41
Archives : 7033
Runtime packers : 33491
Identified viruses : 19
Infected files : 29
Memory processes infected : 2
Suspect files : 0
Warnings : 0
Disinfected files : 0
Deleted files : 0
Moved files : 16
I/O errors : 31
Scan time : 04:31:51
Scan speed (files/sec) : 37

Spyware Statistics

Registry keys scanned : 1633
Registry keys infected : 6
Cookies scanned : 93
Cookies infected : 0
Spyware files infected : 0
Spyware threats detected : 1


Virus definitions : 753972
Scan plugins : 16
Archive plugins : 41
Unpack plugins : 6
Mail plugins : 6
System plugins : 5

Virus scan options

Detection
[X] Scan boot sectors
[X] Memory Processes
[X] Scan archives
[X] Scan runtime packers
[X] Scan email

File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;

Action

Infected objects
[ ] Ignore
[X] Disinfect
[ ] Delete
[ ] Move to quarantine
[ ] Prompt user

Second action
[ ] Ignore
[ ] Delete
[X] Move to quarantine
[ ] Prompt user

Virus scan options
[X] Enable warnings
[X] Enable heuristics
[ ] Show all files in log
[X] Report file: C:\Documents and Settings\All Users\Application Data\Bitdefender\Desktop\Profiles\Logs\deep_scan\1186512670.log

Spyware scan options

[X] Scan for riskware
[ ] Skip dial and applications from scan
[X] Registry keys
[X] Cookies


Summary:

