View Single Post
Old 01-14-2008, 06:42 AM   #1 (permalink)
flame87
Registered User
 
Join Date: Apr 2007
Posts: 47
OS: Windows XP


Trojan Horse PSW.OnlineGames.IBA

Hi

My computer got infected with Trojan Horse PSW.OnlineGames.IBA

Once in awhile my IE would pop up to an address whcih can't be loaded.
I've scan my system once ine AVG right after i got infected but it can't heal my system completely

Im pretty sure it got infected with another Trojan Horse as well.

Is there anyway i can get rid of them completely?

Here's the log.(I've included the panda one as well)
Thanks!

Incident Status Location

Virus:W32/Autorun.DZ.worm Disinfected C:\autorun.inf
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Owner\Desktop\ComboFix.exe[ComboFixT\nircmd.cfexe]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.adtech.de/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.zedo.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.com.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.atwola.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[server.iad.liveperson.net/hc/35245341]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Application Data\Mozilla\Firefox\Profiles\eud9xbpb.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Cookies\owner@888[1].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Cookies\owner@888[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Cookies\owner@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Cookies\owner@atwola[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Cookies\owner@burstnet[1].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Cookies\owner@cassava[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Cookies\owner@doubleclick[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Cookies\owner@www.burstbeacon[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Cookies\owner@xiti[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Cookies\owner@yadro[1].txt
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Desktop\thumbdrive\ComboFix.exe[ComboFixT\nircmd.cfexe]
Virus:Generic Malware Disinfected C:\Documents and Settings\Owner.ADMIN-CDB184AE0\Desktop\thumbdrive\Flash_Disinfector.exe
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\windows-OLD\nircmd.exe
Virus:W32/Autorun.DZ.worm Disinfected D:\autorun.inf
Virus:Generic Malware Not disinfected D:\New Folder\StormCodec5.00.-34.exe[CdnAux.dll]
Virus:Generic Malware Not disinfected D:\New Folder\StormCodec5.00.-34.exe[CdnIEHlp.dll]
Virus:Generic Malware Not disinfected D:\New Folder\StormCodec5.00.-34.exe[CdnProt.dll]
Virus:Generic Malware Not disinfected D:\New Folder\StormCodec5.00.-34.exe[CodeLib.dll]
Virus:Generic Malware Not disinfected D:\New Folder\StormCodec5.00.-34.exe[cdn.dll]
Attached Files
File Type: txt extra.txt (17.2 KB, 5 views)
File Type: txt Activescan.txt (17.6 KB, 2 views)

Last edited by Ried; 01-22-2008 at 06:30 PM.
flame87 is offline  
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here