View Single Post
Old 11-30-2007, 09:36 AM   #5 (permalink)
lachs99
Registered User
 
Join Date: Nov 2007
Posts: 15
OS: WIN XP SP2


Re: Adware-gen + Trojan-gen + Agent-LTS --- rmv.exe etc. -- Red Wallpaper

Here is the panda scan results



Incident Status Location

Adware:adware/wintools Not disinfected Windows Registry
Spyware:spyware/media-motor Not disinfected Windows Registry
Adware:adware/savenow Not disinfected Windows Registry
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\NirCmd.exe
Spyware:Cookie/Adverserve Not disinfected C:\Dokumente und Einstellungen\%USER%\Cookies\%USER%@adverserve[1].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Dokumente und Einstellungen\%USER%\Cookies\%USER%@statse.webtrendslive[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Dokumente und Einstellungen\%USER%\Cookies\%USER%@tribalfusion[1].txt
Spyware:Cookie/Adverserve Not disinfected C:\Dokumente und Einstellungen\%USER%\Anwendungsdaten\Mozilla\Firefox\Profiles\3i4l3xal.default\COOKIES.TXT[.adverserve.net/]
Spyware:Cookie/Mediaplex Not disinfected C:\Dokumente und Einstellungen\%USER%\Anwendungsdaten\Mozilla\Firefox\Profiles\3i4l3xal.default\COOKIES.TXT[.mediaplex.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Dokumente und Einstellungen\%USER%\Anwendungsdaten\Mozilla\Firefox\Profiles\3i4l3xal.default\COOKIES.TXT[.tribalfusion.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Dokumente und Einstellungen\%USER%\Anwendungsdaten\Mozilla\Firefox\Profiles\3i4l3xal.default\COOKIES.TXT[.doubleclick.net/]
Virus:Trj/Citifraud.A Disinfected C:\Programme\Netscape\Users\DEFAULT\Mail\Inbox[~0000050.~]
Virus:Bck/MIRCBased.BI Disinfected C:\Programme\mIRC\BACKUP\MIRC.EXE
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\RECYCLED\Dc1.exe[nircmd.exe]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\RECYCLED\Dc1.exe[nircmd.cfexe]
Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLED\Dc2.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLED\Dc4\Process.exe
Virus:Trj/Rebooter.J Disinfected C:\RECYCLED\Dc4\Reboot.exe
Potentially unwanted tool:Application/SuperFast Not disinfected C:\RECYCLED\Dc4\RESTART.EXE
Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLED\Dc5.zip[SmitfraudFix/Process.exe]
Virus:Trj/Rebooter.J Disinfected C:\RECYCLED\Dc5.zip[SmitfraudFix/Reboot.exe]
Potentially unwanted tool:Application/SuperFast Not disinfected C:\RECYCLED\Dc5.zip[SmitfraudFix/restart.exe]
Virus:Generic Malware Disinfected E:\Download\Audio.zip[Audio/BeatM200.exe]
Virus:Generic Trojan Not disinfected E:\Download\Graphic.zip[Graphic/Adobe/aps70kg[1].zip][aps70kg.rar][keygen.exe]
Virus:Generic Trojan Not disinfected E:\Download\New\System\WinTasks.Professional.v5.04.Incl.Patch-SnD.rar[WinTasks.Professional.v5.04.Incl.Patch-SnD\Patch\patch.exe]
Virus:W32/Nuwar.C.worm Disinfected E:\Download\New\System\Harddrive Encrypting\SecurStar[1].DriveCrypt.v4.20.040517.Read.NFO.Internal-dT.ZIP[SecurStar.DriveCrypt.v4.20.040517.Read.NFO.Internal-dT/d-dc42i1.zip][keymaker.exe]
Virus:Generic Backdoor Not disinfected E:\Download\New\System\Powerquest Drive Image v7.03 Incl Keygen-Ror Shareconnector.rar[KeyGen\keygen.exe]
Hacktool:Exploit/iFrame Not disinfected Lokale Ordner\Archiv\Jahr 2001\Dezember 2001\EBS Mails\Veranstaltungen im Park-Cafe
Hacktool:Exploit/iFrame Not disinfected Lokale Ordner\Archiv\Jahr 2004\03 - 06 / 2004 Sydney\Newsletter\[EVO] Mail Delivery
Hacktool:Exploit/iFrame Not disinfected Lokale Ordner\Archiv\Jahr 2004\03 - 06 / 2004 Sydney\Newsletter\Mail Delivery
Hacktool:Exploit/iFrame Not disinfected Lokale Ordner\Archiv\Jahr 2004\03 - 06 / 2004 Sydney\Newsletter\Mail Delivery
Hacktool:Exploit/iFrame Not disinfected Lokale Ordner\Archiv\Jahr 2004\03 - 06 / 2004 Sydney\Newsletter\[EVO] Mail Delivery
Hacktool:Exploit/iFrame Not disinfected Lokale Ordner\Gesendete Objekte\Send 2002\Fwd: Wochenende, feier
Virus:Generic Trojan Disinfected Lokale Ordner\Gesendete Objekte\Send 2002\keygen\keygen.zip[keygen.exe]
lachs99 is offline