<System>=>C:\WINDOWS\R2lvcmdpbw\command.exe (disk) Detected: Adware.CommAd.A
<System>=>C:\WINDOWS\R2lvcmdpbw\command.exe (disk) Disinfection failed
<System>=>C:\WINDOWS\R2lvcmdpbw\command.exe (disk) Move failed
<System>=>C:\WINDOWS\R2lvcmdpbw\command.exe (full dump) Detected: Adware.CommAd.A
<System>=>C:\WINDOWS\R2lvcmdpbw\command.exe (full dump) Disinfection failed
<System>=>C:\WINDOWS\R2lvcmdpbw\command.exe (full dump) Move failed
<System>=>C:\Program Files\Network Monitor\netmon.exe (memory dump) Detected: Adware.CommAd.A
<System>=>C:\Program Files\Network Monitor\netmon.exe (memory dump) Disinfection failed
<System>=>C:\Program Files\Network Monitor\netmon.exe (memory dump) Move failed
<System>=>C:\Program Files\Network Monitor\netmon.exe (disk) Detected: Adware.CommAd.A
<System>=>C:\Program Files\Network Monitor\netmon.exe (disk) Disinfection failed
<System>=>C:\Program Files\Network Monitor\netmon.exe (disk) Move failed
<System>=>C:\Program Files\Network Monitor\netmon.exe (full dump) Detected: Adware.CommAd.A
<System>=>C:\Program Files\Network Monitor\netmon.exe (full dump) Disinfection failed
<System>=>C:\Program Files\Network Monitor\netmon.exe (full dump) Move failed
<System>=>C:\Program Files\WinPop\winpop.exe (memory dump) Infected: Trojan.Popwin.DE
<System>=>C:\Program Files\WinPop\winpop.exe (memory dump) Disinfection failed
<System>=>C:\Program Files\WinPop\winpop.exe (memory dump) Move failed
<System>=>C:\Program Files\WinPop\winpop.exe (disk) Infected: Trojan.Popwin.DE
<System>=>C:\Program Files\WinPop\winpop.exe (disk) Disinfection failed
<System>=>C:\Program Files\WinPop\winpop.exe (disk) Move failed
<System>=>C:\Program Files\WinPop\winpop.exe (full dump) Infected: Trojan.Popwin.DE
<System>=>C:\Program Files\WinPop\winpop.exe (full dump) Disinfection failed
<System>=>C:\Program Files\WinPop\winpop.exe (full dump) Move failed
<System>=>C:\PROGRA~1\COMMON~1\SMBOLS~1\spoolsv.exe (disk) Detected: Adware.Clickspring.Purityscan.O
<System>=>C:\PROGRA~1\COMMON~1\SMBOLS~1\spoolsv.exe (disk) Disinfection failed
<System>=>C:\PROGRA~1\COMMON~1\SMBOLS~1\spoolsv.exe (disk) Move failed
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CMDSERVICE\ImagePath=>C:\WINDOWS\R2LVCMDPBW\COMMAND.EXE Detected: Adware.CommAd.A
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CMDSERVICE\ImagePath=>C:\WINDOWS\R2LVCMDPBW\COMMAND.EXE Disinfection failed
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CMDSERVICE\ImagePath=>C:\WINDOWS\R2LVCMDPBW\COMMAND.EXE Move failed
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\NETWORK MONITOR\ImagePath=>C:\PROGRAM FILES\NETWORK MONITOR\NETMON.EXE Detected: Adware.CommAd.A
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\NETWORK MONITOR\ImagePath=>C:\PROGRAM FILES\NETWORK MONITOR\NETMON.EXE Disinfection failed
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\NETWORK MONITOR\ImagePath=>C:\PROGRAM FILES\NETWORK MONITOR\NETMON.EXE Move failed
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\CMDSERVICE\ImagePath=>C:\WINDOWS\R2LVCMDPBW\COMMAND.EXE Detected: Adware.CommAd.A
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\CMDSERVICE\ImagePath=>C:\WINDOWS\R2LVCMDPBW\COMMAND.EXE Disinfection failed
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\CMDSERVICE\ImagePath=>C:\WINDOWS\R2LVCMDPBW\COMMAND.EXE Move failed
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\NETWORK MONITOR\ImagePath=>C:\PROGRAM FILES\NETWORK MONITOR\NETMON.EXE Detected: Adware.CommAd.A
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\NETWORK MONITOR\ImagePath=>C:\PROGRAM FILES\NETWORK MONITOR\NETMON.EXE Disinfection failed
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\NETWORK MONITOR\ImagePath=>C:\PROGRAM FILES\NETWORK MONITOR\NETMON.EXE Move failed
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET003\SERVICES\CMDSERVICE\ImagePath=>C:\WINDOWS\R2LVCMDPBW\COMMAND.EXE Detected: Adware.CommAd.A
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET003\SERVICES\CMDSERVICE\ImagePath=>C:\WINDOWS\R2LVCMDPBW\COMMAND.EXE Disinfection failed
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET003\SERVICES\CMDSERVICE\ImagePath=>C:\WINDOWS\R2LVCMDPBW\COMMAND.EXE Move failed
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET003\SERVICES\NETWORK MONITOR\ImagePath=>C:\PROGRAM FILES\NETWORK MONITOR\NETMON.EXE Detected: Adware.CommAd.A
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET003\SERVICES\NETWORK MONITOR\ImagePath=>C:\PROGRAM FILES\NETWORK MONITOR\NETMON.EXE Disinfection failed
<System>=>HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET003\SERVICES\NETWORK MONITOR\ImagePath=>C:\PROGRAM FILES\NETWORK MONITOR\NETMON.EXE Move failed
C:\Documents and Settings\Administrator\Local Settings\Temp\b128.exe=>(NSIS o)=>lzma_solid_nsis0002 Infected: Trojan.Downloader.Purityscan.EH
C:\Documents and Settings\Administrator\Local Settings\Temp\b128.exe=>(NSIS o)=>lzma_solid_nsis0002 Disinfection failed
C:\Documents and Settings\Administrator\Local Settings\Temp\b128.exe=>(NSIS o)=>lzma_solid_nsis0002 Move failed
C:\Documents and Settings\Administrator\Local Settings\Temp\b128.exe=>(NSIS o)=>lzma_solid_nsis0004 Detected: Adware.Softomate.BG
