View Single Post
Old 07-11-2008, 07:46 AM   #3 (permalink)
sam1975
Registered User
 
Join Date: Jul 2008
Posts: 15
OS: XP SP2


Re: warning! spyware detected on your computer!

Hi,

Thank you very much.

Firstly, my windows auto updates is not working since this malware. I am getting the error:
--------------------------------
some updates could not be installed

Microsoft windows installer 3.1.
--------------------------------
Further,

I followed all five steps explained.

Please find the attached Export To file details from Panda ActiveScan.


;***********************************************************************************************************************************************************************************
ANALYSIS: 2008-07-11 22:34:31
PROTECTIONS: 1
MALWARE: 18
SUSPECTS: 2
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
McAfee VirusScan 10.02 No No
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00020994 W32/Bagle.pwdzip Virus No 0 Yes Yes C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric3.zip
00020994 W32/Bagle.pwdzip Virus No 0 Yes Yes C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip
00020994 W32/Bagle.pwdzip Virus No 0 Yes Yes C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip
00020994 W32/Bagle.pwdzip Virus No 0 Yes Yes C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Cookies\sangamnath_hulsoor@doubleclick[1].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.doubleclick.net/]
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Cookies\sangamnath_hulsoor@atdmt[2].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.atdmt.com/]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Cookies\sangamnath_hulsoor@tribalfusion[2].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.tribalfusion.com/]
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.mediaplex.com/]
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.xiti.com/]
00167760 Cookie/Hitslink TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[counter.hitslink.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Cookies\sangamnath_hulsoor@ad.yieldmanager[2].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[ad.yieldmanager.com/]
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.apmebf.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Cookies\sangamnath_hulsoor@serving-sys[2].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.serving-sys.com/]
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Cookies\sangamnath_hulsoor@bs.serving-sys[2].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.bs.serving-sys.com/]
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[statse.webtrendslive.com/]
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Application Data\Mozilla\Firefox\Profiles\whwqk95l.default\cookies.txt[.overture.com/]
01343188 Adware/WebSearch Adware No 0 Yes No C:\Documents and Settings\Sangamnath Hulsoor\Local Settings\Temp\{81936FC0-57D0-4E9F-97C0-FD86485ECAE7}\_extra\objects\cmdline.dll
01343188 Adware/WebSearch Adware Yes 1 Yes No C:\DOCUME~1\SANGAM~1\LOCALS~1\Temp\{81936~1\_extra\objects\cmdline.dll
03162765 Bck/Aimbot.BR Virus/Trojan No 1 Yes Yes C:\System Volume Information\_restore{734E79AB-D53D-4294-AE7D-7B980FEA90A4}\RP7\A0002386.exe
03162765 Bck/Aimbot.BR Virus/Trojan Yes 2 Yes Yes C:\WINDOWS\msauc.exe
03162765 Bck/Aimbot.BR Virus/Trojan No 1 Yes Yes C:\WINDOWS\system32\wpx4.cpx
03194726 Trj/Buzus.AH Virus/Trojan No 1 Yes Yes c:\windows\iexplorer.exe
03204794 Spyware/Virtumonde Spyware No 1 Yes No C:\System Volume Information\_restore{734E79AB-D53D-4294-AE7D-7B980FEA90A4}\RP1\A0000101.exe
03204794 Spyware/Virtumonde Spyware No 1 Yes No C:\System Volume Information\_restore{734E79AB-D53D-4294-AE7D-7B980FEA90A4}\RP1\A0000116.exe
03204794 Spyware/Virtumonde Spyware No 1 Yes No C:\System Volume Information\_restore{734E79AB-D53D-4294-AE7D-7B980FEA90A4}\RP1\A0000085.exe
03204794 Spyware/Virtumonde Spyware Yes 2 Yes No C:\WINDOWS\system32\lphclewj0e5d5.exe
03204794 Spyware/Virtumonde Spyware No 1 Yes No C:\System Volume Information\_restore{734E79AB-D53D-4294-AE7D-7B980FEA90A4}\RP7\A0002387.exe
03204794 Spyware/Virtumonde Spyware No 1 Yes No C:\System Volume Information\_restore{734E79AB-D53D-4294-AE7D-7B980FEA90A4}\RP7\A0002391.exe
03204794 Spyware/Virtumonde Spyware No 1 Yes No C:\System Volume Information\_restore{734E79AB-D53D-4294-AE7D-7B980FEA90A4}\RP1\A0002132.exe
03239006 Trj/Agent.JDF Virus/Trojan No 0 Yes Yes C:\WINDOWS\system32\wpx2.cpx
03239006 Trj/Agent.JDF Virus/Trojan No 0 Yes Yes C:\WINDOWS\system32\userinit.exe
;===================================================================================================================================================================================
SUSPECTS
Sent Location s
;===================================================================================================================================================================================
No C:\WINDOWS\system32\drivers\Yrgr48.sys s
No C:\WINDOWS\system32\wpx5.cpx s
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description s
;===================================================================================================================================================================================
184380 MEDIUM MS08-002 s
184379 MEDIUM MS08-001 s
182048 HIGH MS07-069 s
182046 HIGH MS07-067 s
182043 HIGH MS07-064 s
179553 HIGH MS07-061 s
176382 HIGH MS07-057 s
176383 HIGH MS07-058 s
170911 HIGH MS07-050 s
170907 HIGH MS07-046 s
170906 HIGH MS07-045 s
170904 HIGH MS07-043 s
164915 HIGH MS07-035 s
164913 HIGH MS07-033 s
164911 HIGH MS07-031 s
160623 HIGH MS07-027 s
157262 HIGH MS07-022 s
157261 HIGH MS07-021 s
157260 HIGH MS07-020 s
157259 HIGH MS07-019 s
156477 HIGH MS07-017 s
150253 HIGH MS07-016 s
150249 HIGH MS07-013 s
150248 HIGH MS07-012 s
150247 HIGH MS07-011 s
150243 HIGH MS07-008 s
150242 HIGH MS07-007 s
150241 MEDIUM MS07-006 s
145501 HIGH MS07-004 s
141034 HIGH MS06-076 s
141033 MEDIUM MS06-075 s
137571 HIGH MS06-070 s
133387 MEDIUM MS06-065 s
133386 MEDIUM MS06-064 s
133385 MEDIUM MS06-063 s
133379 HIGH MS06-057 s
129977 MEDIUM MS06-053 s
129976 MEDIUM MS06-052 s
126093 HIGH MS06-051 s
126092 MEDIUM MS06-050 s
126087 HIGH MS06-046 s
126086 MEDIUM MS06-045 s
126082 HIGH MS06-041 s
126081 HIGH MS06-040 s
123421 HIGH MS06-036 s
123420 HIGH MS06-035 s
120825 MEDIUM MS06-032 s
120823 MEDIUM MS06-030 s
120818 HIGH MS06-025 s
120815 HIGH MS06-022 s
117384 MEDIUM MS06-018 s
114666 HIGH MS06-015 s
108744 MEDIUM MS06-008 s
108743 MEDIUM MS06-007 s
108742 MEDIUM MS06-006 s
104567 HIGH MS06-002 s
104237 HIGH MS06-001 s
96574 HIGH MS05-053 s
93395 HIGH MS05-051 s
93394 HIGH MS05-050 s
93454 MEDIUM MS05-049 s
;===================================================================================================================================================================================

Thanks
Sam
sam1975 is offline