C:\Documents and Settings\Administrator\Local Settings\Temp\b128.exe=>(NSIS o)=>lzma_solid_nsis0004 Disinfection failed
C:\Documents and Settings\Administrator\Local Settings\Temp\b128.exe=>(NSIS o)=>lzma_solid_nsis0004 Move failed
C:\Documents and Settings\Administrator\Local Settings\Temp\cmdinst.exe Infected: Trojan.Proxy.493
C:\Documents and Settings\Administrator\Local Settings\Temp\cmdinst.exe Disinfection failed
C:\Documents and Settings\Administrator\Local Settings\Temp\cmdinst.exe Moved
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\1YNM6DXP\installer[1].exe Infected: Trojan.Proxy.493
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\1YNM6DXP\installer[1].exe Disinfection failed
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\1YNM6DXP\installer[1].exe Moved
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4T67KLAB\128[1].net=>(NSIS o)=>lzma_solid_nsis0002 Infected: Trojan.Downloader.Purityscan.EH
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4T67KLAB\128[1].net=>(NSIS o)=>lzma_solid_nsis0002 Disinfection failed
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4T67KLAB\128[1].net=>(NSIS o)=>lzma_solid_nsis0002 Move failed
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4T67KLAB\128[1].net=>(NSIS o)=>lzma_solid_nsis0004 Detected: Adware.Softomate.BG
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4T67KLAB\128[1].net=>(NSIS o)=>lzma_solid_nsis0004 Disinfection failed
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4T67KLAB\128[1].net=>(NSIS o)=>lzma_solid_nsis0004 Move failed
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1E3456J\ctxad-556[1].0006 Infected: Trojan.Dropper.PurityScan.AJ
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1E3456J\ctxad-556[1].0006 Disinfection failed
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1E3456J\ctxad-556[1].0006 Moved
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CY3F2AXO\dohinst-103[1].0000 Infected: MemScan:Adware.Mediatickets.C
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CY3F2AXO\dohinst-103[1].0000 Disinfection failed
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CY3F2AXO\dohinst-103[1].0000 Moved
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\N1WG7D1Q\setar-101[1].0000 Detected: Adware.Yazzle.A
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\N1WG7D1Q\setar-101[1].0000 Disinfection failed
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\N1WG7D1Q\setar-101[1].0000 Moved
C:\Documents and Settings\Administrator\My Documents\ѕystem\lοgonui.exe Detected: Adware.ClickSpring.CB
C:\Documents and Settings\Administrator\My Documents\ѕystem\lοgonui.exe Disinfection failed
C:\Documents and Settings\Administrator\My Documents\ѕystem\lοgonui.exe Moved
C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\system.dll Infected: Trojan.Downloader.Agent.BAL
C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\system.dll Disinfection failed
C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\system.dll Move failed
C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\Update.exe Infected: Trojan.Downloader.Small.AFW
C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\Update.exe Disinfection failed
C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\Update.exe Move failed
C:\Program Files\Common Files\sуmbols\spoolsv.exe Detected: Adware.Clickspring.Purityscan.O
C:\Program Files\Common Files\sуmbols\spoolsv.exe Disinfection failed
C:\Program Files\Common Files\sуmbols\spoolsv.exe Moved
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe Infected: Trojan.Downloader.PurityScan.CR
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe Disinfection failed
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe Moved
C:\Program Files\Network Monitor\netmon.exe Detected: Adware.CommAd.A
C:\Program Files\Network Monitor\netmon.exe Disinfection failed
C:\Program Files\Network Monitor\netmon.exe Moved
C:\Program Files\Outerinfo\OiUninstaller.exe Infected: Trojan.Dropper.PurityScan.AK
C:\Program Files\Outerinfo\OiUninstaller.exe Disinfection failed
C:\Program Files\Outerinfo\OiUninstaller.exe Moved
C:\Program Files\WinPop\winpop.exe Infected: Trojan.Popwin.DE
C:\Program Files\WinPop\winpop.exe Disinfection failed
C:\Program Files\WinPop\winpop.exe Moved
C:\WINDOWS\R2lvcmdpbw\asappsrv.dll Detected: Adware.CommAd.A
C:\WINDOWS\R2lvcmdpbw\asappsrv.dll Disinfection failed
C:\WINDOWS\R2lvcmdpbw\asappsrv.dll Moved
C:\WINDOWS\R2lvcmdpbw\command.exe Detected: Adware.CommAd.A
C:\WINDOWS\R2lvcmdpbw\command.exe Disinfection failed
C:\WINDOWS\R2lvcmdpbw\command.exe Moved
C:\WINDOWS\R2lvcmdpbw\lZ5SwAxDvT.vbs Detected: Adware.Isearch.D
C:\WINDOWS\R2lvcmdpbw\lZ5SwAxDvT.vbs Disinfection failed
C:\WINDOWS\R2lvcmdpbw\lZ5SwAxDvT.vbs Moved
C:\WINDOWS\system32\gwvmwer.dll Detected: Adware.ClickSpring.CB
C:\WINDOWS\system32\gwvmwer.dll Disinfection failed
C:\WINDOWS\system32\gwvmwer.dll Moved
C:\WINDOWS\uninstall_nmon.vbs Infected: Trojan.Small.WY
C:\WINDOWS\uninstall_nmon.vbs Disinfection failed
C:\WINDOWS\uninstall_nmon.vbs Moved






Thats everything, i really appreciate you helping me
zipzappy is offline